3 ms·
This is not as far fetched as you think. In UK, rental contracts are often digitally signed by the renter and landlord. I am sure in finance world many other
by udev 10y ago
This is not as far fetched as you think.
In UK, rental contracts are often digitally signed by the renter and landlord.
I am sure in finance world many other types of contracts are signed digitally, also under the assumption that both parties sign the same thing.
- pornel 10y agoThe "signing" usually doesn't involve any cryptography. You just express your agreement, which can be as trivial as typing your initials in a box. It's purely a legal, not technical thing, so if you cleverly forge the document using collisions, you'll be shouting "but the SHA-1 matched!" from behind the bars.
- pfg 10y agoThe legal thing does make reference to the technical thing in Europe[1] (and probably elsewhere too), by making digital signatures (which use crypto) legally binding. The question is more how courts would rule in a case where a colliding document is signed. That would probably depend on whether you can prove which of the two parties authored the colliding document (since that's a requirement for this particular attack). (Note: I don't know whether this attack is practical for qualified electronic signatures as used by EU countries.) [1]: https://en.wikipedia.org/wiki/Qualified_electronic_signature https://en.wikipedia.org/wiki/Qualified_electronic_signature
- Twirrim 10y agoThere's a difference between digital signatures and sha-1 checksums of the files, which is what they seem to have been demonstrating. Mysteriously the text I quoted has now vanished from the original blog post.