2 ms·
Ah, okay. Yeah, that does seem quite possible. They are saying "HTTPS Certificates" are potentially impacted - but they're probably just trying to push people
by problems 10y ago
Ah, okay. Yeah, that does seem quite possible.
They are saying "HTTPS Certificates" are potentially impacted - but they're probably just trying to push people away from SHA1 as fast as possible.
- jsolson 10y agoRe-reading it and checking out the demo on https://shattered.io/ https://shattered.io/ it looks like it's even stranger -- some PDFs are "safe", so it may be that it requires the original document (and hash) to have certain properties to be able to generate a collision (but if it has those properties they may be able to generate them arbitrarily). It sounds like this is going to be reaaaalllly interesting when the 90 day window passes. (also, should've mentioned in original post just for clarity -- I work for Google, but do not know any of the details of this work)
- eridius 10y agoIt's entirely possible that "dangerous" PDFs are simply ones with a dead chunk containing image data in in the middle of it, and if there's no dead chunks, or if the dead chunks don't allow for arbitrary garbage data, then it's "safe".