10 ms·
As a total neophyte on these kinds of things, the article seems to be talking about Google's SHA vulnerability as if it's a preimage attack rather than a collis
by mnarayan01 10y ago
As a total neophyte on these kinds of things, the article seems to be talking about Google's SHA vulnerability as if it's a preimage attack rather than a collision one. Anyone more knowledgeable care to chime in?
- loup-vaillant 10y agoSome protocols are sensitive to mere collisions. Also, this suggests actual preimage attacks could be found later. Not today, but still. Finally an accurate explanation is longer and has less punch. It's safer to "join the headless chicken" route, consider SHA-1 officially broken, and start thinking of alternatives.
- WorldMaker 10y agoIIRC, collision attacks may be considered precursors to preimage attacks. Some preimage attacks look like "brute force" monte carlo simulations of collision attacks, running enough collision attacks in parallel until a collision attack results in the preimage.
- bjornsing 10y agoYea, it's a bit funny to see somebody complain about headless chickens, and then go straight into dancing around like a headless chicken himself. :P Why is the difference between collision and preimage so difficult for people to understand...? I'm genuinely puzzled.