3 ms·
I had a similar thought, but actually prefer this way. People who understand things well enough will know what first collision means, so can moderate their res
by stestagg 10y ago
I had a similar thought, but actually prefer this way.
People who understand things well enough will know what first collision means, so can moderate their response.
Others who are less familiar with the ridiculous levels of subtlety around this sort of thing are better off being given the simple message that sha1 is now legacy in all cases. Helps to avoid mistakes.
- bjornsing 10y agoSimple "truths" are sometimes useful. I can see that. I'm more surprised though at the resentful attitude towards the actual truth (in the non-alternative sense): collisions are useless in many cases and the necessary second pre-image is much more difficult to find. At least in a forum like HN I'd expect intellectual honesty to prevail. EDIT: Removed the incorrect example out of pure shame! :P
- detaro 10y ago/u/pvg linked below how the ability to generate collisions for MD5 was used to obtain a fake CA certificate. It's not obvious to me that this would not work with SHA-1 certificates, and that no other important things we use have similar weaknesses. (Neither do I know for sure that it would work, but "collisions are useless" seems like a dangerous simplification in the other direction. I suspect for many, simply replacing SHA-1 with something deemed better is easier than thoroughly evaluating the risks involved with not doing so)
- bjornsing 10y agoNow we're getting somewhere in terms of intellectual discussion! :) I of course agree we should replace SHA-1. But I still think a more intellectually honest discussion is meaningful. For example, after reading the link you referred to I'm rather convinced that X.509 is pretty seriously flawed, and could easily be redesigned to be collision resistant. Why not talk about that? Why not do it?
- mook 10y agoAs I understand it, CAs have mitigated the collision attacks by forcing a random serial number they generate into the certificates. Since that's part of the hash, collision attacks are no longer practical. Doing x509 still means having to parse ASN.1 though, and nobody seems to actually like it.