6 ms·
From the same thread (Peter Gutmann, Fri Feb 24 00:42:36 EST 2017): "After sitting through an endless flood of headless-chicken messages on multiple media abou
by ifdefdebug 10y ago
From the same thread (Peter Gutmann, Fri Feb 24 00:42:36 EST 2017):
"After sitting through an endless flood of headless-chicken messages on multiple media about SHA-1 being fatally broken, I thought I'd do a quick writeup about what this actually means. In short:
Reports of SHA-1's demise are considerably exaggerated.
What CWI/Google have done is confirmed what we've known for a long time, that SHA-1 is shaky. Using a nation-state's worth of resources and a year of time (https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html https://security.googleblog.com/2017/02/announcing-first-sha...), they've shown that, with a very carefully-crafted document, you can create a collision. Their presentation of the results is detailed and accurate, it's the panicked misinterpretation of those results that are the problem."
Continues here:
http://www.metzdowd.com/pipermail/cryptography/2017-February/031604.html http://www.metzdowd.com/pipermail/cryptography/2017-February...
[edit: typo]
- simias 10y ago110,000$ is not "a nation-state's worth of resources". I agree with the rest though, the sky is not falling but people shouldn't react to baseless alarmist claims with baseless overconfident claims.
- StreamBright 10y agoSecurity is quite often about the amount of money you have to put in to get something or somebody hacked. 110,000 USD is in the ballpark of state level players when we are talking about forging documents to avoid any sort of tampering detection. It has practically zero use of small time hackers or script kiddies. Why would anybody invest 110K into a collision? What is the practical use of it?
- userbinator 10y agoIn other words, SHA-1 is still nowhere near as insecure as MD5, the latter for which collisions can be generated in seconds on hardware everyone already has.
- aaron695 10y agoI didn't realise this was true - https://www.bishopfox.com/resources/tools/other-free-tools/md4md5-collision-code/ https://www.bishopfox.com/resources/tools/other-free-tools/m...
- adrianN 10y agoIf you manage to get a vulnerability into a widely used codebase using a sha1 collision, that could very well be worth more than $100k.
- StreamBright 10y agoThey managed it without any collision several times: https://arstechnica.com/security/2016/08/cisco-confirms-nsa-linked-zeroday-targeted-its-firewalls-for-years/ https://arstechnica.com/security/2016/08/cisco-confirms-nsa-... https://www.theregister.co.uk/2010/12/15/openbsd_backdoor_claim/ https://www.theregister.co.uk/2010/12/15/openbsd_backdoor_cl...
- simias 10y agoIf there's no practical use for it then even state level players won't bother with it. If there's ever a practical use for it (i.e. money to be made) 110$k is totally accessible to the private sector. It's definitely not "a nation-state's worth of resources" which is the quote I was replying to. Fortunately there doesn't appear to be a whole lot of practical use for these collisions for the time being.
- michaelt 10y agoWhy would anybody invest 110K into a collision? The thing people fear is (1) A collision that lets you have good code pass review, then have evil code released to users; (2) That happening to Linux/Android/Firefox/Chrome; (3) The cost of creating a remote code execution exploit being lower than the market value of that exploit on the black market. I don't know how /realistic/ this fear is. Certainly, if everyone PGP signs all their commits, it's a much-reduced risk - but how many projects mandate that? or some less scrutinised but widely deployed package
- ethbro 10y agoYou'd ideally want to do this with a binary blob (firmware or graphics driver, because you know there's one sitting in git somewhere). Then, how is anyone going to know the difference?
- emn13 10y agoAlso: that cost is certain to drop, and it might drop quite quickly - simply due to software and hardware improvements. If anything algorithmic shows up, it could change dramatically. Let's not wait for that to happen.
- fulafel 10y agoThere are many low cost ways of doing "$100k worth of AWS" computation. Eg botnets, distributed volunteering, moonlight use of employers idle servers etc etc.
- mcherm 10y ago> Why would anybody invest 110K into a collision? What is the practical use of it? Suppose you are on the verge of completing a major sale to some large, nervous purchaser -- perhaps a major world military. This is a decent-sized but not huge sale: $2 billion, with profits of around $200 million. The other major competitor for this contract is built around Linux and your offering relies on a custom operating system. Your head of sales thinks that the the purchasing agent seems particularly concerned about security issues with the operating system -- keeps asking questions like "So, can you document that your system is less vulnerable than some 'open source' system?". The head of sales makes a rough guess that a news story about vulnerabilities in Linux might sway the chance of winning the contract by around 5%. So: that's $10 million in value to your company that might created by generating publicity about the vulnerability of Git so long as that publicity is generated at the right moment in time. What's the chance that 1% of that can be "found" to make it happen? The thing is: $110,000 is actually a very SMALL amount of money, relative to the amounts of money that many influential people manage on a daily basis. The use doesn't have to be very practical for it to be well worth it.
- quizotic 10y agoInteresting hypothetical ... even more interesting if you're implying it might not be so hypothetical
- mcherm 10y agoI am NOT implying that it might not be hypothetical. I have absolutely no reason to believe that anything like this has been attempted. I'm just trying to point out that for many out there, $100K is chump change.
- Chyzwar 10y agoPathes in Linux are reviewed by multiple people before merging. Even if you create a collision and submit patch you cannot really do much without write access to repo. It is even more difficult because person merging path will not fast forward in most cases. This attack still do not allow for inserting a arbitrary data in arbitrary places to make attack on Linux possible. Finally SHA1 in git also take size into consideration and make this attack even more expensive[2]. People should really chill out. There are cheaper attack vectors that collisions. [2] https://public-inbox.org/git/CA+55aFxJGDpJXqpcoPnwvzcn_fB-zaggj=w7P2At-TOt4buOqw@mail.gmail.com/ https://public-inbox.org/git/CA+55aFxJGDpJXqpcoPnwvzcn_fB-za...
- semi-extrinsic 10y agoThe implied meaning might have been "a significant post on a nation-state's cyber attack budget"? I'm pretty sure they did not mean "the total budget of a nation-state" or anything of the sorts, since that's obviously wrong. One has to agree, an entity willing to drop a cool $100k on finding a single SHA1 collision to try and attack your git repo is a lot closer to nation-state level than the for-the-lulz level.
- petertodd 10y ago$100k isn't that much money, particularly since collisions can be reused for multiple attacks w/ length-extension. Heck Bitcoin has had (ineffective) spam attacks that have probably have cost around that much, and there's good reason to suspect they've been privately funded by angry trolls. There's a lot of people for whom $100k is "fuck you" money.
- dmd 10y agoThat's not what "fuck you" money means. https://www.quora.com/What-is-fuck-you-money https://www.quora.com/What-is-fuck-you-money
- phpnode 10y ago"fuck you money" is something different - it's the amount of wealth you need (varying per individual) where you can comfortably say "fuck you" to a particular job or opportunity or proposal someone makes to you if you don't want to do it. I believe the term you're looking for is something like "chump change"
- ominous 10y agoI have seen it used in that (to mean the same as chump change) in linkedin articles by random recruiters, so I guess it will suffer the fate of literally vs. figuratively. Terrible.. but use dictates meaning, if it goes mainstream.
- nommm-nommm 10y ago
- grovegames 10y agoTo put that in perspective, that's roughly the loaded rate of a salaried ~80k employee; roughly. So we're talking a single hire in a nice city.
- smcl 10y agoFor a single PDF document, once
- syncsynchalt 10y ago"For a single malicious C file in the linux kernel, once" (My understanding of the method is it might be extendable to modifying a comment mid-file and then introducing later code, instead of modifying a JPG inside a PDF)
- brockers 10y agoIt cannot. The Google implementation must effectively be done on a blob as the result would not be usable in a structure specific document. What is more, things that require a block chain (like git) are NOT covered with this current attack as both the source and resulting have to be worked on. Currently the attack vector only works when you can get both documents to "work towards each other" to produce a valid identical SHA1 value.
- tialaramex 10y agoThis was a fixed prefix collision attack. That means they can make two documents (P | A | anything) and (P | B | anything) for a fixed P, and they can find A, B, such that A and B are different but SHA1(P | A | anything) = SHA1(P | B anything) The Merkle-Damgård construction (used in MD4, MD5, SHA1 and SHA2 but not in SHA3 and some other modern hashes) invariably means length extension is possible, if you can collide two documents then you can add a suffix to both and also get a collision. This is how there's already a web site where you feed it images and it makes a "different" colliding PDF, it's just using Google's result with a different suffix after the 128-byte collision near the start.
- qdog 10y agoI think the initial r&d to get to this point is more along the lines of a nation-state investment. Google paid much more than $110k to get this working. It's not clear exactly how much it would cost to "weaponize", either.
- frik 10y agoExactly. 110k USD is like a penny for a top 5000 company and foreign state actors.
- deleted 10y ago[deleted]
- nthcolumn 10y agoThat was just SHA1. Linus mentioned the other day that there was another layer and that they weren't worried. It would take considerably more resources to crack that again. But it is rather jolly to speculate about such things and other users of SHA1 (Windows?) might not nearly be so immune?
- dv_dt 10y agoIs that the cost for just the compute resources assuming time from people with expertise is free? Or setting up the resources to have a stable of people with the right background... Once you have that, then yes maybe its 100k.
- ifdefdebug 10y agoIt's worth noting that the figure of $110000 was not mentioned in the referenced message, so probably Peter Gutmann was thinking at a different scale when he wrote "a nation-state's worth of resources".
- deleted 10y ago[deleted]