4 ms·
It's because both colliding files have to be specially prepared by the attacker, before they are published on a download site or presented for signing by a code
by nogbit 9y ago
It's because both colliding files have to be specially prepared by the attacker, before they are published on a download site or presented for signing by a code signing scheme.
https://www.win.tue.nl/hashclash/SoftIntCodeSign/ https://www.win.tue.nl/hashclash/SoftIntCodeSign/
Which means, the published MD5 on on the Intel site would have to be the hash that the attacker created.
Though I'm sure there are better methods that Intel could implement.