4 ms·
His idea is correct -- you're right, you don't know the entire internal state. But you can generate 2^32 possible internal states (because there are 32 bits of
by ReidZB 9y ago
His idea is correct -- you're right, you don't know the entire internal state. But you can generate 2^32 possible internal states (because there are 32 bits of missing information), then perform the length extension process using each possible state.
If the system is using the hash function in such a way that length extension creates a vulnerability, you can then try the 2^32 different possible valid length extended hashes, and one of them will be correct (and that will be evident because the exploit would work). But you are also correct that, in isolation, there is no way to determine which of the 2^32 resultant digests is the correct.
- ktta 9y agoGot it, thanks. So looks like it is possible, but infeasible in many cases. This obviously wouldn't work over internet because of the number of tries required, so what is a possibility that this would actually be a possible vulnerability?
- baby 9y agoI agree that if your oracle is remote, the attack is probably going to take weeks. Now I'm not sure you can conclude that this kind of scenario never allow for more efficient oracles.