3 ms·
There could be hash-colissions of entirely diffrent files. Hashes are not proof enough.
by louithethrid 9y ago
There could be hash-colissions of entirely diffrent files. Hashes are not proof enough.
- alethiophile 9y agoIf it's a hash without known collision vulnerabilities, then it's 2^80 proof at least. This is definitely "beyond a reasonable doubt". Even if there were, what's the threat model? "Government creates colliding images one CP and one not, seeds the non-CP versions widely in torrents or something, then uses the hash collision to accuse anyone who downloaded of CP"? That's way more roundabout than governments will bother with; a dirty prosecutor will just fabricate evidence entirely, or have witnesses lie. (Plus, just producing the innocuous colliding image and demonstrating the collision would be an easy and ironclad defense.)
- manicdee 9y agoThe threat model is "antagonist creates colliding image which is CP, claims original unviewable file was CP." So you, the protagonist, have an encrypted volume full of the names and addresses of people helping evacuate Jews from Nazi-controlled Europe / blockade the construction of a new mine which was approved through bribery and corruption. The antagonist claims you are a CPer and produces a list of known hashes on files on your disk, and a sample of really awful images that conveniently have the same hashes. So the end game is either bust your information out to assist prosecution of the anti-government activists, or land you in the slammer as a CPer thus dragging your cause into the mud.
- alethiophile 9y agoIf the original files weren't under the control of the adversary, that's a preimage attack, not a collision attack. No hash that's ever used for file authentication, even MD5, is vulnerable to second preimage. If they were, then first off you should have been more careful about putting untrusted data on the same drive as anything actually important, but secondly it's usually obvious when a file is constructed as part of a collision attack, and there would be no good reason for the government's exhibits to show those markers. Really, this whole discourse is silly anyway. In accordance with the usual XKCD, if the government really wants to railroad you, they won't bother with cryptographic vulnerabilities; they'll just lie and/or plant evidence. Creating and exploiting a hash collision isn't something you do by accident; it's conscious, outright evidence manipulation, and if they're willing to do that they can do it much easier ways.