3 ms·
If the original files weren't under the control of the adversary, that's a preimage attack, not a collision attack. No hash that's ever used for file authentica
by alethiophile 9y ago
If the original files weren't under the control of the adversary, that's a preimage attack, not a collision attack. No hash that's ever used for file authentication, even MD5, is vulnerable to second preimage.
If they were, then first off you should have been more careful about putting untrusted data on the same drive as anything actually important, but secondly it's usually obvious when a file is constructed as part of a collision attack, and there would be no good reason for the government's exhibits to show those markers.
Really, this whole discourse is silly anyway. In accordance with the usual XKCD, if the government really wants to railroad you, they won't bother with cryptographic vulnerabilities; they'll just lie and/or plant evidence. Creating and exploiting a hash collision isn't something you do by accident; it's conscious, outright evidence manipulation, and if they're willing to do that they can do it much easier ways.