3 ms·
It's totally possible the reality is different from the theoretical limit. See collision attacks against MD5, SHA-0 by Wang Xiaoyun. https://en.wikipedia.org/w
by dracodoc 9y ago
It's totally possible the reality is different from the theoretical limit. See collision attacks against MD5, SHA-0 by Wang Xiaoyun.
https://en.wikipedia.org/wiki/Wang_Xiaoyun https://en.wikipedia.org/wiki/Wang_Xiaoyun
- api 9y agoThose are directed attacks not random collisions.
- skate22 9y agoThe article uses the context of content validation from untrusted sources lol
- DennisP 9y agoAs long as the hash function remains unbroken, untrusted sources can't screw with you. Hash functions tend to be broken gradually and publicly, and we migrate to new ones as they start to look shaky. It's theoretically possible for someone to privately break a function that everyone else thinks is secure, but it would be an extremely impressive achievement since lots of full-time cryptographers work on breaking these things and publish every little bit of progress they make.
- DennisP 9y agoYes, the chance that the hash will be broken is much higher than the chance of collisions occurring randomly. I'm just responding to "hash functions only guarantee no collisions to a high probability." People really underestimate how strong that probabilistic guarantee is.