4 ms·
Why is this a problem? I even considered MD5, to be honest. Afaik, the only reason MD5 or SHA1 are considered "insecure" now is that it's possible to use sophis
by comntr 7y ago
Why is this a problem? I even considered MD5, to be honest. Afaik, the only reason MD5 or SHA1 are considered "insecure" now is that it's possible to use sophisticated techniques called differential analysis to carefully craft two binary files that would have the same hash. But if the space of possible inputs is limited (we can't put arbitrary stuff in the URLs), then good luck finding a collision. Discovering a collision with an existing input is a much harder problem (is it even solved for arbitrary data?). In any case, SHA1 here isn't a security mechanism, but is just a way to hide URLs from the data server and organize comments as a nice hashmap. If someone wants to put anything sensitive in the comments, they shouldn't and I've clearly warned about this with a big yellow banner. If someone ever needs security, the only way to go is to use your own data server, or encrypt comments themselves with ed25519+aes256.
- b3n 7y agoThe problem with using SHA1 to protect PII is it would be trivial to brute force, especially with the restrictive character set of URLs, and a big part of them being able to be guessed. One could very quickly cycle through all Hacker News URLs, for example. This is why a key derivation function would be preferable.
- comntr 7y agoThe space of possible reasonable URLs is way too big to brute force. If your point is that someone can just grab the set of existing HN URLs and get their heashes, then I don't see what this achieves. Someone who knows the URLs can just download all the comments for them anyway. In other words, is there an example where a sophisticated state of the art hash has advantage over MD5 in our case?