4 ms·
Considering the choice of hash function of md5, not so bright I guess..
by luminati 7y ago
Considering the choice of hash function of md5, not so bright I guess..
- saagarjha 7y agoWhy is MD5 a poor choice in this context?
- deleted 7y ago[deleted]
- luminati 7y agoSee my above comment: https://news.ycombinator.com/item?id=20508786 https://news.ycombinator.com/item?id=20508786
- bhl 7y agoWhat’s wrong with the application of MD5 to this process?
- eliseumds 7y agoThis is not cryptography. MD5 is a very popular choice for hashing static assets.
- varenc 7y agoBut this is an adversarial use case. You're not trying to cause md5 hash collisions in your own static assets, but WeChat users might benefit from that. See my other comment above.
- swinglock 7y agoBig whoop. The hash collisions of MD5 allows an "attacker" to prevent himself from posting his own image. A simpler and cheaper way to perform the same "attack" would be to just not post the image in the first place as the outcome is the same.
- chrismsnz 7y agoIgnoring MD5/image format-specific collision realities, theoretically an attacker could submit a contraband image that collides with a valid, allowed image they may want to remove. When action is taken on the first image, the collided image could also be censored.
- deleted 7y ago[deleted]
- HALtheWise 7y agoNot with current technologies. There is a big difference between creating an image that collides with a specific target hash and just making two images that collide when you control both. The former is not currently possible, and the latter is. That being said, you could probably create a pair of colliding images, give one to a news outlet or something, then later post the second (presumably banned) one. The app would on short notice need to decide between banning neither or banning both.
- deleted 7y ago[deleted]
- chrismsnz 7y ago> That being said, you could probably create a pair of colliding images, give one to a news outlet or something, then later post the second (presumably banned) one. The app would on short notice need to decide between banning neither or banning both. Yeah they did this - except the contraband was automatically recognised and both images were banned via hash.
- xxxpupugo 7y agoWrong, it is digital fingerprint, not for encrypting. It is suffice for most cases to prevent the same image to spread, had it been blacklisted. Not all users are that tech savvy.
- deleted 7y ago[deleted]
- varenc 7y agoYou're right. CityLab researchers exploited MD5's weakness to answer questions about the system. While not a real problem in practice, it seems clear MD5 was not an ideal choice. From the article, the researchers generated forbidden and allowed images with a colliding hash to prove WeChat was using MD5. The allowed image was banned in the future as a result. However, MD5 collision generation has some constraints. It's very hard make an image collide with a particular known hash, but it's feasible (5 hours with a large GPU) to take two images and modify them until their hashes collide. Practically this means exploitation opportunities are rather limited, but a forced collision being possible at all seems non-ideal for an adversarial use case. There's also the risk that future cryptanalysis will further weaken MD5. Seems clear to me WeChat just should have used something like sha256.
- chillacy 7y agoAnother constraint is going to be cpu/battery usage, md5 probably has better hardware support in mobile processors as well as being faster to compute than a 256bit hash.
- blaser-waffle 7y ago> Practically this means exploitation opportunities are rather limited, but a forced collision being possible at all seems non-ideal for an adversarial use case. There's also the risk that future cryptanalysis will further weaken MD5. Seems clear to me WeChat just should have used something like sha256. With a billion people using phones, "good enough" is probably good enough. Given the scale and scope of the Chinese security apparatus, anyone capable of using a GPU to hash out collisions is probably already known to the state. And the handful of collisions are probably not important enough to worry about -- a stealthy Winnie The Poo image isn't a big deal.
- luminati 7y agoAs you pointed out, since this is an adversarial use case, a robust cryptographic hash function is the way to go. [For a non-cryptographic Hash function, SeaHash [1] would be the best choice, which is violently fast!] BLAKE2b would have been the perfect choice given the adversarial nature, as it much secure and faster than MD5. [2] MD5 is so broken, it's really poor choice for any use case - cryptographic (fundamentally broken) or not (fundamentally slow). [1] http://ticki.github.io/blog/seahash-explained/ http://ticki.github.io/blog/seahash-explained/ [2] https://leastauthority.com/blog/BLAKE2-harder-better-faster-stronger-than-MD5/ https://leastauthority.com/blog/BLAKE2-harder-better-faster-...