5 ms·
The Second SHA-1 Hash Collision
- fulldecent2 7y agoNow 1000x smaller than the original Shattered attack from Google! And 1000000x less expensive!!! Buy now
- elgfare 7y agoThis has frustratingly little information about how it was done.
- djsumdog 7y agoYes, there isn't much. The two files have PDF headers; so I presume they were messing around with some PDF exploit experiments? or signed PDF documents? I wonder if we'll get more information; or if they're holding back until people take it seriously and attempt to get off SHA-1 for critical stuff?
- tedunangst 7y agoTruncate the original files to the differing blocks. Tada.
- ummonk 7y agoOh of course. So any of us could generate "new" hash collisions by adding new identical blocks to these...
- deleted 7y ago[deleted]
- jacquesm 7y agoInteresting how 'privacy log' includes 'google', 'twitter', 'facebook' and - strangely - 'paypal' 3rd party bits & pieces. Authors home page is here: https://phor.net/ https://phor.net/
- deleted 7y ago[deleted]
- Trias11 7y agoEvery hash function is guaranteed to have infinite number of collisions.
- sida 7y agoI mean, this is a really “water is wet” statement
- bawolff 7y agoEvery lottery is garunteed to have a winner. Doesnt mean i wouldnt be excited if i won the jackpot
- nikbackm 7y agoDepends on the lottery, sometimes there is no one getting all the numbers correct so the prize money accumulates to the next round.
- deleted 7y ago[deleted]
- clement_b 7y agoThis is great, but it's a bit like an endangered animal giving birth in a zoo. Has anyone seen a collision happening in the wild? What's the likelihood? Vs UUID?
- bawolff 7y agoAsking the liklihood is kind of the wrong question. The problem with sha-1 is the possibility that a malicious person could intentionally make two files with the same hash (in order to do evil). The probability of this happening if someone decides to do it and has sufficient resources to pull it off, is 1. The probability of it happening accidentally hasn't changed and is so small it might as well be 0.
- clement_b 7y agoMakes sense! Thanks for explaining
- C4stor 7y agoUUID don't "collide", they're just the same, or not. They're not generated from any business relevant input, there is nothing to "confuse" in the first place, and the whole concept of uuid "colliding" doesn't make sense.
- deathanatos 7y agohttps://en.wikipedia.org/wiki/Universally_unique_identifier https://en.wikipedia.org/wiki/Universally_unique_identifier v5 UUIDs are generated from SHA-1 hashes of their input, so they can collide in exactly the same way a normal SHA-1 can collide: two different inputs yield the same output. But even for v4 (randomly generated) UUIDs, I would say "collide" is appropriate, if you're asking about the chance of two or more randomly generated v4 UUIDs colliding is. (That is, generating the same UUID twice. Infinitesimal, but the use of "colliding" to ask is still valid.)
- kfrzcode 7y agoWon't be the last. Would appreciate a longer writeup but I'm sure we'll see more. First one, for reference: https://shattered.it/ https://shattered.it/ https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html https://www.schneier.com/blog/archives/2012/10/when_will_we_...
- vbitz 7y agoThis is just the first 320 bytes of the original shattered. They just cut off the rest of the PDF data.
- re 7y agoYes. It also isn't the "second" sha-1 collision, by any means -- you could already trivially use the prefix and colliding blocks from the shattered example and append any suffix you want to generate more collisions: https://news.ycombinator.com/item?id=13723892 https://news.ycombinator.com/item?id=13723892 A true second collision wouldn't start with the same 320 bytes. A more interesting one might use fewer bits to achieve the collision.
- SpicyLemonZest 7y agoDoes that... work? I guess so, but why does it work?
- tedunangst 7y agoOnce the two sha1 states are synchronized, after the first 320 bytes, they will remain in sync as long as you extend them with the same data. (BTW This is why hmac exists, to prevent extension attacks.)
- bawolff 7y agoLol, i wonder if this is the first example of someone using the inverse of the length extension attack to trick people
- latchkey 7y agoFor those who are curious, here is a screenshot of `vbindiff shat-a.bin shat-b.bin` output in my terminal: https://imgur.com/a/uZttSbD https://imgur.com/a/uZttSbD
- hurricanetc 7y agoMake sure to like, tweet, and FB comment on this... privacy blog.
- joshspankit 7y agoIt doesn’t get mentioned enough: this is with the exact same filesize. Most collision mitigations (such as git’s) revolve around using hash combined with filesize as a collision is inevitable, but a collision with the same filesize is much harder.