3 ms·
> No... Why ? > in this scenario the attacker has the victim’s new private key You don't want to keep your private key in cleartext on your email provider se
by _notreallyme_ 7y ago
> No...
Why ?
> in this scenario the attacker has the victim’s new private key
You don't want to keep your private key in cleartext on your email provider servers, do you ?
- makomk 7y agoThis allows you to take two messages and append some data to both of them which causes the modified versions to have the same SHA-1 hash - but you need to modify both messages, and in order to use this in an attack you need to set up a scenario where the SHA-1 hash of one of your modified messages is trusted for some purpose. Creating a message with the same hash as another, existing message requires a second-preimage attack which is much harder and not feasible for any cryptographic hash that's currently in use.