7 ms·
I found the footnote quite interesting: > Some software, notably git, is still using SHA-1, and relying on the fact that the best publicly-known method of gene
by Hanschri 5y ago
I found the footnote quite interesting:
> Some software, notably git, is still using SHA-1, and relying on the fact that the best publicly-known method of generating SHA-1 collisions costs 2⁶⁹ computations, which is expensive. I think it is unwise to rely on this for two reasons. One is that there could be more efficient techniques to compute SHA-1 collisions that we don’t know about. Another is that the cost of doing 2⁶⁹ computations is falling rapidly—at the time of this writing (March 22, 2014), the Bitcoin network is performing enough computation to generate SHA-1 collisions every 131 minutes!
By guesstimating from just looking at the graph to the linked site, it seems the Bitcoin network was at about 100 PH/s, with the network at 185 EH/s, which is close to a 2000x in hashrate since this blogpost went live.
- staticassertion 5y agoAnd Linus was told of this and, in typical Linus fashion, he dismissed it.
- stickfigure 5y agoIs there some way of co-opting the bitcoin network into calculating specific hash collisions?
- loeg 5y agoNo; it's a different algorithm.
- drexlspivey 5y agoYou would need 6 zettabytes per second to even store all the hashes generated by the BTC network. That’s many times the world’s storage capacity generated every second.
- Dylan16807 5y agoAnd was he wrong?
- staticassertion 5y agoYes. He chose to design his system with no ability to migrate and use a hash algorithm that was already known to be flawed. https://www.metzdowd.com/pipermail/cryptography/2017-February/031623.html https://www.metzdowd.com/pipermail/cryptography/2017-Februar...
- Dylan16807 5y agoOh, you're not talking about him dismissing news of practical attacks as a direct threat, you're talking about him being dismissive very early on about the idea that he was doing a bad job of picking a hash. Yeah, okay, he was wrong to be dismissive there.
- qqii 5y agoFrom the threat it looks like Linus' threat model for git is simply different from the common use today. Of course a judgement under a different threat model would make it seem like a bad tradeoff!
- staticassertion 5y agoIt's more that Linus: 1. Didn't understand the attack 2. Doesn't understand security 3. Doesn't care He's shown this repeatedly for decades.
- nsajko 5y agoHash function transition document from the Git documentation: https://git-scm.com/docs/hash-function-transition/ https://git-scm.com/docs/hash-function-transition/
- benchaney 5y agoThis isn’t really true. git is relying on the second-preimage resistance of sha1 rather than the collision resistance. There are few attacks that theoretically are enabled by finding Sha collisions, by they aren’t really practical.