5 ms·
Not (at all) an expert, but I think what you are referring to is a harder problem: given an SHA1-hash, to find something that maps to it. Getting a collision is
by spi 4y ago
Not (at all) an expert, but I think what you are referring to is a harder problem: given an SHA1-hash, to find something that maps to it. Getting a collision is quite simpler: just create two inputs that map to the same thing, or (more realistically in attacks) you know the original content (and therefore its SHA1 hash) and you want to create another content that has the same SHA1. If, on top, you can also decide (to some margin) what to put in, you can add some "invisible" malevolent pieces. As far as I understand, this is much easier than reversing an arbitrary SHA1-key (with or without "chosen" additional content) without knowing one decrypted key, because the collisions that were found so far were always of rather big files sharing a vast majority of their contents. An ideal hashing would give totally different results changing just any byte in the contents, but apparently this is not the case for SHA1 (but again, I'm just a casual reader about these things!).