4 ms·
Regarding the difficulty of generating a collision with working code, wouldn't it be as "trivial" as generating a SHA-1 collision in the first place? Just have
by hmsimha 4y ago
Regarding the difficulty of generating a collision with working code, wouldn't it be as "trivial" as generating a SHA-1 collision in the first place?
Just have the malicious code in a file and append a multiline comment block, then have your collision generator insert random junk into that comment block
- ed25519FUUU 4y agoGenerating the “junk” is the extraordinarily challenging part, though it’s been proved possible.
- hmsimha 4y agoSure, I had the word "trivial" in quotes for that reason. I meant that if you're able to generate a collision, the rest of this doesn't follow (from the article) > Even if creating a collision were feasible for an attacker, Bjarmason pointed out, that is only the first step in the development of a successful attack. Finding a collision of any type is hard; finding one that is still working code, that has the functionality the attacker is after, and that looks reasonable to both humans and compilers is quite a bit harder — if it is possible at all.