3 ms·
For example, if you already happen to know a collision hash(m1)=hash(m2), where m1 and m2 have full block size, then you also get a collision hash(m1|key)=hash(
by more_original 14y ago
For example, if you already happen to know a collision hash(m1)=hash(m2), where m1 and m2 have full block size, then you also get a collision hash(m1|key)=hash(m2|key), just as explained in the article. So, one could forge messages, which should clearly be counted as a weakness, even if it assumes knowledge of a collision.
- tomp 14y agoNot according to http://news.ycombinator.com/item?id=4089076 http://news.ycombinator.com/item?id=4089076 (SHA1 appends the length of the original message to the message).
- more_original 14y agoWell, if you have an internal collision hash(m1)=hash(m2) and both messages m1 and m2 are of the same size, then it seems that one would also get hash(m1|key|size) = hash(m2|key|size). So, I cannot really see how appending the size will help. (All subject to optimistic assumptions about block sizes, etc.)
- tomp 14y agoIn this sense, every hash function is equally unsafe, even HMAC.
- more_original 14y agoPlease substantiate. An attacker knowing an internal collision of the hash algorithm for m1 and m2 (of the same size...) can construct HMAC(m2,key) from HMAC(m1,key) without knowing the key?