4 ms·
Wouldn’t “x”.join(…) be enough?
by __david__ 2y ago
Wouldn’t “x”.join(…) be enough?
- Terr_ 2y agoOnly if you can guarantee it that possible for someone to sneak in an input that already contains those "x" characters.
- blueflow 2y agoPossibly not: "x".join({'aa'+'bxb'}) == "x".join({'aaxb','b'}) The separator should not be able to show up in the inputs.
- deathanatos 2y agoThis is why I raised an eyebrow when TFA wrote, > When I saw this, I wondered why it has several inner hashes instead of using the raw string. The inner hash constrains the alphabet on that portion of the input to the outer hash, thus easily letting you use a separator like "," or "|" without having to deal with the alphabet of the inner input, since it gets run through a hash. That is, for a very simplistic use case of two inputs a & b: sha256(','.join( [sha256(a), sha256(b)] )) If one is familiar with a git tree or commit object, this shouldn't be unfamiliar. Now … whether that's why there was an inner hash at that point in TFA's code is another question, but I don't think one should dismiss inner hashes altogether.
- blueflow 2y agoI'm not dismissing them, inner hashes returning a hexadecimal string fulfills the "the separator should not be able to show up in the inputs" constraint.
- bmicraft 2y agoI could see an attack vector here based on file/directory names or the full path. Different inputs could lead to the same order of enumerated checksums.
- __david__ 2y agoThanks—that makes sense. I was struggling to come up with an example that would fail but I was just unconsciously assuming the separator wasn’t showing up naturally in the individual parts instead of explicitly considering that as a prerequisite.