3 ms·
Yes. But, they look for another input that has the same hash and for which they also have other secret information. For example, a PGP public key with the same
by vabmit 14y ago
Yes. But, they look for another input that has the same hash and for which they also have other secret information. For example, a PGP public key with the same hash (Fingerprint) for which they have a valid private key thereby affording them a working "collision" key pair. Obviously, very difficult.
There are a wide array of attacks. Using the method just described and the existence of a hash collision to fake a signature, rather than a key pair, in some cases can be much easier. Depending upon the protocol and procedures used, it may also be possible to use a different method such as providing the true authorized signer with any content that shares a collision with something you'd like the authorized signer to sign (but that they would not normally sign). This can be especially true when the signing procedure is fully automated (For example, some CA's SSL certificate acquisition process is fully automated).
The reason that the collision is important is because many cryptosystem implementations (and humans of course) use hashes as unique identifiers of key pair material (PGP Keys & PKI certs).