3 ms·
Two things: 1. Hashes don't "sign" things (not directly anyway) 2. Hashes aren't unique in theory or practice (using a 256-bit hash on every 257-bit number wi
by silentOpen 12y ago
Two things:
1. Hashes don't "sign" things (not directly anyway)
2. Hashes aren't unique in theory or practice (using a 256-bit hash on every 257-bit number will generate 2^256 collisions by the pigeonhole principle).
- Retric 12y agoHigh quality hashes are unique in practice. Suppose every person generates 1 billion files a second * 7 billion people * 1,000 years = ~3x10 ^ 28 call it 10^29. For a collusion among non identical files using a good 256 bit hash you get ~1/(2^256) * (10^29) * (10^29) = ~1/(2^198). Or 1 chance in ~4 * 10 ^ 59 of finding even one collision.
- nly 12y agoYour math is off a bit[0][1] but you're right, it's a vanishingly small probability of a single collision. This is fairly academic though, when you're talking about an adversary exploiting weaknesses in the algorithm itself, and not a perfect PRF. [0] http://preshing.com/20110504/hash-collision-probabilities/ http://preshing.com/20110504/hash-collision-probabilities/ [1] http://www.wolframalpha.com/input/?i=%281+billion+*+7+billion+per+second+*+1000+years%29^2+%2F+%282+*+2^256%29 http://www.wolframalpha.com/input/?i=%281+billion+*+7+billio...
- Retric 12y agoOps, when counting exponents make sure there in the same base.