3 ms·
It's novel in that I wasn't able to find anyone else who had posted a colliding HMAC pair, and the couple papers people have found have sniffed around but hadn'
by dakami 11y ago
It's novel in that I wasn't able to find anyone else who had posted a colliding HMAC pair, and the couple papers people have found have sniffed around but hadn't quite gotten to the point of "Oh, yeah, compensate for ipad and collide after the first block".
You're correct that it went without saying in that people did not actually say it.
Way to not cite Solar Designer though.
- tptacek 11y agoWhat exactly should he have cited Solar Designer about? If you're going to criticize someone for not citing, and the citation isn't obvious, you should probably provide a link. Are you referring to the key expansion property that Scott mentioned downthread? He cited the appropriate source: the HMAC specification. The properties he's talking about are obvious: the key is zero-padded to the block size and, if longer than the block size, hashed.
- dakami 11y agoYou're right. I'm specifically referring to his attacks. I'm curious if you can find any references to the key expansion / hashing collision before Solar Designer started talking about it a little while ago. If they're obvious you should be able to find dozens of references. Because they're obvious.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- tptacek 11y agoThis took 15 seconds to find: https://eprint.iacr.org/2012/684.pdf https://eprint.iacr.org/2012/684.pdf
- dakami 11y agoI stand corrected, there are in fact a decent number of people who mentioned HMAC(K,X)==HMAC(H(K),X) when len(K)>blocksize. So, you had no reason to cite Solar Designer and I shouldn't have implied you should. Sorry about that! Still interested if you can find an earlier cite for HMAC collision. Most of what I find implies mad crypto cleverness, not this silly little construction.