• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Whoah. MD5 cracked!

Status
Not open for further replies.

Nerevar

they call me "Man Gravy".
not cool.

Pretty soon we're going to see viruses spreading through bittorrent now, I'm sure :(
 

Phoenix

Member
An MD5 break is HUGE... though not particularly new, you could hack them before - they just took a while. Anyone who wanted to hack a torrent stream could have done it a little bit a go.
 

maharg

idspispopd
Yeah. Obviously, eventually any individual hash algorithm will be reduced to uselessness. Hashes should really be a moving target. People shouldn't stick with them longer than they have to, and software should be designed to be flexible in this area. Since hashes are only useful for validity checking, it should be possible to move easily from one to another as new data is generated.

Of course, an ideal solution may be to start double hashing things so that you not only have to crack one hash, but two, and then make a collision string that matches BOTH. That would be a challenge.

And of course, as far as I know, even this shouldn't cause a problem with properly implemented HMACs (hash(hash(shared_secret) . hash(random_string))), since in order to properly collide with a hash, a) you need to know the hash and b) the hash needs to stay stable, and b) is not true with HMACs even if a) is.
 

Shompola

Banned
aaaaa0 said:
SHA1 is also showing signs of weakness, though for now it's probably still secure.

you know SHA1 is not the only one showing weaknesses. Even the new AES wich uses SHA-256 for verification is showing weaknesses so early in its lifetime. But it's still secure.
 

Phoenix

Member
Just don't expect it to protect any information you don't want to get out in the open. These hash collisions are the death knell for any encryption format - usually they mean that the people with more hardware at their disposal (governments) have already broken those encryptions in reasonable time.
 
Status
Not open for further replies.
Top Bottom