Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.advocacy > #351075

Re: LOL underestimated

From owl <owl@rooftop.invalid>
Newsgroups comp.os.linux.advocacy
Subject Re: LOL underestimated
Date 2016-04-20 22:06 +0000
Organization O.W.L.
Message-ID <ghjdu03.a09uh3@rooftop.invalid> (permalink)
References (3 earlier) <20160420203110.1b2edf85@maxa-pc> <ghdmjbd.lo3@rooftop.invalid> <20160420232546.4804cf6f@maxa-pc> <ghjmbnjc03.are@rooftop.invalid> <nf8tc6$f5c$1@dont-email.me>

Show all headers | View raw


Peter Köhlmann <peter-koehlmann@t-online.de> wrote:
> owl wrote:
> 
>> Melzzzzz <mel@zzzzz.com> wrote:
>>> On Wed, 20 Apr 2016 21:13:16 +0000 (UTC)
>>> owl <owl@rooftop.invalid> wrote:
>>> 
>>>> Melzzzzz <mel@zzzzz.com> wrote:
>>>> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC)
>>>> > owl <owl@rooftop.invalid> wrote:
>>>> >   
>>>> >> 
>>>> >> I'm simultaneously running an attack on a particular hash over the
>>>> >> entire address space (those eight small windows in the vid).
>>>> >>   
>>>> > 
>>>> > https://eprint.iacr.org/2006/105
>>>> > Tunnels in Hash Functions: MD5 Collisions Within a Minute
>>>> 
>>>> Unless I'm misunderstanding things, that's just generating collision
>>>> pairs.  Correct me if I'm wrong, but I assume that all attacks
>>>> against a hash still require a dictionary of hashes (which is what
>>>> I'm generating).
>>>> 
>>> 
>>> If you find collision of particular length, you have probable
>>> solution...
>> 
>> Length of what?
>> Can you give me a layman's executive summary of how the described
>> approach can reveal the original input given only the known hash?
> 
> There is none. The MD5 collisions just give another set of data which will 
> return the same MD5 hash. You don't get a peek at the original data
> 
> For that very reason linux packages protected by MD5 are still safe, because 
> a "forged" package would not be runable in any way. There is no way to alter 
> a program (with the intent of introducing malware) and expecting to get the 
> original MD5 hash. All the supercomputers existing don't have enough time to 
> compute that before crumbling to rust and sand

So would you say that the approach I'm taking, i.e. a lookup table, is
the best approach?

Back to comp.os.linux.advocacy | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 15:10 +0000
  Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-20 16:55 +0000
    Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 17:25 +0000
      Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-20 18:45 +0000
        Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-20 18:47 +0000
          Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:05 +0000
            Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-25 19:07 +0000
              Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-25 21:16 +0000
        Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 20:51 +0200
  Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 19:19 +0200
    Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 17:34 +0000
      Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 20:31 +0200
        Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:13 +0000
          Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:20 +0200
            Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:29 +0000
              Re: LOL underestimated Me Sham <osirus47@yahoo.com> - 2016-04-20 14:33 -0700
                Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:58 +0200
                Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:04 +0000
          Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:25 +0200
            Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:41 +0000
              Re: LOL underestimated Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-04-20 23:50 +0200
                Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:06 +0000
                Re: LOL underestimated Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-04-21 08:54 +0200
                Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 17:12 +0000
              Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:50 +0200
                Re: LOL underestimated Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-04-20 23:51 +0200
                Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:59 +0200
                Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:10 +0000
                Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-21 00:11 +0200
                Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:19 +0000
                Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-21 00:57 +0200
                Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 00:07 +0000
      Re: LOL underestimated DFS <nospam@dfs.com> - 2016-04-20 23:17 -0400
        Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 03:49 +0000
          Re: LOL underestimated DFS <nospam@dfs.com> - 2016-04-21 10:27 -0400
            Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 16:26 +0000

csiph-web