Server Help Forum Index Server Help
Community forums for Subgame, ASSS, and bots
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   StatisticsStatistics   RegisterRegister 
 ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin (SSL) 

Server Help | ASSS Wiki (0) | Shanky.com
MD5 proved broken

 
Post new topic   Reply to topic Printable version
 View previous topic  webmaster Post :: Post I'm back... but I bet noone remembers ...  View next topic  
Author Message
Mine GO BOOM
Hunch Hunch
What What
Hunch Hunch<br>What What


Age:41
Gender:Gender:Male
Joined: Aug 01 2002
Posts: 3615
Location: Las Vegas
Offline

PostPosted: Wed Aug 18, 2004 12:10 pm   Post maybe stupid    Post subject: MD5 proved broken Reply to topic Reply with quote

Note that I did not read the Slashdot article, but instead the SA Thread about it.

Quick summary: They say they can generate a collision within about a hour on a normal computer.

Proof of a collision
Code: Show/Hide
  $ cmp file1.bin file2.bin
  file1.bin file2.bin differ: byte 20, line 1

  $ md5sum file1.bin file2.bin
  a4c0d35c95a63a805915367dcfe6b751  file1.bin
  a4c0d35c95a63a805915367dcfe6b751  file2.bin
Back to top
View users profile Send private message Add User to Ignore List Send email
Mr Ekted
Movie Geek


Gender:Gender:Male
Joined: Feb 09 2004
Posts: 1379
Offline

PostPosted: Wed Aug 18, 2004 12:48 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Scary stuff.
_________________
4,691 irradiated haggis!
Back to top
View users profile Send private message Add User to Ignore List
CypherJF
I gargle nitroglycerin


Gender:Gender:Male
Joined: Aug 14 2003
Posts: 2582
Location: USA
Offline

PostPosted: Wed Aug 18, 2004 1:39 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

ITS THE END OF THE WORLD! lol jk icon_smile.gif
_________________
Performance is often the art of cheating carefully. - James Gosling
Back to top
View users profile Send private message Add User to Ignore List
Cyan~Fire
I'll count you!
I'll count you!


Age:37
Gender:Gender:Male
Joined: Jul 14 2003
Posts: 4608
Location: A Dream
Offline

PostPosted: Wed Aug 18, 2004 4:39 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

But didn't we know this all along? It's not like anyone can actually use this to their advantage unless they're really lucky.
_________________
This help is informational only. No representation is made or warranty given as to its content. User assumes all risk of use. Cyan~Fire assumes no responsibility for any loss or delay resulting from such use.
Wise men STILL seek Him.
Back to top
View users profile Send private message Add User to Ignore List Visit posters website
Mine GO BOOM
Hunch Hunch
What What
Hunch Hunch<br>What What


Age:41
Gender:Gender:Male
Joined: Aug 01 2002
Posts: 3615
Location: Las Vegas
Offline

PostPosted: Wed Aug 18, 2004 10:25 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

The idea was that people knew it was weak, and that collisions were possible, but the chance of someone brute-forcing a matching md5 checksum on data the same length was very slim, and would take many years. They claim that they have a formula in which they can find a matching checksum of almost any data within a hour on a normal machine, not some super-computer.

The fact that it only finds a few bytes off can do harm. Take for example, digital signatures. You run something through the md5sum to create a signature of your object for security reasons, but now there is some method in which some other data, the same length, will have the same checksum.

It is unknown if the formula can be repeated on itself, like creating another same-length dataset for the same checksum. And the fact that they state that SH1 has a theoritical weakness is still scary also.

Just so you know, this is the first example of any data stream with matching MD5. So yes, this is a big deal.
Back to top
View users profile Send private message Add User to Ignore List Send email
Bak
?ls -s
0 in


Age:26
Gender:Gender:Male
Joined: Jun 11 2004
Posts: 1826
Location: USA
Offline

PostPosted: Wed Aug 18, 2004 11:51 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

So I see the digital signature and accept the email someone signed and sent me. Instead of a message, I get random text, what's the harm again?
Back to top
View users profile Send private message Add User to Ignore List AIM Address
Donkano.
Guest


Offline

PostPosted: Wed Aug 18, 2004 11:59 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

What makes me wonder is... What is MD5?
Back to top
CypherJF
I gargle nitroglycerin


Gender:Gender:Male
Joined: Aug 14 2003
Posts: 2582
Location: USA
Offline

PostPosted: Thu Aug 19, 2004 12:04 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

MD5 is a method supposively that was unique to any key it is given; to create a finger print for the data that is parsed into it. When 2 inputs creates the same output; it's become a problem.

Make sense now? lol icon_smile.gif

2 files = same MD5 checksum?(hash?), very bad icon_smile.gif
Back to top
View users profile Send private message Add User to Ignore List
myke
Seasoned Helper


Gender:Gender:Male
Joined: Sep 11 2003
Posts: 142
Offline

PostPosted: Thu Aug 19, 2004 12:59 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

cypher you forgot it means message digest 5 lol
Back to top
View users profile Send private message Add User to Ignore List AIM Address
Display posts from previous:   
Post new topic   Reply to topic    Server Help Forum Index -> Trash Talk All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
View online users | View Statistics | View Ignored List


Software by php BB © php BB Group
Server Load: 377 page(s) served in previous 5 minutes.

phpBB Created this page in 0.644089 seconds : 34 queries executed (88.2%): GZIP compression disabled