atom feed28 messages in org.freebsd.freebsd-securityReport of collision-generation with MD5
FromSent OnAttachments
David WolfskillAug 18, 2004 10:24 am 
Peter C. LaiAug 18, 2004 11:02 am 
ClaudiuAug 18, 2004 11:08 am 
Mike TancsaAug 18, 2004 11:16 am 
Peter C. LaiAug 18, 2004 11:26 am 
Peter C. LaiAug 18, 2004 11:29 am 
mari...@ipad.com.brAug 18, 2004 12:26 pm 
Matthew SeamanAug 18, 2004 1:35 pm 
Chris DohertyAug 18, 2004 1:54 pm 
Brett GlassAug 18, 2004 4:46 pm 
Fernando GleiserAug 18, 2004 5:22 pm 
Borja MarcosAug 19, 2004 1:15 am 
Borja MarcosAug 19, 2004 2:45 am 
Jan GrantAug 19, 2004 3:28 am 
TigAug 19, 2004 7:48 am 
Poul-Henning KampAug 19, 2004 7:53 am 
Mohacsi JanosAug 19, 2004 8:40 am 
George F. CostanzoAug 19, 2004 4:12 pm 
gu...@device.dyndns.orgAug 25, 2004 12:56 pm 
Brooks DavisAug 25, 2004 1:21 pm 
Scott GerhardtAug 25, 2004 3:07 pm 
Mohacsi JanosAug 26, 2004 12:46 am 
Peter JeremyAug 26, 2004 1:09 am 
Oliver EikemeierAug 26, 2004 1:39 am 
Neo-VortexAug 26, 2004 1:54 am 
Jan GrantAug 26, 2004 6:41 am 
Chuck SwigerAug 26, 2004 1:19 pm 
Oliver EikemeierAug 26, 2004 3:08 pm 
Subject:Report of collision-generation with MD5
From:Mike Tancsa (mi@sentex.net)
Date:Aug 18, 2004 11:16:27 am
List:org.freebsd.freebsd-security

At 01:58 PM 18/08/2004, Peter C. Lai wrote:

Well while collisions are cryptographically significant, they don't necessarily impact any operational security of the the hash. (Since the collision merely means that there are possibly two inputs which will hash to the same digest).

As I have no crypto background to evaluate some of the (potentially wild and erroneous) claims being made in the popular press* (eg http://news.com.com/2100-1002_3-5313655.html see quote below), one thing that comes to mind is the safety of ports. If someone can pad an archive to come up with the same MD5 hash, this would challenge the security of the FreeBSD ports system no ?

* "MD5's flaws that have been identified in the past few days mean that an attacker can generate one hash collision in a few hours on a standard PC. To write a specific back door and cloak it with the same hash collision may be much more time intensive. "

---Mike