| From | Sent On | Attachments |
|---|---|---|
| David Wolfskill | Aug 18, 2004 10:24 am | |
| Peter C. Lai | Aug 18, 2004 11:02 am | |
| Claudiu | Aug 18, 2004 11:08 am | |
| Mike Tancsa | Aug 18, 2004 11:16 am | |
| Peter C. Lai | Aug 18, 2004 11:26 am | |
| Peter C. Lai | Aug 18, 2004 11:29 am | |
| mari...@ipad.com.br | Aug 18, 2004 12:26 pm | |
| Matthew Seaman | Aug 18, 2004 1:35 pm | |
| Chris Doherty | Aug 18, 2004 1:54 pm | |
| Brett Glass | Aug 18, 2004 4:46 pm | |
| Fernando Gleiser | Aug 18, 2004 5:22 pm | |
| Borja Marcos | Aug 19, 2004 1:15 am | |
| Borja Marcos | Aug 19, 2004 2:45 am | |
| Jan Grant | Aug 19, 2004 3:28 am | |
| Tig | Aug 19, 2004 7:48 am | |
| Poul-Henning Kamp | Aug 19, 2004 7:53 am | |
| Mohacsi Janos | Aug 19, 2004 8:40 am | |
| George F. Costanzo | Aug 19, 2004 4:12 pm | |
| gu...@device.dyndns.org | Aug 25, 2004 12:56 pm | |
| Brooks Davis | Aug 25, 2004 1:21 pm | |
| Scott Gerhardt | Aug 25, 2004 3:07 pm | |
| Mohacsi Janos | Aug 26, 2004 12:46 am | |
| Peter Jeremy | Aug 26, 2004 1:09 am | |
| Oliver Eikemeier | Aug 26, 2004 1:39 am | |
| Neo-Vortex | Aug 26, 2004 1:54 am | |
| Jan Grant | Aug 26, 2004 6:41 am | |
| Chuck Swiger | Aug 26, 2004 1:19 pm | |
| Oliver Eikemeier | Aug 26, 2004 3:08 pm |
| Subject: | Report of collision-generation with MD5 | |
|---|---|---|
| From: | Mike Tancsa (mi...@sentex.net) | |
| Date: | Aug 18, 2004 11:16:27 am | |
| List: | org.freebsd.freebsd-security | |
At 01:58 PM 18/08/2004, Peter C. Lai wrote:
Well while collisions are cryptographically significant, they don't necessarily impact any operational security of the the hash. (Since the collision merely means that there are possibly two inputs which will hash to the same digest).
As I have no crypto background to evaluate some of the (potentially wild and erroneous) claims being made in the popular press* (eg http://news.com.com/2100-1002_3-5313655.html see quote below), one thing that comes to mind is the safety of ports. If someone can pad an archive to come up with the same MD5 hash, this would challenge the security of the FreeBSD ports system no ?
* "MD5's flaws that have been identified in the past few days mean that an attacker can generate one hash collision in a few hours on a standard PC. To write a specific back door and cloak it with the same hash collision may be much more time intensive. "
---Mike





