• A more real SHA-1 hack; ten days computime

    Author
    Topic
    #502573

    DHE, RC4 and now SHA-1 (though the attack took ten days of computing time on GPU cards, but we all know what that eventually means). And yet, the businesses want your credit card and other personal info, but don’t want to upgrade their servers encryption algorithms:

    SHA-1 Freestart Collision

    Schneier on Security
    Oct. 8, 2015

    There’s a new cryptanalysis result against the hash function SHA-1:

    Abstract: We present in this article a freestart collision example for SHA-1, i.e., a collision for its internal compression function. This is the first practical break of the full SHA-1, reaching all 80 out of 80 steps, while only 10 days of computation on a 64 GPU cluster were necessary to perform the attack. This work builds on a continuous series of cryptanalytic advancements on SHA-1 since the theoretical collision attack breakthrough in 2005. ….

    [Continue reading here: https://www.schneier.com/blog/archives/2015/10/sha-1_freestart.html%5D

    Viewing 3 reply threads
    Author
    Replies
    • #1531473

      That’s why we use SHA-256.

      cheers, Paul

      • #1531792

        I use a little free program from https://raylin.wordpress.com/downloads/md5-sha-1-checksum-utility/ to check most of my downloads, especially the large .iso files for Windows and Linux OSes, gives more comparison ability but I do have to remember to get the hash from the download page if offered. The hash number is embedded in the download by the publisher.

        Before you wonder "Am I doing things right," ask "Am I doing the right things?"
    • #1531785

      If you are allowed that option.

    • #1531925

      Nice program Berton

      Just thinking, ooops I thought it would be nice to have a D/L manager that could auto check against ‘copied’ hashtag, never came across one!

      :cheers:

      BTW not on Gizmos list…

      🍻

      Just because you don't know where you are going doesn't mean any road will get you there.
      • #1531928

        Nice program Berton

        Just thinking, ooops I thought it would be nice to have a D/L manager that could auto check against ‘copied’ hashtag, never came across one!

        :cheers:

        BTW not on Gizmos list…

        Automatic would be nice. The closest I’ve come is on Linux Mint 17.x, has a choice on right-click menu of an .iso file to check but still need the hash from the download site to compare with.

        Before you wonder "Am I doing things right," ask "Am I doing the right things?"
    • #1531960

      Haha trying real hard to stay away from Linux. Still have a couple of bootable Usb HDD and SSD available but I am way too dumb,fussy and impatient for Linux. :cheers:

      🍻

      Just because you don't know where you are going doesn't mean any road will get you there.
      • #1531972

        Haha trying real hard to stay away from Linux. Still have a couple of bootable Usb HDD and SSD available but I am way too dumb,fussy and impatient for Linux. :cheers:

        I usually play with Linux LiveDVDs so the computer doesn’t get changed. I only have it installed on a Dell Optiplex 755 Desktop because it is an extra computer and always interested in a replacement for WinXP that don’t meet later system requirements, does pretty good. Use Firefox and LibreOffice, both included in the install disc.

        Before you wonder "Am I doing things right," ask "Am I doing the right things?"
    Viewing 3 reply threads
    Reply To: A more real SHA-1 hack; ten days computime

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: