Finally a SHA-1 collision. TL;DR: same-prefix collision, don't panic *yet*, but Git better start thinking of SHA-256 and don't trust PDFs.
Hard to contrive a scenario where you could collide a PNG *and* make it into an attack... though not impossible.
-
-
Basically it depends on how the rest of the system reacts to it. E.g. you could append a malicious colliding ZIP.
-
Such that if filetype sniffing is involved somewhere then interesting things could happen.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.