Remember, this SHA1 attack is *not* the attack that broke MD5 TLS certs and gave us Flame. *This* attack on MD5 you can run on a smartphone.
-
-
Replying to @marcan42
This SHA1 attack does NOT allow you to collide an innocent-looking file with a malicious file. You need TWO blatantly malicious files.
2 replies 13 retweets 10 likes -
Replying to @marcan42
... of course, if nobody's looking at the hex dump, one of those files might not look malicious when you open it. Hence the PDF trick.
1 reply 3 retweets 5 likes -
Replying to @marcan42
Similarly, you could make two colliding binaries and have them behave differently, but the "evil" code would have to exist in both.
1 reply 6 retweets 8 likes -
Replying to @marcan42
This is the last nail in the "but it isn't broken yet" excuse to keep using SHA-1, so if you haven't *started* migrating yet, start *now*.
1 reply 12 retweets 18 likes -
Replying to @marcan42
Hash attacks 101: preimage=any clean file; chosen prefix=64b of junk in otherwise clean known file; same prefix=both files evil.
1 reply 5 retweets 7 likes -
Replying to @marcan42
preimage=we're screwed (not even MD*2* is preimage-broken); chosen prefix=Flame, git totally broken; same prefix=git safe-ish for code.
2 replies 6 retweets 12 likes -
Replying to @marcan42
If you're putting binary files in Git without carefully vetting their contents, time to start pestering the devs to switch to a better hash.
2 replies 4 retweets 9 likes -
Replying to @marcan42
PNG is binary (in the sense of not text) but has internal CRC. Are these reasonably safe?
1 reply 0 retweets 0 likes -
Replying to @PinoBatch
Hard to contrive a scenario where you could collide a PNG *and* make it into an attack... though not impossible.
1 reply 0 retweets 0 likes
Basically it depends on how the rest of the system reacts to it. E.g. you could append a malicious colliding ZIP.
-
-
Replying to @marcan42 @PinoBatch
Such that if filetype sniffing is involved somewhere then interesting things could happen.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.