Make your own colliding PDFs: https://alf.nu/SHA1
-
-
Hmm. I hope this can't be easily used to attack git repositories' integrity. Has git got any plans to upgrade from SHA1?
1 reply 0 retweets 0 likes -
The published collision cannot be used to attack Git because Git prefixes blobs with a header.
2 replies 0 retweets 3 likes -
Someone could use the same approach and spend the $100k to compute a Git-targeted prefix collision though.
2 replies 0 retweets 3 likes -
Could they though? I forgot about the prefix - it actually contains the blob length in bytes.
1 reply 0 retweets 0 likes
Sure, it just means the length would have to be constant. Hardly a showstopper.
5:09 AM - 24 Feb 2017
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.