So many people are getting the SHA1 story wrong. With the collision that Google released, *anyone* can create colliding PDFs for *free*.
-
-
Replying to @marcan42
You can take the two sets of 320 bytes that were published, append *anything* to both sets, and they will still have the same hash.
6 replies 105 retweets 105 likes -
So literally anything that parses from the bottom up is fucked?"
1 reply 0 retweets 0 likes -
The specific collision released is only useful for PDFs and for the (few) file formats that parse bottom up (...)
1 reply 1 retweet 3 likes -
(...) *and* can reference prior data with either no header or something in the collision blocks passes for a header.
1 reply 1 retweet 2 likes
I'm not sure if any such formats exist. They probably do, but can't think of one off the top of my head.
0 replies
1 retweet
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.