@taviso paper concludes that 50 bits of freedom remain. You should try a bruteforce over that to see if there are higher round collisions ;)
AFAIK Marc's result is the best known on non-reduced forms of SHA-1 (previous best was Wang's R58 single block collision). Exciting stuff!
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.