[109622] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

RE: PlayStation 3 predicts next US president

daemon@ATHENA.MIT.EDU (Weger, B.M.M. de)
Sun Dec 2 15:24:34 2007

Date: Sun, 2 Dec 2007 18:10:37 +0100
In-Reply-To: <4752E28C.9080204@gmail.com>
From: "Weger, B.M.M. de" <b.m.m.d.weger@TUE.nl>
To: "William Allen Simpson" <william.allen.simpson@gmail.com>
Cc: <cryptography@metzdowd.com>,
	<hash-forum@nist.gov>

Hi William,

> > ... We say so on
> > the website. We did show this hiding of collisions for other data=20
> > formats, such as X.509 certificates
>=20
> More interesting.  Where on your web site?  I've long abhorred the
> X.509 format, and was a supporter of a more clean alternative.

See http://www.win.tue.nl/hashclash/TargetCollidingCertificates/

> > Our real work is chosen-prefix collisions combined with=20
> > multi-collisions. This is crypto, it has not been done before,
>=20
> Certainly it was done before!=20

I was referring to MD5. Apart from that, I'd be interested in
seeing references to older work on chosen-prefix multicollisions.

> What *would* be crypto is the quantification of where MDx=20
> currently falls on the computational spectrum.

Our first chosen-prefix collision attack has complexity of about
2^50, as described in our EuroCrypt 2007 paper. This has been=20
considerably improved since then. In the full paper that is in
preparation we'll give details of those improvements.

Grtz,
Benne

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post