[109622] in cryptography@c2.net mail archive
RE: PlayStation 3 predicts next US president
daemon@ATHENA.MIT.EDU (Weger, B.M.M. de)
Sun Dec 2 15:24:34 2007
Date: Sun, 2 Dec 2007 18:10:37 +0100
In-Reply-To: <4752E28C.9080204@gmail.com>
From: "Weger, B.M.M. de" <b.m.m.d.weger@TUE.nl>
To: "William Allen Simpson" <william.allen.simpson@gmail.com>
Cc: <cryptography@metzdowd.com>,
<hash-forum@nist.gov>
Hi William,
> > ... We say so on
> > the website. We did show this hiding of collisions for other data=20
> > formats, such as X.509 certificates
>=20
> More interesting. Where on your web site? I've long abhorred the
> X.509 format, and was a supporter of a more clean alternative.
See http://www.win.tue.nl/hashclash/TargetCollidingCertificates/
> > Our real work is chosen-prefix collisions combined with=20
> > multi-collisions. This is crypto, it has not been done before,
>=20
> Certainly it was done before!=20
I was referring to MD5. Apart from that, I'd be interested in
seeing references to older work on chosen-prefix multicollisions.
> What *would* be crypto is the quantification of where MDx=20
> currently falls on the computational spectrum.
Our first chosen-prefix collision attack has complexity of about
2^50, as described in our EuroCrypt 2007 paper. This has been=20
considerably improved since then. In the full paper that is in
preparation we'll give details of those improvements.
Grtz,
Benne
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com