[109950] in cryptography@c2.net mail archive
Re: PlayStation 3 predicts next US president
daemon@ATHENA.MIT.EDU (James A. Donald)
Wed Dec 5 17:11:58 2007
Date: Tue, 04 Dec 2007 11:28:17 +1000
From: "James A. Donald" <jamesd@echeque.com>
To: William Allen Simpson <william.allen.simpson@gmail.com>
CC: cryptography@metzdowd.com, hash-forum@nist.gov
In-Reply-To: <475408DD.2080401@gmail.com>
Dirk-Willem van Gulik wrote:
>> Keep in mind that the notary is still 'careful' --
>> effectively they sign the hash -- rather than the
>> document; and state either such (e.g. in the case of
>> some software/code where you do not hand over the
>> actual code) or state that _a_ document was presented
>> with said hash.
William Allen Simpson wrote:
> And that makes all the difference. The digital notary
> is not certifying the original document. You
> described the notary generating its own tuples
> (credentials as presented, the hash, a timestamp, and
> a notarized declaration that such was presented).
> There is no problem, and the described attack does not
> apply.
The described attack does apply: The notary has
complied with normal procedures and with the rules, but
the rules and procedure fail to have the desired effect,
because an MD5 hash lacks the desired properties.
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com