[110351] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: PlayStation 3 predicts next US president

daemon@ATHENA.MIT.EDU (Francois Grieu)
Mon Dec 10 10:34:00 2007

Date: Mon, 10 Dec 2007 15:11:54 +0100
From: Francois Grieu <fgrieu@gmail.com>
To: <cryptography@metzdowd.com>
CC: William Allen Simpson <william.allen.simpson@gmail.com>
In-Reply-To: <475C9781.5060008@gmail.com>

william.allen.simpson@gmail.com wrote:

>  Dp := any electronic document submitted by some person, converted to its
>        canonical form
>  Cp := a electronic certificate irrefutably identifying the other person
>        submitting the document
>  Cn := certificate of the notary
>  Tn := timestamp of the notary
>  S() := signature of the notary
> 
>  S( MD5(Tn || Dp || Cp || Cn) ).

In this context, the only thing that guards agains an attack by
"some person" is the faint hope that she can't predict the Tn
that the notary will use for a Dp that she submits.

That's because if Tn is known (including chosen) to "some person",
then (due to the weakness in MD5 we are talking about), she can
generate Dp and Dp' such that
  S( MD5(Tn || Dp || Cp || Cn) ) = S( MD5(Tn || Dp' || Cp || Cn) )
whatever Cp, Cn and S() are.

If Tn was hashed after Dp rather than before, poof goes security.


  Francois Grieu

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post