[56580] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cfrg] Applications of target collisions: Pre or post-dating

daemon@ATHENA.MIT.EDU (Alfonso De Gregorio)
Fri Oct 27 08:29:07 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Fri, 27 Oct 2006 08:09:20 -0400
From: Alfonso De Gregorio <adg@crypto.lo.gy>
To: "Weger, B.M.M. de" <b.m.m.d.weger@TUE.nl>,
	"Steven M. Bellovin" <smb@cs.columbia.edu>
Cc: cryptography@metzdowd.com, cfrg@ietf.org, hash-forum@nist.gov,
	ietf-pkix@imc.org
In-Reply-To: <DFA3206A564B80499B87B89B49BCD31365B8D1@EXCHANGE3.campus.tue.nl>

Hi Steven, hi Benne,

Yes, this is a sweet and sour truth. We are not getting closer to
preimage attacks. We are getting more far away from considering preimage
and second-preimage resistance sufficient hash-function requirements for
the real-world security of some protocols.

Cheers,

-- Alfonso              http://crypto.lo.gy


Weger, B.M.M. de wrote:
>> So how close are we getting to first or second preimage attacks?
>>     
>
> As far as we know, not one bit closer. 
> Best known attack on MD5 preimage resistance still is brute force. 
>
> You may interpret our result as enlarging the applicability of 
> collision attacks. In that sense the gap to preimage attacks has 
> diminished. But we have no measure available to tell by how much.
>
> Grtz,
> Benne de Weger
>   


---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post