[183767] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Synful Knock questions...

daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Tue Sep 15 16:01:31 2015

X-Original-To: nanog@nanog.org
To: Jake Mertel <jake.mertel@ubiquityhosting.com>
From: Valdis.Kletnieks@vt.edu
In-Reply-To: <CAOhg=RzB-+r5zxq3doWktLdfs1qTgd4yUaQgX9QSdkyg01_oew@mail.gmail.com>
Date: Tue, 15 Sep 2015 16:01:21 -0400
Cc: nanog list <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

--==_Exmh_1442347281_2221P
Content-Type: text/plain; charset=us-ascii

On Tue, 15 Sep 2015 11:54:30 -0700, Jake Mertel said:
> Indeed -- While there are methods that can be used to "pack" a file so that
> it collides with a desirable checksum, that would be nearly impossible to
> do in this scenario.

Small clarification here.

There are known methods to easily produce two files that have the same MD5
hash, but you have no control over the checksum.

There are not (to my knowledge) ways to tweak a file to produce a specified
MD5 hash.  MD5 is broken, but not *that* broken (yet).  Feel free to point
me at papers if it's been done.

There are ways to easily produce a file with a specified non-crypto-strength
hash like a CRC-32.

So it really matters to be clear on what algorithm is used for the checksum/hash.

--==_Exmh_1442347281_2221P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: Exmh version 2.5 07/13/2001

iQIVAwUBVfh5EQdmEQWDXROgAQJuEw/9GilTzY/cSTXS3OeSFgaYDN18+IywFPP/
UiQ3qfPdvUrLTGhZfj6ktPGEIQKQwYlcmxNsXoRt161w2umw6Cug5PCmY9DaLLMQ
I9IrXhBQrkTpOPrj5v59Xxm5+joL1OgglBwfZq3dcfJcTs5s736gd39QnYEqNAo5
q8OzNVY8uWfNB0SQMV9Q5h8EJbpp2MPI85Df8Wk2SH4Q8Qqtv6KTh58ucDKa1oo+
Kt8gMK7x8b8Rhqr3Shkh61d3HPQuDTXrhWg0nayMXiBhjIBAW2UgNJObxyqjvksF
6ATOMUCJoFvyMjy/Es/PS8vyLs624rsVQdmaDFSJ2CXwrgUK8hAOgPyDBnC6LUj0
pwbtp/puHN2DILqt9YHGb75KjeWKWvhB44UvwwVwAaKCa4OB/1rOQywtJ4R6i5xL
blv1UusHdQfXDDVAbvN1YjLIQ2nXMlI98emVx6m3eWFDOLAWtj3222iS2K/9ZLSF
MOS6yZSSFEclxweklwzN93UeUV8NztFsSP1G2zBZlVb3sHaiC1n2zyIz6Af0YfuZ
H6/lViPaSvZ0D89Ikv57COCumik7K1Ld4FKMPjwdC+qYrhqaP/CWjXvMkTk2HeyS
UV6L5Y9U99t2B4LQKyrFMnAbo7XV6VUNfIGxBXMeAcASzHR/Z8ibRjuIfWErdx1J
3ojsDjP2srg=
=rHq1
-----END PGP SIGNATURE-----

--==_Exmh_1442347281_2221P--

home help back first fref pref prev next nref lref last post