compare-by-hash (was Re: sharing /etc/passwd)

Colin Percival colin.percival at wadham.ox.ac.uk
Tue Sep 28 09:27:35 PDT 2004


David Schultz wrote:
> ...  In fact, recent results have
> raised some concerns about SHA-1 (http://eprint.iacr.org/2004/146/).

I have yet to hear any justification for claims that the SHA-0 attack
implies a weakness in SHA-1.  The paper you cite even says "Due to the
additional rotate instruction, the results of this paper are not
applicable to SHA-1".

Colin Percival


More information about the freebsd-security mailing list