Talk About Network

Google


Register and Login
Nick
Password
Register create new account Sign up is FREE and you can post replies, new topics, bookmark posts and more!
Recover lost password


Government > Crypto > Re: Basic Quest...
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 7 of 8 Topic 349 of 474
Post > Topic >>

Re: Basic Question

by soneill@[EMAIL PROTECTED] Oct 22, 2006 at 06:40 PM

In article <453a5c6d$0$1142$39db0f71@[EMAIL PROTECTED]
>, Taneli Huuskonen wrote:
> Je 2006-10-20, soneill@[EMAIL PROTECTED]
 <soneill@[EMAIL PROTECTED]
>
skribis:
> 
>> validator for that message.  I believe that an alogrithm like MD5, for
>> example, which produces a 128-bit hash, is guaranteed not to produce
any
>> collisions for strings up to 2^64 bits in length.  If the messages
produced by
>> your system are shorter than that, then the MD5 hash value accompanying
a
>> message can almost certainly be accepted as the correct validator for
that
>> message.
> 
> I'm afraid you're confusing two things.  Any 128-bit hash is guaranteed
> to produce collisions for some strings no longer than 129 bits.  On the
> other hand, if you pick substantially less than 2^64 different strings
> at random, no matter what their lengths, then a good 128-bit hash is
> unlikely to produce collisions among the strings.  The exact meaning of
> "substantially less" can be calculated given the exact meaning of
> "unlikely" and vice versa.
> 
> Taneli Huuskonen

You're right about the confusion.  It's been a while since I read the
description of MD5, so I misremembered what Rivest said about the
probablility
of collisions.  I found my copy of RFC 1321, and in his summary he
_conjectures_ that finding two messages with the same hash is on the order
of
2^64 operations, and that finding a message with a given hash is on the
order
of 2^128 operations.  That was in 1992, before any method of forcing a
collision had been found, so the validity of his conjectures may be open
to
question.  OTOH, a ha****ng function like SHA-256 has no known
vulnerabilities
at present, so a message authenticated with it would seem to have almost
no
chance of being false or in error.

SJO
 




 8 Posts in Topic:
Basic Question
"on3_person" &l  2006-10-07 01:37:08 
Re: Basic Question
soneill@[EMAIL PROTECTED]  2006-10-08 15:51:10 
Re: Basic Question
Hagen Ladwig <hal22@[E  2006-10-18 17:08:57 
Re: Basic Question
Anne & Lynn Wheeler &  2006-10-18 11:36:04 
Re:Basic Question
soneill@[EMAIL PROTECTED]  2006-10-20 20:40:01 
Re: Basic Question
Taneli Huuskonen <tane  2006-10-21 17:44:13 
Re: Basic Question
soneill@[EMAIL PROTECTED]  2006-10-22 18:40:11 
Re: Basic Question
Maarten Bodewes <maart  2006-10-28 17:07:50 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
tan12V112 Fri Dec 5 1:16:22 CST 2008.