Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I hear you regarding infeasibility, though right now there's another article about content hash collisions being used to distribute a tampered-with Mint Linux image (MD5 collisions).

It's "easier" to get the computational resources to fabricate a collision there, of course, but who is to say how much compute power state level adversaries bring to bear?



To be fair, MD5 was broken in 1996. If your content addressable system uses crypto broken 10 years ago, of course, you can't guarantee integrity :-)

who is to say how much compute power state level adversaries bring to bear

Not enough to break modern hash functions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: