More or less?
Letophoro | 01/22/07
|

More reliable
ken_ballard@... | 01/22/07
|
 
You're wrong by many orders of magnitude.
georgeou | 01/22/07
|
  
Finger prints are even less with today's readers
nucrash | 01/22/07
|
   
far worse ...
zoroaster | 01/22/07
|

Sorry, MUCH LESS. I fixed the sentense in the blog
georgeou | 01/22/07
|
 
2^16 = 65536
rpmyers1 | 01/22/07
|
  
Sorry for the quick and dirty math, meant 24 bits
georgeou | 01/22/07
|
I suppose it depends on how the crack works.
Zogg | 01/22/07
|

Same SHA-1 sum and the same file size.
Henry Miller | 01/22/07
|
 
You can't just tinker with the bits in a compressed archive file.
Zogg | 01/22/07
|
  
uncompress, change then add random stuff until SHA worked?
stevey_d | 01/22/07
|
   
You're making some big leaps
georgeou | 01/22/07
|
    
I don't think you realise how easy it would be
stevey_d | 01/22/07
|
     
Do you have any idea how silly that statement is
georgeou | 01/22/07
|
     
Try this from wikipedia
stevey_d | 01/24/07
|
   
Heh, I'm not afraid of the "brute force" approach
Zogg | 01/22/07
|
    
well you wouldn't use a computer
stevey_d | 01/22/07
|
     
C'mon, now you're getting ridiculous
georgeou | 01/22/07
|
     
Bruce Scheider "this pretty much puts a bullet in SHA-1"
stevey_d | 01/24/07
|

Not even close, it's just a hash collision.
georgeou | 01/22/07
|
Good old lawyers
Erik Engbrecht | 01/22/07
|

Good old lawyers
peter.seattle@... | 01/22/07
|
foreign legal precedent
enduser_z | 01/22/07
|

It's not up to the courts to make that call
georgeou | 01/22/07
|
 
legal precedence
stevey_d | 01/22/07
|
Talk about your great Freudian slips...
pglaskowsky | 01/22/07
|
It Indicates Something Bigger
bcroner | 01/22/07
|

Secure Enough.
dave.leigh@... | 01/22/07
|
 
but why not build around something that has proven to be unbreakable
stevey_d | 01/22/07
|
  
You're confusing a cryptographic hash for encryption.
georgeou | 01/22/07
|
   
george you're assuming you know what I'm saying and you don't
stevey_d | 01/22/07
|
    
No stevey, you've said enough and it's clear you don't even know
georgeou | 01/22/07
|
     
OK "Genius" here it is spelt out for you
stevey_d | 01/24/07
|
Ah sorry for the quick and dirty math
georgeou | 01/22/07
|

DNA test accurate ... perhaps
stevey_d | 01/22/07
|
SHA-1 was marketed as being unbreakable with all computing power in world
stevey_d | 01/22/07
|

Cryptographers aren't marketers
georgeou | 01/22/07
|
 
Federal Information Processing Standard
stevey_d | 01/22/07
|
  
You used the words "unbreakable", which is just wrong
georgeou | 01/22/07
|
   
please don't pigeonhole me
stevey_d | 01/22/07
|
    
And there's your problem
georgeou | 01/22/07
|
     
I complained to a webshop saying SSL was unbreakable for just this reason
stevey_d | 01/24/07
|
     
The problem lies in the computational feasability of the brute force ...
p_msac@... | 01/25/07
|
     
brute force isn't the only way
stevey_d | 01/26/07
|

not so ...
zoroaster | 01/22/07
|
Two years later, it makes news on ZDNet
GW Mahoney | 01/23/07
|

No, that was a different event
georgeou | 01/23/07
|
OTP "needs" a special environment ..
p_msac@... | 01/27/07
|

yes, you're right, topology more difficult
stevey_d | 01/29/07
|