http://www.javayou.com (收藏,设为首页)
当你不能再拥有时,你唯一能做的,就是让自己不要忘记 (手机请访问 http://3g.dlog.cn/javayou)

SHA-1 Broken

2005年2月17日(Thursday) 09点07分 作者: 本站原创 天气: 心情: 一般

继MD5被中国山东大学的马小云教授破解后,人们开始改用SHA-1来作为替代算法,但是SHA-1也出事了:

SHA-1 has been broken. Not a reduced-round version. Not a simplified version. The real thing.

The research team of Xiaoyun Wang, Yiqun Lisa Yin, and Hongbo Yu (mostly from Shandong University in China) have been quietly circulating a paper describing their results:

collisions in the the full SHA-1 in 2**69 hash operations, much less than the brute-force attack of 2**80 operations based on the hash length.

collisions in SHA-0 in 2**39 operations.


collisions in 58-round SHA-1 in 2**33 operations.

This attack builds on previous attacks on SHA-0 and SHA-1, and is a major, major cryptanalytic result. It pretty much puts a bullet into SHA-1 as a hash function for digital signatures (although it doesn't affect applications such as HMAC where collisions aren't important).

The paper isn't generally available yet. At this point I can't tell if the attack is real, but the paper looks good and this is a reputable research team.

More details when I have them.

还是同一拨人,文章来自:

http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
http://jroller.com/page/eu/20050216#sha1_is_not_secure
http://www.gadgetguy.de/index.php/2005/02/16/sha_1_has_been_broken

现在还能依赖什么算法???

评论者: aeonsun 2005-2-17 09:11 (Thursday)
如电影所说的一样:“这是一个动荡不安的年代”,我觉得用来形容现在的IT是很适合了,哎 安全--新技术--稳定 怎么抓呢?
姓名: 
邮箱:  {可选}
网址:  {可选} 此评论只有我和写日记的人查阅
校验码: ... <我看不清楚>
网记为您提供手机和互联网同步的个人主页,带给你不一样的体验