Vulnerability Development mailing list archives

Re: Hashes,File protection,etc


From: Jose Nazario <jose () monkey org>
Date: Tue, 15 Oct 2002 10:06:56 -0400 (EDT)

On Mon, 14 Oct 2002, Tony wrote:

Does anyone have a reference/link to any well known md5 vulnerabilities.
I remeber reading something about them awhile back but couldn't google
up anything. Also , are there any arguements *against* using md5? Should
persons be using sha1 instead ?

http://www.dcs.ex.ac.uk/~aba/crypto-papers/dobbertin.ps

that's the one you're probably thinking of. completely theoretical, as i
understand it, meaning md5 is still safe enough for real world use.

___________________________
jose nazario, ph.d.                     jose () monkey org
                                        http://www.monkey.org/~jose/



Current thread: