Re: About git and the use of SHA-1

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Geoffrey Irving
Date: Tuesday, April 29, 2008 - 8:59 am

On Tue, Apr 29, 2008 at 8:42 AM, Nicolas Pitre <nico@cam.org> wrote:

Here's the standard scenario for a hash collision attack, with
parties, A, B, and C:

1. C, the malicious one, computes the standard two pdfs with matching
sha1 hashes.
2. C sends the valid pdf to B through a git commit, and B signs it with a tag.
3. C grabs the signature, and then forwards the "signed" commit to A,
but substitutes the invalid pdf with the same hash.

The fact that git will check for hash collisions within one repository
is nice, but it doesn't significantly increase the security of git
against hash collision attacks.

Geoffrey
--
To unsubscribe from this list: send the line "unsubscribe git" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
About git and the use of SHA-1, Henrik Austad, (Mon Apr 28, 9:29 am)
Re: About git and the use of SHA-1, Daniel Barkalow, (Mon Apr 28, 12:34 pm)
Re: About git and the use of SHA-1, Henrik Austad, (Mon Apr 28, 2:29 pm)
Re: About git and the use of SHA-1, Daniel Barkalow, (Mon Apr 28, 3:15 pm)
Re: About git and the use of SHA-1, Andreas Ericsson, (Mon Apr 28, 11:38 pm)
Re: About git and the use of SHA-1, Russ Dill, (Tue Apr 29, 12:09 am)
Re: About git and the use of SHA-1, Andreas Ericsson, (Tue Apr 29, 12:21 am)
Re: About git and the use of SHA-1, Sverre Rabbelier, (Tue Apr 29, 4:05 am)
Re: About git and the use of SHA-1, Andreas Ericsson, (Tue Apr 29, 5:27 am)
Re: About git and the use of SHA-1, Dmitry Potapov, (Tue Apr 29, 5:41 am)
Re: About git and the use of SHA-1, Jurko Gospodnetić, (Tue Apr 29, 5:46 am)
Re: About git and the use of SHA-1, Paolo Bonzini, (Tue Apr 29, 6:05 am)
Re: About git and the use of SHA-1, Andreas Ericsson, (Tue Apr 29, 7:37 am)
Re: About git and the use of SHA-1, Andreas Ericsson, (Tue Apr 29, 7:41 am)
Re: About git and the use of SHA-1, Paolo Bonzini, (Tue Apr 29, 7:52 am)
Re: About git and the use of SHA-1, Tom Widmer, (Tue Apr 29, 8:02 am)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 8:34 am)
Re: About git and the use of SHA-1, Nicolas Pitre, (Tue Apr 29, 8:42 am)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 8:59 am)
Re: About git and the use of SHA-1, Russ Dill, (Tue Apr 29, 9:21 am)
Re: About git and the use of SHA-1, Russ Dill, (Tue Apr 29, 9:24 am)
Re: About git and the use of SHA-1, Daniel Barkalow, (Tue Apr 29, 9:27 am)
Re: About git and the use of SHA-1, Nicolas Pitre, (Tue Apr 29, 9:39 am)
Re: About git and the use of SHA-1, Tom Widmer, (Tue Apr 29, 10:08 am)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 10:48 am)
Re: About git and the use of SHA-1, Nicolas Pitre, (Tue Apr 29, 10:55 am)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 11:02 am)
Re: About git and the use of SHA-1, Matthieu Moy, (Tue Apr 29, 11:17 am)
Re: About git and the use of SHA-1, Fredrik Skolmli, (Tue Apr 29, 11:23 am)
Re: About git and the use of SHA-1, Daniel Barkalow, (Tue Apr 29, 11:41 am)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 1:31 pm)
Re: About git and the use of SHA-1, Fredrik Skolmli, (Tue Apr 29, 1:50 pm)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 2:39 pm)
Re: About git and the use of SHA-1, Fredrik Skolmli, (Tue Apr 29, 2:52 pm)
Re: About git and the use of SHA-1, Martin Langhoff, (Tue Apr 29, 7:58 pm)
Re: About git and the use of SHA-1, Geoffrey Irving, (Tue Apr 29, 10:18 pm)
Re: About git and the use of SHA-1, David Brown, (Tue Apr 29, 10:47 pm)
Re: About git and the use of SHA-1, Martin Langhoff, (Tue Apr 29, 10:56 pm)