From: “Perry E. Metzger” <perry@piermont.com>
To: cypherpunks@toad.com
Message Hash: 0a00c52bac4abbcbf8745c1632071254757ca3e90c71cc3a6f3373ca78d3f1a0
Message ID: <199607010408.AAA19179@jekyll.piermont.com>
Reply To: N/A
UTC Datetime: 1996-07-01 08:52:47 UTC
Raw Date: Mon, 1 Jul 1996 16:52:47 +0800
From: "Perry E. Metzger" <perry@piermont.com>
Date: Mon, 1 Jul 1996 16:52:47 +0800
To: cypherpunks@toad.com
Subject: MD5 breaks, etc.
Message-ID: <199607010408.AAA19179@jekyll.piermont.com>
MIME-Version: 1.0
Content-Type: text/plain
1) On the question of MD4, it has been demonstrated that one can
generate multiple documents with the same hash -- an example was
given in a paper a while back of two contracts, identical but for
the dollar sum agreed two, with identical MD4 hashes. That
demonstrates that MD4 is useless.
2) Hans Dobbertin on May 2nd released a short paper that circulated
widely on the net describing collisions in the MD5 compression
function. Several people have asked me for references on this. I
cannot give you anything -- all I have is postscript of the
document, which had not been published in any journal when I last
checked. However, the result is widely known. MD5 is *not*
something that should be trusted going forward, and I hope the next
version of PGP uses SHA-1.
Perry
Return to July 1996
Return to ““Perry E. Metzger” <perry@piermont.com>”
1996-07-01 (Mon, 1 Jul 1996 16:52:47 +0800) - MD5 breaks, etc. - “Perry E. Metzger” <perry@piermont.com>