nanog mailing list archives

Re: SHA1 collisions proven possisble


From: valdis.kletnieks () vt edu
Date: Thu, 23 Feb 2017 18:21:19 -0500

On Thu, 23 Feb 2017 17:40:42 -0500, "Ricky Beam" said:

cost! However this in no way invalidates SHA-1 or documents signed by
SHA-1.

We negotiate a contract with terms favorable to you.  You sign it (or more
correctly, sign the SHA-1 hash of the document).

I then take your signed copy, take out the contract, splice in a different
version with terms favorable to me.  Since the hash didn't change, your
signature on the second document remains valid.

I present it in court, and the judge says "you signed it, you're stuck with
the terms you signed".

I think that would count as "invalidates documents signed by SHA-1", don't you?

Attachment: _bin
Description:


Current thread: