Re: IQ Handling vulnerabilities

Dave Cridland <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <CAKHUCzyv1cMiZn9OkAXOeaMs-Ti8Z32K-gjygc1dMM9NVLqVPQ@mail.gmail.com>
On Tue, Feb 11, 2014 at 4:31 PM, Alexander Holler <[email protected]>wrote:

> which I interpret such, that, besides using a hash from hash (so no new
> source), the ID consists of just the first 10 characters of the 40 of a
> sha1. And then you argument with the collision rate of sha1?
>
>
Oh, I see what you mean now.

Yes, on that model the collision would probably happen much sooner.

It's a collision space of 2^40, though, so a birthday attack would hit
after about 1.3 million stanzas by my calculations. The chance of this
causing a problem seems pretty low.

Dave.

_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.