Re: IQ Handling vulnerabilities
Dave Cridland <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <CAKHUCzyv1cMiZn9OkAXOeaMs-Ti8Z32K-gjygc1dMM9NVLqVPQ@mail.gmail.com> |
On Tue, Feb 11, 2014 at 4:31 PM, Alexander Holler <[email protected]>wrote: > which I interpret such, that, besides using a hash from hash (so no new > source), the ID consists of just the first 10 characters of the 40 of a > sha1. And then you argument with the collision rate of sha1? > > Oh, I see what you mean now. Yes, on that model the collision would probably happen much sooner. It's a collision space of 2^40, though, so a birthday attack would hit after about 1.3 million stanzas by my calculations. The chance of this causing a problem seems pretty low. Dave. _______________________________________________ xmpp mailing list [email protected] https://www.ietf.org/mailman/listinfo/xmpp