Re: IQ Handling vulnerabilities

"Joe Hildebrand (jhildebr)" <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <CF22F6E5.3993D%[email protected]>
(as chair)
Yes, let's call that off-topic.

(as individual)
I don't believe we have to specify an algorithm, since there are no
interoperability consequences.

On 2/11/14 11:48 AM, "Alexander Holler" <[email protected]> wrote:

>Am 11.02.2014 18:59, schrieb Alexander Holler:
>
>> To play with that hash of hash, is it possible that the hash of a hash
>> is the hash itself? If that ever happens your system will have a
>> problem, so how likely is that? And in the proposed solution it's a bit
>> more difficult, because only the higher 5 bytes of the 20 bytes long
>> hash are used. At least for me, the answer to that isn't obvious.
>
>To become completely offtopic, one could formalize that question to how
>the possibility is that
>
>sha1^n(x) = sha1(x) for 2 < n <= 100
>
>(if you need that 100  IDs in series are unique) and furthermore you
>have to look at the upper 5 bytes. I'm not sure if that is what
>cryptographers usually do look at if they check hash algorithms. So
>argueing with whatever they found out about sha1 doesn't look obvious to
>me.
>
>Regards,
>
>Alexander Holler
>
>_______________________________________________
>xmpp mailing list
>[email protected]
>https://www.ietf.org/mailman/listinfo/xmpp
>


-- 
Joe Hildebrand
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.