MD4 second-preimage attack
[email protected] Tue, 21 Feb 2006 14:58:58 -0800
| Newsgroups | gmane.network.librsync.general,gmane.network.rsync.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, A year ago we discussed the strength of the MD4 hash used by rsync and librsync, and one of the points mentioned was that only collision attacks are known on MD4. Well, a recent paper by Wang et al [1] shows a several second preimage attacks. First, there's an algorithm which, given a random message and its MD4 hash, finds another message having the same hash with probability 2^-56. Second, if the attacker can also alter the original message (and thus its hash) slightly, he can find a second message having the same hash with just 2^27 MD4 invocations. Doubtless, even stronger attacks will soon be found. MD4 (with known seed) is thus completely broken, making rsync batch mode and librsync unsafe to use in malicious environments. Please do consider phasing out MD4. The fastest hash function with no interesting known attacks is SHA-256, which is still somewhat expensive (though this can be partially addressed by the meta-hash idea discussed on the librsync list last July, "Re: more info on 25gig files"). SHA-1 may also be OK for a while despite the known collision attacks, and has acceptable speed. Also, as discussed in detail earlier: to thwart some attacks, rsync batch mode and librsync should be fixed to use a random seed. Eran [1] http://www.springerlink.com/openurl.asp?genre=article&issn=0302-9743&volume=3810&spage=1 ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642