SHA-1/MD5 Cracked

w1z4rd

Karmic Sangoma
Joined
Jan 17, 2005
Messages
52,146
Reaction score
8,340
Location
127.0.0.1
Hades1010 writes to mention an article in the Epoch Times (a Chinese newspaper) about a brilliant Chinese professor who has cracked her fifth encryption scheme in ten years. This one's a doozy, too: she and her team have taken out the SHA-1 scheme, which includes the (highly thought of) MD5 algorithm. As a result, the U.S. government and major corporations will cease using the scheme within the next few years. From the article: " These two main algorithms are currently the crucial technology that electronic signatures and many other password securities use throughout the international community. They are widely used in banking, securities, and e-commerce. SHA-1 has been recognized as the cornerstone for modern Internet security. According to the article, in the early stages of Wang's research, there were other data encryption researchers who tried to crack it. However, none of them succeeded. This is why in 15 years Hash research had become the domain of hopeless research in many scientists' minds. "

http://it.slashdot.org/article.pl?sid=07/01/20/1936257
 
These were cracked by her in 2005 or before not so? Why the sudden interest - or did I miss something?
 
what I want to know is even thouhgt if may have been cracked, does that mean that even if you are using random salt in your encryption is it still "un-safe"?
 
MD5/SHA-1 are used to check the authenticity of Data (For example , the MD5 sum of a file from then web) its a secure CRC check formula.

Changing 1 bit in the original data will result in the MD5 being completely different, but it cant tell you which byte has changed - nor recover the tampered byte.
 
Interesting nevertheless. It's not as though the hash is now completely insecure.

http://www.heise-security.co.uk/articles/75686

If an attack is successful with far fewer attempts than in the brute force method, the procedure is considered cracked. According to Schneier, this is exactly what the Chinese research group has accomplished: they are said to have developed a method of finding a collision with 2^69 operations instead of 2^80.

That's about "about 590 million billion operations" according to Yin at:

http://news.zdnet.com/2100-1009_22-5598536.html
 
Top
Sign up to the MyBroadband newsletter
X