Hacker News new | ask | show | jobs
by fivesigma 3398 days ago
This requires the addition of random garbage in the first file which someone will detect anyway. Why not release an infected file with a timebomb malware instead of colliding SHA1? Much cheaper. Still, none of this allows you to attack an already existing torrent.
2 comments

Nobody will detect if a not important metadata field/asciiart is created/changed randomly, so this is a practical attack.
> This requires the addition of random garbage in the first file

Like a third party binary driver?