Hacker News new | ask | show | jobs
by maligree 3397 days ago
"On the edge"

"A contrived collision on MD5 in 2004 got perfected to a single block collision in 2010 [1]" so they'd have at least years to fix it were they using md5?

He says they'll migrate, but it's no reason to go crazy. If anything, calmness of this sort is what we need more of (this industry, anyway... we go crazy about stuff way too much).

2 comments

As someone who has done "security" full time before - there's nothing worse than the "Security By Jumping Up And Down Like An Excited Monkey" policy.

Fix what's broken, no doubt. But stay rational and look at the problem from all perspectives.

Sha1 was already a questionable idea in 2005 when git came out, because it was then already understood to have fundamental flaws.

https://www.schneier.com/blog/archives/2005/02/cryptanalysis...