Hacker News new | ask | show | jobs
by amenghra 3275 days ago
It's unfortunate that proof.py doesn't give an example of a message block that leads from h0 to the q._h constant.

I.e. Free-start collisions don't let you create two PDFs with the same sha256 hash.