[Dshield] Crypto Question

John Hardin jhardin at impsec.org
Wed Mar 4 22:12:06 GMT 2009

On Wed, 4 Mar 2009, Frank Knobbe wrote:

> The bigger risk with MD5 is to covertly sneak in changes in plaintext 
> and have them still be valid with the same signature. That's the real 
> problem with MD5, not how much faster you can find a password in an 
> offline attack against a password database.

What I'm wondering is why the file formats and protocols that incorporate 
such signing don't provide for multiple signatures using different crypto 
hash algorithms. Isn't it a good idea to assume that _all_ crypto hash 
algorithm _will_ have collisions (regardless of how expensive those might 
be to find), and your goal is to make that inherent flaw not a problem in 

What's the likelihood that the same collision plaintext would generate the 
same crypto hash using several different algorithms?

While this is interesting, it's rather OT...

