Bitcoin Forum
June 28, 2024, 06:57:14 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Can SHA256 have a backdoor?  (Read 660 times)
thejaytiesto (OP)
Legendary
*
Offline Offline

Activity: 1358
Merit: 1014


View Profile
January 30, 2016, 04:21:27 PM
 #1

I was reading this thread:

https://bitcointalk.org/index.php?topic=1345897.0

And I considered the possibility of hashing algorithm used in Bitcoin having some sort of backdoor. There has been some articles in certain websites talking about this too, which lead to the conspiracy theories with your favorite 3 letter agencies. I want to know what are the chances that this is certain and someone that is technically sound to give this any credit or discard it as absolutely tinfoilhat nonsense.
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
January 30, 2016, 04:39:09 PM
 #2

You should ignore anyone who starts these kinds of threads or people who seriously believe in these conspiracy theories. These people obviously have nothing better to do in their lives (flat Earth believers anyone?) which implies a lack of education as well. Don't let them get to you.

And I considered the possibility of hashing algorithm used in Bitcoin having some sort of backdoor. There has been some articles in certain websites talking about this too, which lead to the conspiracy theories with your favorite 3 letter agencies. I want to know what are the chances that this is certain and someone that is technically sound to give this any credit or discard it as absolutely tinfoilhat nonsense.
Anyhow, there is always a possibility of this. Now calculating the odds here would be quite difficult. If you ask me, tt is a very tiny possibility since someone would have most likely discovered the backdoor/flaw by now. You should not be worried about this. If SHA256 does appear to be broken (e.g. in the news; evidence of someone tempering with it in Bitcoin) the whole financial system would most likely collapse and the world goes into chaos. Bitcoin would be the least of your worries then. Remember that most of these institutions (e.g. Banks) use SHA256.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
watashi-kokoto
Sr. Member
****
Offline Offline

Activity: 682
Merit: 269



View Profile
January 30, 2016, 05:20:12 PM
 #3

And I considered the possibility of hashing algorithm used in Bitcoin having some sort of backdoor. There has been some articles in certain websites talking about this too, which lead to the conspiracy theories with your favorite 3 letter agencies. I want to know what are the chances that this is certain and someone that is technically sound to give this any credit or discard it as absolutely tinfoilhat nonsense.

What type of Backdoor? Collision? Partial Collision? Second pre image attack?

Are you aware that SHA256 and RIPEMD160 are the most heavily scrutinized cryptographic hash function out there?

This is the whole thing:
http://www.opensource.apple.com/source/zfs/zfs-59/zfs_kext/zfs/sha256.c
Just one table and two procedures. Care to explain to us what may be hidden in there?
franky1
Legendary
*
Offline Offline

Activity: 4270
Merit: 4534



View Profile
January 30, 2016, 05:28:14 PM
 #4

This is the whole thing:
http://www.opensource.apple.com/source/zfs/zfs-59/zfs_kext/zfs/sha256.c
Just one table and two procedures. Care to explain to us what may be hidden in there?

not quite 2 procedures.. check the <includes>..

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
watashi-kokoto
Sr. Member
****
Offline Offline

Activity: 682
Merit: 269



View Profile
January 30, 2016, 05:35:53 PM
 #5

Let's talk. What would they do? Open that file and change one of the numbers? Then fake all books about crypto and update it on all websites?
jonald_fyookball
Legendary
*
Offline Offline

Activity: 1302
Merit: 1004


Core dev leaves me neg feedback #abuse #political


View Profile
January 30, 2016, 05:41:28 PM
 #6

Backdoor is doubtful.  

Read this.

https://bitcointalk.org/index.php?topic=598903.5




RIPEMD-160 and SHA-256 are well understood Merkle–Damgard designs which have been extensively studied for over a decade.  So I believe ECDSA will be weakened long before either of the hashing algorithms.

Soros Shorts
Donator
Legendary
*
Offline Offline

Activity: 1617
Merit: 1012



View Profile
January 30, 2016, 05:49:59 PM
 #7

What type of Backdoor? Collision? Partial Collision? Second pre image attack?

"Decryption" backdoor - recover first preimage from hash.  Grin
watashi-kokoto
Sr. Member
****
Offline Offline

Activity: 682
Merit: 269



View Profile
January 30, 2016, 05:53:40 PM
 #8

Backdoor is doubtful.  


You're right.

Let me just add, as a reference, these people have been testing crypto hash functions in the lab, SHA256 since 2004.

http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.htm

So for example they tested in 2004 the 234 F-Secure® Cryptographic Library for Windows 2000 . If you are interested you can buy this product and test if it's the indeed the same function Bitcoin uses. Protip: yes
watashi-kokoto
Sr. Member
****
Offline Offline

Activity: 682
Merit: 269



View Profile
January 30, 2016, 05:55:12 PM
 #9

What type of Backdoor? Collision? Partial Collision? Second pre image attack?

"Decryption" backdoor - recover first preimage from hash.  Grin





Yes and they secretly mine using it Grin That explains the high difficulty Grin
Erkallys
Legendary
*
Offline Offline

Activity: 1120
Merit: 1004



View Profile
January 30, 2016, 06:12:12 PM
 #10

No, I don't think that it is possible. A lot more things than Bitcoin run on SHA-256. If Bitcoin was manipulated this way, we'll simply swicth to another cryptocurrency. However, this would the chaos Cheesy !
franky1
Legendary
*
Offline Offline

Activity: 4270
Merit: 4534



View Profile
January 30, 2016, 07:39:24 PM
 #11

No, I don't think that it is possible. A lot more things than Bitcoin run on SHA-256. If Bitcoin was manipulated this way, we'll simply swicth to another cryptocurrency. However, this would the chaos Cheesy !
but in some ways signature hashing of sha256 can be manipulated to give false readings.
   hash length extension attack

so although sha256 is safe in regards to how bitcoin uses it.. other applications have been misused

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
Erkallys
Legendary
*
Offline Offline

Activity: 1120
Merit: 1004



View Profile
January 30, 2016, 07:44:14 PM
 #12

No, I don't think that it is possible. A lot more things than Bitcoin run on SHA-256. If Bitcoin was manipulated this way, we'll simply swicth to another cryptocurrency. However, this would the chaos Cheesy !
but in some ways signature hashing of sha256 can be manipulated to give false readings.
   hash length extension attack

so although sha256 is safe in regards to how bitcoin uses it.. other applications have been misused

So, if I understood correctly your message, that's only Bitcoin that make a proper use of SHA-256 ?
franky1
Legendary
*
Offline Offline

Activity: 4270
Merit: 4534



View Profile
January 30, 2016, 08:07:56 PM
 #13

No, I don't think that it is possible. A lot more things than Bitcoin run on SHA-256. If Bitcoin was manipulated this way, we'll simply swicth to another cryptocurrency. However, this would the chaos Cheesy !
but in some ways signature hashing of sha256 can be manipulated to give false readings.
   hash length extension attack

so although sha256 is safe in regards to how bitcoin uses it.. other applications have been misused

So, if I understood correctly your message, that's only Bitcoin that make a proper use of SHA-256 ?

no. other things do too.. but some dont.

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!