Bitcoin Forum
November 11, 2024, 02:11:53 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Collisions for Hash SHA256 will kill Bitcoin.  (Read 1628 times)
bellicose (OP)
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 263


Sovryn - 300-500% APY on USDT Deposit


View Profile
December 06, 2014, 10:38:27 PM
Last edit: December 06, 2014, 11:13:38 PM by bellicose
 #1





Try it your self:

Code:
# wget http://s16.postimg.org/3snukd41x/00313.jpg
# wget http://s10.postimg.org/n3tn1taq1/0046.jpg
# md5sum *
e06723d4961a0a3f950e7786f3766338  00313.jpg
e06723d4961a0a3f950e7786f3766338  0046.jpg

What are you thinking ?


Edit:

Original article: http://natmchugh.blogspot.co.uk/2014/10/how-i-created-two-images-with-same-md5.html

.The DeFi for Bitcoin Platform.            ███   ███
           ███   ███
          ███   ███
         ███   ███
        ███   ███
       ███   ███
      ███   ███
     ███   ███
    ███   ███
   ███   ███
  ███   ███
 ███   ███
███   ███
▄  ▄██████████████████████▄  ▄
 ▀▄ ▀████████████████████▀ ▄▀
  ▀█ ▀████▀ ▄▄            █▀
   ▀█▄ ▀█ ████████████▀ ▄█▀
     ██▄ ▀▀▀▀▀▀▀▀▀███  ██
      ███      ▀█▄ ▀ ▄██
       ███▄ ▀█████ ▄███
        ████ ▀██▀ ▄███
         ▀███▄  ▄███▀
          ▀███▄ ▀██▀
            ████▄ ▀
             ████▀
              ▀█▀
SOVRYN███   ███
 ███   ███
  ███   ███
   ███   ███
    ███   ███
     ███   ███
      ███   ███
       ███   ███
        ███   ███
         ███   ███
          ███   ███
           ███   ███
            ███   ███
.300% APY on USDT Deposits.
████████████████████████████
████████████████████████████
████████████████████████████
████████▀▀▄██████▄▀▀████████
███████  ▀        ▀  ███████
██████                ██████
█████▌   ███    ███   ▐█████
█████▌   ▀▀▀    ▀▀▀   ▐█████
██████                ██████
███████▄  ▀██████▀  ▄███████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████▀▀  ███████
█████████████▀▀      ███████
█████████▀▀   ▄▄     ███████
█████▀▀    ▄█▀▀     ████████
█████████ █▀        ████████
█████████ █ ▄███▄   ████████
██████████████████▄▄████████
████████████████████████████
████████████████████████████
████████████████████████████
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1540


No I dont escrow anymore.


View Profile
December 06, 2014, 10:51:00 PM
 #2

-snip-
What are you thinking ?

md5sum =|= sha256sum

md5 is broken, we know that.

Im not really here, its just your imagination.
jonald_fyookball
Legendary
*
Offline Offline

Activity: 1302
Merit: 1008


Core dev leaves me neg feedback #abuse #political


View Profile
December 06, 2014, 10:54:08 PM
 #3

not all black guys' hash sum looks alike, stop being racist.

lol, but seriously, 10 seconds of googling tells me that md5 has a high collision rate.

How did you create the collision?

instagibbs
Member
**
Offline Offline

Activity: 114
Merit: 12


View Profile
December 06, 2014, 11:09:07 PM
 #4

lmao this thread.

I'm guessing the pixel values were mutated until a collision occurred, right?

Some stuff: http://stackoverflow.com/questions/933497/create-your-own-md5-collisions
hexafraction
Sr. Member
****
Offline Offline

Activity: 392
Merit: 268

Tips welcomed: 1CF4GhXX1RhCaGzWztgE1YZZUcSpoqTbsJ


View Profile
December 07, 2014, 12:28:40 AM
 #5

This is complete FUD. In addition, all bank vaults are now insecure since I can buy a saw and use it to saw through wood. Logical, right?

I have recently become active again after a long period of inactivity. Cryptographic proof that my account has not been compromised is available.
Remember remember the 5th of November
Legendary
*
Offline Offline

Activity: 1862
Merit: 1011

Reverse engineer from time to time


View Profile
December 07, 2014, 04:12:57 AM
 #6

>Talks about collision and SHA256
>>shows md5 as example

Where is the logic in this? As far as I know there have been collisions in SHA256 up to round 40 I think, not afterwards.

BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
bellicose (OP)
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 263


Sovryn - 300-500% APY on USDT Deposit


View Profile
December 07, 2014, 03:39:28 PM
 #7

This is complete FUD. In addition, all bank vaults are now insecure since I can buy a saw and use it to saw through wood. Logical, right?

Are you sure, sha256 will not be cracked in next 20 years?

What did Satoshi built in Bitcoin, +100 years? 100 years for sha256? My bad. for double sha256.

.The DeFi for Bitcoin Platform.            ███   ███
           ███   ███
          ███   ███
         ███   ███
        ███   ███
       ███   ███
      ███   ███
     ███   ███
    ███   ███
   ███   ███
  ███   ███
 ███   ███
███   ███
▄  ▄██████████████████████▄  ▄
 ▀▄ ▀████████████████████▀ ▄▀
  ▀█ ▀████▀ ▄▄            █▀
   ▀█▄ ▀█ ████████████▀ ▄█▀
     ██▄ ▀▀▀▀▀▀▀▀▀███  ██
      ███      ▀█▄ ▀ ▄██
       ███▄ ▀█████ ▄███
        ████ ▀██▀ ▄███
         ▀███▄  ▄███▀
          ▀███▄ ▀██▀
            ████▄ ▀
             ████▀
              ▀█▀
SOVRYN███   ███
 ███   ███
  ███   ███
   ███   ███
    ███   ███
     ███   ███
      ███   ███
       ███   ███
        ███   ███
         ███   ███
          ███   ███
           ███   ███
            ███   ███
.300% APY on USDT Deposits.
████████████████████████████
████████████████████████████
████████████████████████████
████████▀▀▄██████▄▀▀████████
███████  ▀        ▀  ███████
██████                ██████
█████▌   ███    ███   ▐█████
█████▌   ▀▀▀    ▀▀▀   ▐█████
██████                ██████
███████▄  ▀██████▀  ▄███████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████▀▀  ███████
█████████████▀▀      ███████
█████████▀▀   ▄▄     ███████
█████▀▀    ▄█▀▀     ████████
█████████ █▀        ████████
█████████ █ ▄███▄   ████████
██████████████████▄▄████████
████████████████████████████
████████████████████████████
████████████████████████████
hexafraction
Sr. Member
****
Offline Offline

Activity: 392
Merit: 268

Tips welcomed: 1CF4GhXX1RhCaGzWztgE1YZZUcSpoqTbsJ


View Profile
December 07, 2014, 04:27:32 PM
 #8

This is complete FUD. In addition, all bank vaults are now insecure since I can buy a saw and use it to saw through wood. Logical, right?

Are you sure, sha256 will not be cracked in next 20 years?

What did Satoshi built in Bitcoin, +100 years? 100 years for sha256? My bad. for double sha256.

It doesn't seem that you understand actual cryptography very much. There is a possible ~40-round preimage attack on SHA256 (once, not twice as in mining). There are more than 40 rounds. In addition, none of these preimage attacks actually extend to be able to find a preimage that matches the correct structure of a Bitcoin coinbase+nonce, let alone over two hashings, even if they did manage to actually "break" sha256. Even if you do find a preimage that lets you get a hash matching the current difficulty, that preimage will be garbage for you as it won't be constructed to have a valid block header that will match correctly to pay you coins.

I have recently become active again after a long period of inactivity. Cryptographic proof that my account has not been compromised is available.
bellicose (OP)
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 263


Sovryn - 300-500% APY on USDT Deposit


View Profile
December 07, 2014, 07:59:25 PM
 #9

@hexafraction, Are you really thinking that this attack on md5 differ from mining of Bitcoin? I'm talking about brute-force.

.The DeFi for Bitcoin Platform.            ███   ███
           ███   ███
          ███   ███
         ███   ███
        ███   ███
       ███   ███
      ███   ███
     ███   ███
    ███   ███
   ███   ███
  ███   ███
 ███   ███
███   ███
▄  ▄██████████████████████▄  ▄
 ▀▄ ▀████████████████████▀ ▄▀
  ▀█ ▀████▀ ▄▄            █▀
   ▀█▄ ▀█ ████████████▀ ▄█▀
     ██▄ ▀▀▀▀▀▀▀▀▀███  ██
      ███      ▀█▄ ▀ ▄██
       ███▄ ▀█████ ▄███
        ████ ▀██▀ ▄███
         ▀███▄  ▄███▀
          ▀███▄ ▀██▀
            ████▄ ▀
             ████▀
              ▀█▀
SOVRYN███   ███
 ███   ███
  ███   ███
   ███   ███
    ███   ███
     ███   ███
      ███   ███
       ███   ███
        ███   ███
         ███   ███
          ███   ███
           ███   ███
            ███   ███
.300% APY on USDT Deposits.
████████████████████████████
████████████████████████████
████████████████████████████
████████▀▀▄██████▄▀▀████████
███████  ▀        ▀  ███████
██████                ██████
█████▌   ███    ███   ▐█████
█████▌   ▀▀▀    ▀▀▀   ▐█████
██████                ██████
███████▄  ▀██████▀  ▄███████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████▀▀  ███████
█████████████▀▀      ███████
█████████▀▀   ▄▄     ███████
█████▀▀    ▄█▀▀     ████████
█████████ █▀        ████████
█████████ █ ▄███▄   ████████
██████████████████▄▄████████
████████████████████████████
████████████████████████████
████████████████████████████
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1043


#Free market


View Profile
December 07, 2014, 08:01:57 PM
 #10

This is complete FUD. In addition, all bank vaults are now insecure since I can buy a saw and use it to saw through wood. Logical, right?

Are you sure, sha256 will not be cracked in next 20 years?

What did Satoshi built in Bitcoin, +100 years? 100 years for sha256? My bad. for double sha256.

Maybe in the next few years ( 20-40 years) we will have a new technology , but at the moment the "code" is strong.
hexafraction
Sr. Member
****
Offline Offline

Activity: 392
Merit: 268

Tips welcomed: 1CF4GhXX1RhCaGzWztgE1YZZUcSpoqTbsJ


View Profile
December 07, 2014, 11:59:13 PM
 #11

@hexafraction, Are you really thinking that this attack on md5 differ from mining of Bitcoin? I'm talking about brute-force.

Well, yes, bruteforce is what is going on this minute, at hundreds (if not thousands) of pools. At 1 exahash/sec over the world (much higher than what is today), the hash space is 1.15792089E59. Granted, a birthday problem might exist, but at the current difficulty (and 10 minutes per accepted hash) it will be sufficiently rare that it won't pose a problem. MD5 is twice-as-short, and truly broken.

I have recently become active again after a long period of inactivity. Cryptographic proof that my account has not been compromised is available.
P4man
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500



View Profile
December 10, 2014, 10:47:34 AM
 #12

Collide this then:
28fb9fbd8d2d6e97ee177c5bf1dbfd1070b677ed8908aaf041e231720aef64d2

MrTeal
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
December 10, 2014, 05:40:03 PM
 #13

Collide this then:
28fb9fbd8d2d6e97ee177c5bf1dbfd1070b677ed8908aaf041e231720aef64d2


Code:
                                                                        ____
                                                                   _||__|  |  ______   ______   ______
                                                                  (        | |      | |      | |      |
 28fb9fbd8d2d6e97ee177c5bf1dbfd1070b677ed8908aaf041e231720aef64d2 /-()---() ~ ()--() ~ ()--() ~ ()--()
lynn_402
Sr. Member
****
Offline Offline

Activity: 462
Merit: 253


View Profile
December 10, 2014, 06:31:43 PM
 #14

This is complete FUD. In addition, all bank vaults are now insecure since I can buy a saw and use it to saw through wood. Logical, right?

Are you sure, sha256 will not be cracked in next 20 years?

What did Satoshi built in Bitcoin, +100 years? 100 years for sha256? My bad. for double sha256.

Maybe in the next few years ( 20-40 years) we will have a new technology , but at the moment the "code" is strong.

And when the "code" won't be strong anymore, it will simply be updated. That's one of the best things about Bitcoin.
Bizmark13
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
December 11, 2014, 07:12:57 AM
 #15

And when the "code" won't be strong anymore, it will simply be updated. That's one of the best things about Bitcoin.

That would be the ideal scenario but since the Bitcoin network is decentralized, it might not be as easy. In such a case, a hard fork would be required. Unless every single miner switches to the new fork, you would have two different chains both calling themselves the real "Bitcoin". Once the current encryption algorithm is broken, there could even be multiple encryption algorithms vying to be the successor of SHA-256. If this happens then there would be multiple versions of Bitcoin.
zmiley
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
December 11, 2014, 09:50:27 AM
 #16

I'm thinking it would make more sense if you showed collisions for SHA256 instead Roll Eyes https://bitcointalk.org/index.php?topic=120473.0
DarkHyudrA
Legendary
*
Offline Offline

Activity: 1386
Merit: 1000


English <-> Portuguese translations


View Profile
December 11, 2014, 10:45:52 AM
 #17

IF there was an easy way to make collisions for SHA256 right?
Because, md5 is old and only used to be a checksum hashing algorithm, it isn't made to be unique and secure.

English <-> Brazilian Portuguese translations
bellicose (OP)
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 263


Sovryn - 300-500% APY on USDT Deposit


View Profile
December 15, 2014, 12:45:47 AM
 #18

I'm thinking it would make more sense if you showed collisions for SHA256 instead Roll Eyes https://bitcointalk.org/index.php?topic=120473.0

nice post.

This thread finished with this link: https://en.bitcoin.it/wiki/Contingency_plans#SHA-256_is_broken

Looks like this is most constructive and laconic answer.


This is what called "Raisin" of Bitcoin, it is bringing the theory of cryptography's hardening-core to the real world.

An attacker with power of large country possibly unable to crack sha256 today. Than more Bitcoin will cost in price, than merrier than harder will looks cryptography embedded into it.
Who is the concerned person? Possible, it is current mass-media stars and players on this board, it is Onion-Narco-Bosses FBI, it is NSA. Because, sha256 is NSA's child. And everything apart from.

In the end, USA NSA shall not hinder the existence of coins. It is their "Alert-System", much better than cross-words in newspapers.

.The DeFi for Bitcoin Platform.            ███   ███
           ███   ███
          ███   ███
         ███   ███
        ███   ███
       ███   ███
      ███   ███
     ███   ███
    ███   ███
   ███   ███
  ███   ███
 ███   ███
███   ███
▄  ▄██████████████████████▄  ▄
 ▀▄ ▀████████████████████▀ ▄▀
  ▀█ ▀████▀ ▄▄            █▀
   ▀█▄ ▀█ ████████████▀ ▄█▀
     ██▄ ▀▀▀▀▀▀▀▀▀███  ██
      ███      ▀█▄ ▀ ▄██
       ███▄ ▀█████ ▄███
        ████ ▀██▀ ▄███
         ▀███▄  ▄███▀
          ▀███▄ ▀██▀
            ████▄ ▀
             ████▀
              ▀█▀
SOVRYN███   ███
 ███   ███
  ███   ███
   ███   ███
    ███   ███
     ███   ███
      ███   ███
       ███   ███
        ███   ███
         ███   ███
          ███   ███
           ███   ███
            ███   ███
.300% APY on USDT Deposits.
████████████████████████████
████████████████████████████
████████████████████████████
████████▀▀▄██████▄▀▀████████
███████  ▀        ▀  ███████
██████                ██████
█████▌   ███    ███   ▐█████
█████▌   ▀▀▀    ▀▀▀   ▐█████
██████                ██████
███████▄  ▀██████▀  ▄███████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
████████████████████████████
█████████████████▀▀  ███████
█████████████▀▀      ███████
█████████▀▀   ▄▄     ███████
█████▀▀    ▄█▀▀     ████████
█████████ █▀        ████████
█████████ █ ▄███▄   ████████
██████████████████▄▄████████
████████████████████████████
████████████████████████████
████████████████████████████
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!