SHA-1 rumors

| Comments (2) | COMSEC
I'm not at CRYPTO but my sources tell me that there may have been some more progress on SHA-1 and that the latest estimates are on the order of 260.x. Anyone with more details please post them in the comments.


I watched the webcast of the rump session, and Christian Rechberger said that they think they will get 2^60ish with a new technique. He did not describe the technique in any detail. Offline, he has told me that there will be papers published.

I also talked to Christian, and I believe him. They've produced a 70-step collision already, and have done an amazing amount of work on developing these attacks. You can't know the outcome of an experiment until you run it, but I'm guessing we'll see a real SHA1 collision in the next year or so.

Leave a comment