{"id":33517,"date":"2019-10-31T21:53:04","date_gmt":"2019-10-31T18:53:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1\/"},"modified":"2019-10-31T21:53:04","modified_gmt":"2019-10-31T18:53:04","slug":"predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1","title":{"rendered":"A more efficient method for determining collision prefixes for SHA-1 has been presented","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Researchers from the French National Institute for Research in Computer Science and Automation (INRIA) and Nanyang Technological University (Singapore) <noindex><a rel=\"nofollow\" href=\"https:\/\/mailarchive.ietf.org\/arch\/msg\/cfrg\/NhiGvOFzcEw108YLwF_ndyfB1k4\">developed<\/a><\/noindex> enhanced <noindex><a rel=\"nofollow\" href=\"https:\/\/eprint.iacr.org\/2019\/459\">the method<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/eprint.iacr.org\/2019\/459.pdf\">attacks<\/a><\/noindex> the SHA-1 algorithm, significantly simplifying the creation of two different documents with identical SHA-1 hashes. The essence of the method is to reduce the operation of a full collision search in SHA-1 to <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9A%D0%BE%D0%BB%D0%BB%D0%B8%D0%B7%D0%B8%D0%BE%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B0%D1%82%D0%B0%D0%BA%D0%B0#%D0%9A%D0%BE%D0%BB%D0%BB%D0%B8%D0%B7%D0%B8%D0%BE%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B0%D1%82%D0%B0%D0%BA%D0%B0_%D1%81_%D0%B7%D0%B0%D0%B4%D0%B0%D0%BD%D0%BD%D1%8B%D0%BC_%D0%BF%D1%80%D0%B5%D1%84%D0%B8%D0%BA%D1%81%D0%BE%D0%BC\">a collision attack with a specified prefix<\/a><\/noindex>, where a collision occurs with certain prefixes, regardless of the other data in the set. In other words, two predefined prefixes can be computed, and if one is attached to one document and the other to the second \u2014 the resulting SHA-1 hashes for these files will be identical.<\/p>\n<p>This type of attack still requires enormous computations, and prefix selection remains more complex than ordinary collision searches, but the practical effectiveness of the result is significantly higher. If previously the fastest method for finding collision prefixes in SHA-1 required about 277.1 operations, the new method reduces the number of computations to a range from 266.9 to 269.4. At this level of computation, the estimated cost of the attack is less than a hundred thousand dollars, which is quite affordable for intelligence agencies and large corporations. For comparison, finding a standard collision requires approximately 264.7 operations.<\/p>\n<p>In <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=46091\">previous<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/shattered.it\/\">demonstration<\/a><\/noindex>  Google's ability to generate different PDF files with the same SHA-1 hash <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=46102\">used<\/a><\/noindex> is a trick that combines two documents into one file, switches the visible layer, and shifts the layer selection mark into the collision occurrence area. With similar resource expenditure (Google spent a year computing on a cluster of 110 GPUs to find the first SHA-1 collision), the new method allows for matching SHA-1 for two arbitrary sets of data. Practically, it enables the preparation of TLS certificates that reference different domains but have identical SHA-1 hashes. This capability allows a rogue certificate authority to create a certificate for a digital signature that can be used to authorize bogus certificates for arbitrary domains. This issue can also be exploited to compromise protocols that rely on the absence of collisions, such as TLS, SSH, and IPsec.<\/p>\n<p>The proposed prefix search strategy for collisions involves breaking down calculations into two stages. The first stage entails searching for blocks that are on the verge of collision by embedding random chain variables into a predefined target set of differences. In the second stage, at the level of individual blocks, the obtained difference chains are matched with the state pairs that lead to collisions, using traditional collision search attack methods. <\/p>\n<p>Although the theoretical possibility of an attack on SHA-1 was proven back in 2005, the first collision was practically <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=46091\">achieved<\/a><\/noindex> in 2017, SHA-1 still remains in use and is covered by certain standards and technologies (TLS 1.2, Git, etc.). The main goal of this work was to provide yet another compelling argument for the immediate discontinuation of SHA-1, especially in certificates and digital signatures.<\/p>\n<p>Additionally, it can be noted <noindex><a rel=\"nofollow\" href=\"https:\/\/eprint.iacr.org\/2019\/474\">publication<\/a><\/noindex> <noindex>results<\/noindex> of the cryptanalysis of block ciphers <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Simon_(cipher)\">SIMON-32\/64<\/a><\/noindex>, developed by the NSA and approved in 2018 as a standard <noindex><a rel=\"nofollow\" href=\"https:\/\/www.iso.org\/ru\/standard\/70388.html\">ISO\/IEC 29167-21:2018<\/a><\/noindex>.<br \/>\nResearchers have developed a method for recovering the private key based on two known pairs of plaintext and ciphertext. With limited computational resources, key cracking takes anywhere from several hours to several days. The theoretical success rate of the attack is estimated to be 0.25, while the practical rate for the existing prototype is 0.025.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50674\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u0433\u043e \u0433\u043e\u0441\u0443\u0434\u0430\u0440\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u0438\u043d\u0441\u0442\u0438\u0442\u0443\u0442\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0439 \u0432 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0442\u0438\u043a\u0435 \u0438 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u043a\u0435 (INRIA) \u0438 \u041d\u0430\u043d\u044c\u044f\u043d\u0441\u043a\u043e\u0433\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 (\u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440) \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0438 \u0443\u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c SHA-1, \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0438\u0439 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u0434\u0432\u0443\u0445 \u0440\u0430\u0437\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0441 \u043e\u0434\u0438\u043d\u0430\u043a\u043e\u0432\u044b\u043c\u0438 \u0445\u044d\u0448\u0430\u043c\u0438 SHA-1. \u0421\u0443\u0442\u044c \u043c\u0435\u0442\u043e\u0434\u0430 \u0432 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u043f\u043e\u043b\u043d\u043e\u0446\u0435\u043d\u043d\u043e\u0433\u043e \u043f\u043e\u0434\u0431\u043e\u0440\u0430 \u043a\u043e\u043b\u043b\u0438\u0437\u0438\u0438 \u0432 SHA-1 \u043a \u043a\u043e\u043b\u043b\u0438\u0437\u0438\u043e\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0435 \u0441 \u0437\u0430\u0434\u0430\u043d\u043d\u044b\u043c \u043f\u0440\u0435\u0444\u0438\u043a\u0441\u043e\u043c, \u043f\u0440\u0438 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043a\u043e\u043b\u043b\u0438\u0437\u0438\u044f \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u0435\u0442 \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-33517","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u0433\u043e \u0433\u043e\u0441\u0443\u0434\u0430\u0440\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u0438\u043d\u0441\u0442\u0438\u0442\u0443\u0442\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0439 \u0432 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0442\u0438\u043a\u0435 \u0438 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u043a\u0435 (INRIA) \u0438 \u041d\u0430\u043d\u044c\u044f\u043d\u0441\u043a\u043e\u0433\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 (\u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440)\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0431\u043e\u043b\u0435\u0435 \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u0444\u0438\u043a\u0441\u043e\u0432 \u043a\u043e\u043b\u043b\u0438\u0437\u0438\u0439 \u0434\u043b\u044f SHA-1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u0433\u043e \u0433\u043e\u0441\u0443\u0434\u0430\u0440\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u0438\u043d\u0441\u0442\u0438\u0442\u0443\u0442\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0439 \u0432 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0442\u0438\u043a\u0435 \u0438 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u043a\u0435 (INRIA) \u0438 \u041d\u0430\u043d\u044c\u044f\u043d\u0441\u043a\u043e\u0433\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 (\u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440)\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:53:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:53:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47A more effective method for determining prefix collisions for SHA-1 has been presented | ProHoster","description":"Researchers from the French National Institute for Research in Computer Science and Automation (INRIA) and Nanyang Technological University (Singapore)","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0431\u043e\u043b\u0435\u0435 \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u0444\u0438\u043a\u0441\u043e\u0432 \u043a\u043e\u043b\u043b\u0438\u0437\u0438\u0439 \u0434\u043b\u044f SHA-1 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u0433\u043e \u0433\u043e\u0441\u0443\u0434\u0430\u0440\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u0438\u043d\u0441\u0442\u0438\u0442\u0443\u0442\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0439 \u0432 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0442\u0438\u043a\u0435 \u0438 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u043a\u0435 (INRIA) \u0438 \u041d\u0430\u043d\u044c\u044f\u043d\u0441\u043a\u043e\u0433\u043e \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 (\u0421\u0438\u043d\u0433\u0430\u043f\u0443\u0440)","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/predstavlen-bolee-effektivnyj-metod-opredeleniya-prefiksov-kollizij-dlya-sha-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:53:04+00:00","article:modified_time":"2019-10-31T18:53:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33517","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 15:37:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:39:23","updated":"2026-01-21 15:37:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/33517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=33517"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/33517\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=33517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=33517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=33517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}