ππππ ππ»π demystifying hash collisions
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Show slide in full page or toggle automatic source change | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
You probably think when reading this: “MD5 is already broken!”. Yes, it’s possible to create two different files with the same MD5 in a few seconds, or make two arbitrary files get the same MD5 in a few hours, but it has some limited impact.
Since MD5 is considered broken by experts, it’s now out of scope for research, and yet these two attacks are probably not scary enough so developers still think that MD5 is good to index or verify files.
This talk is a joint effort between Marc Stevens and Ange Albertini, associating the best known cryptographic attacks with new file format manipulations, and will present instant collisions of many common file types, and help you understand how it’s done and their impact, which hopefully will convince everyone to kill MD5 for good.
SHA1 is covered too, but the impact of existing attacks is more limited at this stage.
Speaker
Ange Albertini
Bio
Author of Corkami
Other media in the channel "2019"
- 989 views, 7 this year, 1 this monthPatrOwl - Orchestrating SecOps with an open-source SOAR platformJuly 3rd, 2019
- 139 views, 3 this year, 1 this monthBetter curl !July 3rd, 2019
- 114 views, 12 this yearManaging a growing fleet of WiFi routers combining OpenWRT, WireGuard, Salt and ZabbixJuly 3rd, 2019
- 33 views, 1 this yearNo IT security without Free SoftwareJuly 3rd, 2019
- 34 views, 1 this yearD4 Project - Design and Implementation of an Open Source Distributed and Collaborative Security MonitoringJuly 3rd, 2019
- 15 viewsProgramming research, a missed opportunity for secure and libre software?July 3rd, 2019