all messages for Emacs-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: "Petros Travioli" <travioli@gmx.de>
To: "Andreas Schwab" <schwab@linux-m68k.org>, 13949@debbugs.gnu.org
Subject: bug#13949: Aw: Re: bug#13949: fill-paragraph is buggy, but using MD5 is even more buggy
Date: Mon, 28 Mar 2016 15:29:19 +0200	[thread overview]
Message-ID: <trinity-d7553a86-4d25-4c99-9770-4b469ac6fd97-1459171759869@3capp-gmx-bs57> (raw)
In-Reply-To: <87r3euhozp.fsf@linux-m68k.org>

> > But that's exactly what happens when you are using hash functions to
> > verify buffer equality, just with a more complicated mathematical
> > formulation and at a slightly different scale.
> >
> > So don't use hash functions to a two-sided correct answer to test buffer
> > equality. For a one-sided answer (if hash(x) != hash(y) then x != y), you
> > are fine.
> 
> There is a difference between a hash function and a cryptographic hash
> function.  An inportant property of a cryptographic hash function is the
> avalanche effect, that means a small change in the plaintext will result
> in a big change in the hash value.  That makes such a hash function
> suitable for the reverse condition x != y => hash(x) != hash(y), with a
> very high probability of being true.
> 
So far most old crypto functions have been broken. There is no doubt this will happen to any newer one sooner or later. If any single person would lose his work because of a random collision, this is an argument agains crypto hash functions.

I am citing RFC 6151 (https://tools.ietf.org/html/rfc6151):

"MD5 is no longer acceptable where collision resistance is required..."

If the developers (I think, it was Eli who embraced the patch) are so sure about collision freedom:

Eli, if you are so sure about MD5, please post your password MD5 hash here with login data and a consent that anyone is allowed to hack in. I do not want to go into prison. Then wait for, say, 1 week.





  reply	other threads:[~2016-03-28 13:29 UTC|newest]

Thread overview: 116+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-03-13 22:09 bug#13949: 24.3.50; `fill-paragraph' should not always put the buffer as modified Dani Moncayo
2013-03-14  3:43 ` Eli Zaretskii
2013-03-14  7:57   ` Dani Moncayo
2013-03-14 10:27     ` Andreas Röhler
2013-03-14 17:50       ` Eli Zaretskii
2013-03-14 13:38     ` Stefan Monnier
2013-03-14 17:53       ` Eli Zaretskii
2013-03-14 18:34         ` Andreas Röhler
2013-03-14 18:49           ` Eli Zaretskii
2013-03-14 19:01             ` Andreas Röhler
2013-03-14 19:19               ` Eli Zaretskii
2013-03-14 19:32                 ` Andreas Röhler
2013-03-15  4:02         ` Stefan Monnier
2013-03-15  7:27           ` Dani Moncayo
2013-03-14 17:46     ` Eli Zaretskii
2013-03-14 18:34       ` Dani Moncayo
2016-03-22 10:50 ` bug#13949: 24.4.1; " Jaakov
2016-03-22 11:39   ` Andreas Röhler
2016-03-22 16:15   ` Eli Zaretskii
2016-03-22 17:40     ` Jaakov
2016-03-22 17:56       ` Michael Heerdegen
2016-03-22 18:07         ` Drew Adams
2016-03-22 18:23           ` Michael Heerdegen
2016-03-22 18:31       ` Eli Zaretskii
2016-03-22 18:42         ` Jaakov
2016-03-26 23:46           ` John Wiegley
2016-03-27  3:31             ` Óscar Fuentes
2016-03-27  7:44               ` Andreas Röhler
2016-03-27 15:09                 ` Óscar Fuentes
2016-03-28  8:01                   ` Andreas Röhler
2016-03-27  8:42               ` Andreas Schwab
2016-03-27 14:59                 ` Óscar Fuentes
2016-03-27 15:15                   ` Drew Adams
2016-03-27 15:21                     ` Óscar Fuentes
2016-03-27 18:53                     ` Drew Adams
2016-03-27 15:13                 ` Drew Adams
2016-03-27 14:56               ` Eli Zaretskii
2016-03-27 15:28                 ` Óscar Fuentes
2016-03-27 15:42                   ` Dmitry Gutov
2016-03-27 15:52                     ` Óscar Fuentes
2016-03-27 15:57                       ` Lars Magne Ingebrigtsen
2016-03-27 16:21                         ` Óscar Fuentes
2016-03-27 16:33                           ` Lars Magne Ingebrigtsen
2016-03-27 16:46                             ` Óscar Fuentes
2016-03-27 16:58                               ` Lars Magne Ingebrigtsen
2016-03-27 18:22                                 ` Drew Adams
2016-03-27 15:29                 ` Óscar Fuentes
2016-03-27 15:58                   ` Eli Zaretskii
2016-03-27 16:05                     ` Óscar Fuentes
2016-03-27 16:12                       ` Eli Zaretskii
2016-03-27 16:37                         ` Óscar Fuentes
2016-03-27 16:50                           ` Eli Zaretskii
2016-03-27 17:30                             ` Óscar Fuentes
2016-03-27 17:51                               ` Eli Zaretskii
2016-03-27 16:38                         ` Óscar Fuentes
2016-03-27 17:00                           ` Lars Magne Ingebrigtsen
2016-03-27 16:14                       ` Lars Magne Ingebrigtsen
2016-03-27 15:46                 ` Lars Magne Ingebrigtsen
2016-03-27 16:04                   ` Eli Zaretskii
2016-03-27 16:11                     ` Lars Magne Ingebrigtsen
2016-03-27 16:18                       ` Eli Zaretskii
2016-03-27 16:28                         ` Lars Magne Ingebrigtsen
2016-03-28 10:39                           ` Lars Magne Ingebrigtsen
2016-03-28 11:27                             ` Lars Magne Ingebrigtsen
2016-03-28 11:32                               ` Lars Magne Ingebrigtsen
2016-03-28 11:39                                 ` Lars Magne Ingebrigtsen
2016-03-28 13:46                               ` Lars Magne Ingebrigtsen
2016-03-28 15:29                               ` Eli Zaretskii
2016-03-28 15:39                                 ` Lars Magne Ingebrigtsen
2016-03-28 15:15                             ` Eli Zaretskii
2016-03-28 15:39                               ` Lars Magne Ingebrigtsen
2016-03-28 15:52                                 ` Óscar Fuentes
2016-03-28 16:29                                   ` Lars Magne Ingebrigtsen
2016-03-28 17:04                                     ` Eli Zaretskii
2016-03-28 17:07                                       ` Lars Magne Ingebrigtsen
2016-03-28 17:37                                         ` Eli Zaretskii
2016-03-28 17:45                                           ` Lars Magne Ingebrigtsen
2016-03-28 18:17                                             ` Eli Zaretskii
2016-03-28  8:09                 ` Andreas Röhler
2016-03-27 15:28               ` Dmitry Gutov
2016-03-27 15:35                 ` Óscar Fuentes
2016-03-27 15:46                   ` Dmitry Gutov
2016-03-27 15:53                     ` Lars Magne Ingebrigtsen
2016-03-27 20:24                       ` Dmitry Gutov
2016-03-27 21:05                         ` Óscar Fuentes
2016-03-27 21:20                           ` Dmitry Gutov
2016-03-27 22:03                             ` Óscar Fuentes
2016-03-27 15:35                 ` Lars Magne Ingebrigtsen
2016-03-27 15:42                   ` Dmitry Gutov
2016-03-27 15:50                     ` Lars Magne Ingebrigtsen
2016-03-27 20:27                       ` Dmitry Gutov
2016-03-27 21:36                         ` Jaakov
2016-03-27 16:08                   ` Jaakov
2016-03-22 17:52     ` Jaakov
2016-03-22 18:40 ` bug#13949: (no subject) Jaakov
2016-03-22 18:56   ` Eli Zaretskii
2016-03-22 19:07     ` Jaakov
2016-03-22 19:10       ` Eli Zaretskii
2016-03-22 19:53         ` Jaakov
2016-03-22 20:07           ` Eli Zaretskii
2016-03-22 21:58             ` Jaakov
2016-03-22 22:38               ` Glenn Morris
2016-03-23 15:57                 ` Eli Zaretskii
2016-03-23 17:45                   ` Jaakov
2016-03-26 23:33                 ` John Wiegley
2016-03-23 15:57               ` Eli Zaretskii
2016-03-22 23:44 ` bug#13949: `fill-paragraph' should not always put the buffer as modified Petros Travioli
2016-03-28  4:55 ` bug#13949: fill-paragraph is buggy, but using MD5 is even more buggy Petros Travioli
2016-03-28 10:32   ` Andreas Schwab
2016-03-28 13:29     ` Petros Travioli [this message]
2016-03-28 14:31       ` bug#13949: Aw: " Andreas Schwab
2016-03-28 17:05       ` Eli Zaretskii
2016-03-28 15:16 ` Petros Travioli
2016-03-28 17:05   ` Lars Magne Ingebrigtsen
2016-03-28 17:06   ` Eli Zaretskii
2016-03-28 19:03     ` Petros Travioli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=trinity-d7553a86-4d25-4c99-9770-4b469ac6fd97-1459171759869@3capp-gmx-bs57 \
    --to=travioli@gmx.de \
    --cc=13949@debbugs.gnu.org \
    --cc=schwab@linux-m68k.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/emacs.git
	https://git.savannah.gnu.org/cgit/emacs/org-mode.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.