[Madlug] slightly OT: cell coverage and plans

Mark Felder felderado at gmail.com
Sun Jan 3 18:15:44 CST 2010


On Sun, Jan 03, 2010 at 06:07:56PM -0600, Marcin Antkiewicz wrote:
> SHA1 is theoretically broken, but still very useful in practice. Last
> time I checked
> it was something in the order of 2**60something ops to calculate a
> collision, but

I'm quite aware of all of this. The point is, if you're pretend you've got a tinfoil hat on you might as well act the part :) Broken is broken -- we all know that the calculation time on it is incredibly expensive, but that's just assuming there's no other methods that are hidden from the public, right? :)

I personally am not afraid of using SHA1, but I do shy away from MD5. When possible and if it's not too expensive I do bump it up to SHA256 which will make it quite unreasonable to break.

I also agree with you about the courts -- their use of MD5 shows the government needs some proper guidance in law for IT standards.


Mark


More information about the Madlug mailing list