Friday, May 26, 2006

MD5 không còn an toàn

Hic... tin đã cũ, nhưng giờ mới biết. Thực khó tin là có ngày MD5 lại bị phá vỡ.

Slashdot | Practical Exploits of Broken MD5 Algorithm:
jose parinas writes "A practical sample of an MD5 exploit can be found, with source code included,in codeproject, a site for .Net programmers.
The intent of the demos is to demonstrate a very specific type of attack that exploits the inherent trust of an MD5 hash. It's sort of a semi-social engineering attack.
At Microsoft, the MD5 hash functions are banned.

The main problem is that the attack is directed to the distribution of software process, as you can understand reading the paper, Considered Harmful Someday. Some open source programs, like RPM, use MD5, and in many open source distributions MD5 is used as check sum."