
Bugtraqmailing list archives
Re: MD5 To Be Considered Harmful Someday
From: Dan Kaminsky <dan () doxpara com>
Date: Wed, 08 Dec 2004 14:03:56 -0800
Brute force work efforts like password cracking tend to be anexponential times a constant -- say, 2^32 operations that take 100mseach. Increasing the complexity of a legitimate password verificationincreases the constant. Interestingly, the more efficient a legitimateverifier becomes, the more efficient your brute forcer is.Not that brute force is the only approach available. There are numerousattacks that might break "pure" MD5 but fail given such massiveoverlapping. There are, however, others that abuse extra rounds togreat effect. For instance, SHA-0 is an 80 round algorithm. Biham'spaper (http://eprint.iacr.org/2004/146/) showed that an 82 round variantis actually much weaker. And Joux's unreleased paper makes it veryclear that simply stacking primitives doesn't create nearly the level ofcombinatorial complexity that you'd expect.Of course, as I've said elsewhere passwords really aren't at allvulnerable to the MD5 attack. But, if they were, extra iterationswouldn't be helpful. Once the first round collided, all future roundswould continue to collide.The algorithm is far more complicated than "raw" MD5. It consists of1000 iterations of MD5 with both output from the previous iterationand the original input (plaintext password and salt) being rolled intothe hash on each iteration.
--Danwww.doxpara.com
Current thread:
- Re: MD5 To Be Considered Harmful Someday,(continued)
- Re: MD5 To Be Considered Harmful SomedayJoel Maslak (Dec 08)
- Re: MD5 To Be Considered Harmful SomedaySteve Friedl (Dec 08)
- RE: MD5 To Be Considered Harmful SomedayDavid Schwartz (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayGandalf The White (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayKeith Oxenrider (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayPaul Wouters (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayDan Kaminsky (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayPaul Wouters (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayAdam Shostack (Dec 09)
- Re: MD5 To Be Considered Harmful SomedayJoel Maslak (Dec 08)
- Re: MD5 To Be Considered Harmful SomedaySolar Designer (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayDan Kaminsky (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayPavel Kankovsky (Dec 09)
- Re: MD5 To Be Considered Harmful SomedaySolar Designer (Dec 13)
- Re: MD5 To Be Considered Harmful SomedayGeorge Georgalis (Dec 08)
- Re: MD5 To Be Considered Harmful SomedayDan Kaminsky (Dec 08)
- Re: MD5 To Be Considered Harmful TodayDan Kaminsky (Dec 08)
- Re: MD5 To Be Considered Harmful TodayPavel Machek (Dec 08)
- Re: MD5 To Be Considered Harmful TodayDan Kaminsky (Dec 08)
