SHA-1 has been broken. Not a reduced-round version. Not a simplified version. The real thing.
The research team of Xiaoyun Wang, Yiqun Lisa Yin, and Hongbo Yu (mostly from Shandong University in China) have been quietly circulating a paper describing their results:
* collisions in the the full SHA-1 in 2**69 hash operations, much less than the brute-force attack of 2**80 operations based on the hash length.
* collisions in SHA-0 in 2**39 operations.
* collisions in 58-round SHA-1 in 2**33 operations.
quelle: bruce schneier http://www.schneier.com/blog/archives/2 ... roken.html
diskussion der konsequenzen:
http://msgs.securepoint.com/bugtraq/
http://slashdot.org/index.pl?issue=20050215
auf deutsch: http://www.heise.de/newsticker/meldung/56507