DEF CON 25 - Elie Bursztein - How We Created the First SHA 1 Collision

In this talk, we recount how we found the first SHA-1 collision. We delve into the challenges we faced from developing a meaningful payload, to scaling the c...

DEF CON 25 -  Elie Bursztein - How We Created the First SHA 1 Collision
DEFCONConference
40.5K views • Aug 7, 2017
DEF CON 25 -  Elie Bursztein - How We Created the First SHA 1 Collision

About this video

In this talk, we recount how we found the first SHA-1 collision. We delve into the challenges we faced from developing a meaningful payload, to scaling the computation to that massive scale, to solving unexpected cryptanalytic challenges that occurred during this endeavor.

We discuss the aftermath of the release including the positive changes it brought and its unforeseen consequences. For example it was discovered that SVN is vulnerable to SHA-1 collision attacks only after the WebKit SVN repository was brought down by the commit of a unit-test aimed at verifying that Webkit is immune to collision attacks.

Building on the Github and Gmail examples we explain how to use counter-cryptanalysis to mitigate the risk of a collision attacks against software that has yet to move away from SHA-1. Finally we look at the next generation of hash functions and what the future of hash security holds.

Tags and Topics

Browse our collection to discover more content in these categories.

Video Information

Views

40.5K

Likes

451

Duration

37:17

Published

Aug 7, 2017

User Reviews

4.4
(8)
Rate:

Related Trending Topics

LIVE TRENDS

Related trending topics. Click any trend to explore more videos.