|
|
Log in / Subscribe / Register

GnuPG 2.1.0 "modern" released

GnuPG 2.1.0 "modern" released

Posted Nov 13, 2014 10:01 UTC (Thu) by tialaramex (subscriber, #21167)
In reply to: GnuPG 2.1.0 "modern" released by dd9jn
Parent article: GnuPG 2.1.0 "modern" released

The known pre-image attack for MD5 is only marginally better than brute force. It's a theoretical rather than practical attack, nobody has or could obtain the resources to even try it once as a proof of concept, let alone weaponise it.

I agree that we should migrate off MD5, and SHA-1 too, but migrating off something is not quite the same as it being broken. People have been saying MD5 will "soon" be broken for about a decade now and it's still standing. When the tornado warning siren sounds, you should seek shelter, but it would be a mistake to therefore conclude that each time the siren sounds a tornado hits.

If you have a message sent to you in 1996 with an MD5 MAC, you can in many ways be even _more_ confident in 2014 that it's genuine than you could when you received it in 1996. Because if somebody broke MD5 _before_ 1996 they have so far kept it secret for 18 years, which is quite remarkable and thus very unlikely.


to post comments

GnuPG 2.1.0 "modern" released

Posted Nov 13, 2014 11:23 UTC (Thu) by dd9jn (✭ supporter ✭, #4459) [Link]

Okay. A MAC is very different from a plain hash and even HMAC-MD5 is still believed to be safe. OpenPGP does not use a MAC, though.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds