It gets worse...

Jeremy Allison jra at samba.org
Fri Aug 20 19:33:14 GMT 2004


On Fri, Aug 20, 2004 at 09:30:35PM +0200, Simo Sorce wrote:
> On Fri, 2004-08-20 at 19:30, Jeremy Allison wrote:
> > I don't know if anyone here follows sci.crypt, but it looks
> > like a generic method of finding MD4 collisions has been
> > discovered. No published details yet.
> 
> > "* Weng, Fang, Lai, and Yu have what appears to be a general method for
> >   finding collisions in MD4, MD5, HAVAL-128, and RIPEMD. They
> >   haven't published any details."
> > 
> > This could be very bad for NTLM auth.....
> 
> Have you seen this ?
> 
> MD4,MD5,HAVAL-128,RPEMD:
> http://eprint.iacr.org/2004/199.pdf

Thanks - that's the paper I was referring to. No word yet
on exactly how it is done though.

Jeremy.


More information about the samba-technical mailing list