{"type":"rich","version":"1.0","author_name":"npub1uvtfvcegcn9kds68r8he57emc480vqtx8t22kpsctxgjxae44gvsksaxrt","author_url":"https://nostr.ae/npub1uvtfvcegcn9kds68r8he57emc480vqtx8t22kpsctxgjxae44gvsksaxrt","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-04-01\n📝 Original message:On 2 April 2013 00:10, Will \u003cwill at phase.net\u003e wrote:\n\n\u003e The threat of a SHA1 collision attack to insert a malicious pull request\n\u003e are tiny compared with the other threats - e.g. github being compromised,\n\u003e one of the core developers' passwords being compromised, one of the core\n\u003e developers going rogue, sourceforge (distribution site) being compromised\n\u003e etc etc... believe me there's a lot more to worry about than a SHA1\n\u003e attack...\n\u003e\n\u003e Not meaning to scare, just to put things in perspective - this is why we\n\u003e all need to peer review each others commits and keep an eye out for\n\u003e suspicious commits, leverage the benefits of this project being open source\n\u003e and easily peer reviewed.\n\u003e\n\nVery good points, and I think you're absolutely right.\n\nBut just running the numbers, to get the picture, based of scheiner's\nstatistics:\n\nhttp://www.schneier.com/blog/archives/2012/10/when_will_we_se.html\n\nWe're talking about a million terrahashes = 2^60 right?\n\nWith the block chain, you only have a 10 minute window, but with source\ncode you have a longer time to prepare.\n\nCouldnt this be done with an ASIC in about a week?\n\n\n\n\u003e\n\u003e Will\n\u003e\n\u003e\n\u003e On 1 April 2013 23:52, Melvin Carvalho \u003cmelvincarvalho at gmail.com\u003e wrote:\n\u003e\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e On 1 April 2013 20:28, Petr Praus \u003cpetr at praus.net\u003e wrote:\n\u003e\u003e\n\u003e\u003e\u003e An attacker would have to find a collision between two specific pieces\n\u003e\u003e\u003e of code - his malicious code and a useful innoculous code that would be\n\u003e\u003e\u003e accepted as pull request. This is the second, much harder case in the\n\u003e\u003e\u003e birthday problem. When people talk about SHA-1 being broken they actually\n\u003e\u003e\u003e mean the first case in the birthday problem - find any two arbitrary values\n\u003e\u003e\u003e that hash to the same value. So, no I don't think it's a feasible attack\n\u003e\u003e\u003e vector any time soon.\n\u003e\u003e\u003e\n\u003e\u003e\u003e Besides, with that kind of hashing power, it might be more feasible to\n\u003e\u003e\u003e cause problems in the chain by e.g. constantly splitting it.\n\u003e\u003e\u003e\n\u003e\u003e\n\u003e\u003e OK, maybe im being *way* too paranoid here ... but what if someone had\n\u003e\u003e access to github, could they replace one file with one they had prepared at\n\u003e\u003e some point?\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e\u003e\n\u003e\u003e\u003e\n\u003e\u003e\u003e On 1 April 2013 03:26, Melvin Carvalho \u003cmelvincarvalho at gmail.com\u003e wrote:\n\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e  I was just looking at:\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e https://bitcointalk.org/index.php?topic=4571.0\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e I'm just curious if there is a possible attack vector here based on the\n\u003e\u003e\u003e\u003e fact that git uses the relatively week SHA1\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Could a seemingly innocuous pull request generate another file with a\n\u003e\u003e\u003e\u003e backdoor/nonce combination that slips under the radar?\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Apologies if this has come up before ...\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e ------------------------------------------------------------------------------\n\u003e\u003e\u003e\u003e Own the Future-Intel\u0026reg; Level Up Game Demo Contest 2013\n\u003e\u003e\u003e\u003e Rise to greatness in Intel's independent game demo contest.\n\u003e\u003e\u003e\u003e Compete for recognition, cash, and the chance to get your game\n\u003e\u003e\u003e\u003e on Steam. $5K grand prize plus 10 genre and skill prizes.\n\u003e\u003e\u003e\u003e Submit your demo by 6/6/13. http://p.sf.net/sfu/intel_levelupd2d\n\u003e\u003e\u003e\u003e _______________________________________________\n\u003e\u003e\u003e\u003e Bitcoin-development mailing list\n\u003e\u003e\u003e\u003e Bitcoin-development at lists.sourceforge.net\n\u003e\u003e\u003e\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e ------------------------------------------------------------------------------\n\u003e\u003e Own the Future-Intel\u0026reg; Level Up Game Demo Contest 2013\n\u003e\u003e Rise to greatness in Intel's independent game demo contest.\n\u003e\u003e Compete for recognition, cash, and the chance to get your game\n\u003e\u003e on Steam. $5K grand prize plus 10 genre and skill prizes.\n\u003e\u003e Submit your demo by 6/6/13. http://p.sf.net/sfu/intel_levelupd2d\n\u003e\u003e _______________________________________________\n\u003e\u003e Bitcoin-development mailing list\n\u003e\u003e Bitcoin-development at lists.sourceforge.net\n\u003e\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e\u003e\n\u003e\u003e\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20130402/7b3c7f99/attachment.html\u003e"}
