Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / SHA-1 collision can break SVN code repositories

SHA-1 collision can break SVN code repositories

Latest Govt. Jobs 23:06:00 News Edit
The implications of the SHA-1 collision attack begin to surface.

A recently announced SHA-1 collision attack has the potential to break code repositories that use the Subversion (SVN) revision control system. The first victim was the repository for the WebKit browser engine that was corrupted after someone committed two different PDF files with the same SHA-1 hash to it.
The incident happened hours after researchers from Google and Centrum Wiskunde & Informatica (CWI) in the Netherlands announced the first practical collision attack against the SHA-1 hash function on Thursday. Their demonstration consisted of creating two PDF files with different contents that had the same SHA-1 digest.
This proved without a doubt that SHA-1 is cryptographically broken because a hash function should always produce different digests (hashes) for different pieces of data or files. SHA-1 is a hash function used to calculate an alphanumeric string that serves as the cryptographic representation of a file or a piece of data. 
A WebKit developer wanted to build a test to prove that the demonstrated collision can't be used for cache poisoning in the context of WebKit's disk cache deduplication feature that relies on SHA-1. In order to do this, he uploaded the two PDF files generated by CWI and Google to the WebKit SVN which then started giving out errors.
It seems that even after removing the files, some problems remained and further manual intervention was required to fix them.
The issue is not specific to WebKit's repository, but to all SVN-based repositories. The Subversion developers have released a script that SVN administrators can use to prevent SHA-1 colliding files from being committed to their repositories. Meanwhile, work for a more permanent fix is in progress.
Git, a competing and more popular version control system, also uses SHA-1 internally, and according to the CWI and Google researchers, is theoretically vulnerable.
"It is essentially possible to create two GIT repositories with the same head commit hash and different contents, say a benign source code and a backdoored one," the researchers said on their shattered.io website. "An attacker could potentially selectively serve either repository to targeted users."
This kind of attack would require attackers to compute their own collision, which at this time requires significant resources. It took Google over nine quintillion SHA-1 computations, the equivalent of a year of continuous computations on 110 GPUs or 6,500 CPUs.
Linus Torvalds, the founder of both Linux and git, doesn't seem too concerned about the attack's implications, partly because it can be easily deterred by adding some simple checks that would make an attack not worth it.
"Unlike some 'signing a pdf' attack, git doesn't fundamentally depend on the SHA1 as some kind of absolute security," Torvalds said in a discussion on the git mailing list. "If we have the minimal machinery in git to just notice the attack, the attack essentially goes away. Attackers can waste infinite amounts of CPU time, and if it's cheap for us to notice, it completely disarms all that attack work."
Later in that same discussion, the git developers decided to use the collision detection code provided by the CWI researchers to build some protection. Meanwhile moving git to another hash function is being discussed as a goal and SHA3 seems to be the chosen candidate because it has better performance than SHA2.
"I doubt the sky is falling for git as a source control management tool," Torvalds concluded in one of his emails. "Do we want to migrate to another hash? Yes. Is it 'game over' for SHA1 like people want to say? Probably not."
Even though it's been known for a long time that SHA-1 is theoretically vulnerable to collision attacks, the real-world implications of a practical attack for file synchronization, deduplication and backup systems, in particular, are yet to be seen. In 90 days, the Google and CWI researchers plan to disclose the code they used to generate the colliding PDF files, which will allow others to create similar collisions, if they have the necessary computing resources.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Oppo F7 India launch confirmed

Alcatel 1x with Android Oreo (Go ed...

Huawei P20, P20 Pro, P20 Lite price
SHA-1 collision can break SVN code repositories SHA-1 collision can break SVN code repositories Reviewed by Latest Govt. Jobs on 23:06:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • TOP 10 ANDROID GAMES OF MARCH 2016
    TOP 10 ANDROID GAMES OF MARCH 2016
    03.04.2016 - 0 Comments
    It has been a long time since Nokia launched their popular Tetris and Snake game. After that in 2008 when…
  • Logitech ZeroTouch review
    Logitech ZeroTouch review
    09.02.2017 - 0 Comments
    Update : Amazon's smart assistant Alexa has arrived for the Logitech ZeroTouch,…
  • New 'Micromax Home Assist' app launched for ACs
    New 'Micromax Home Assist' app launched for ACs
    04.03.2017 - 0 Comments
    Micromax Informatics has launched a new range of air-conditioners with "Micromax Home…
  • Peppertap Paytm Offer – Get 15% Off + extra 15% Cashback using Paytm [Ultimatez Tricks]
    Peppertap Paytm Offer – Get 15% Off + extra 15% Cashback using Paytm [Ultimatez Tricks]
    21.03.2016 - 0 Comments
    Peppertap Paytm Offer – Peppertap is just awesome for buying groceries online. It is now offering flat…
  • Sony Xperia Z5 Compact Review: Good Things Come In Small Packages
    Sony Xperia Z5 Compact Review: Good Things Come In Small Packages
    12.02.2017 - 0 Comments
    The Sony Xperia Z5 range finds itself in a strange place right now. After a rather muted launch in Europe…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...

Random Posts

  • Samsung Galaxy J7 pro, Galaxy J7 Max launched at Rs 20,900 and Rs 17,900 respectively
    Samsung Galaxy J7 pro, Galaxy J7 Max launched at Rs 20,900 and Rs 17,900 respectively
    17.06.2017 - 0 Comments
    Samsung Galaxy J7 Max and Galaxy J7 pro smartphones were released in India. The devices are priced at Rs…
  • Lenovo IdeaPad 320S Review
    Lenovo IdeaPad 320S Review
    03.02.2018 - 0 Comments
    As The Lenovo IdeaPad 320S presentations, that you can safely select a extra reasonably priced ‘price…
  • Apple HomePod praised for sound
    Apple HomePod praised for sound
    08.02.2018 - 0 Comments
    The company’s latest hardware product arrives for pre-order customers and in stores on Friday, a late…
  • Google looks to invest or buyout startups to serve next billion users in India
    Google looks to invest or buyout startups to serve next billion users in India
    15.02.2017 - 0 Comments
    Google has begun exploratory talks with startups and venture capital investors in the country in…
  • Microsoft's Satya Nadella on public cloud bet, India Stack, effect of AI on jobs & more
    Microsoft's Satya Nadella on public cloud bet, India Stack, effect of AI on jobs & more
    21.02.2017 - 0 Comments
    Satya Nadella has been widely credited with reshaping Microsoft since he took over as CEO.…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!