Re: md5() algorithm, probabilities

From: Date: Fri, 21 Jul 2000 14:09:07 +0000
Subject: Re: md5() algorithm, probabilities
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-25353@lists.php.net to get a copy of this message
You could also add time() to the list of things going into MD5, which would greatly increase your odds of staying unique. On Fri, 21 Jul 2000, waldschrott wrote the following to Sascha Schumann and...: > > PHP is not the proper tool to run brute force attacks against > > hash functions. Some would argue that brute force attacks > > against hash functions are pointless at all. > > sure, but if you remember my initial post, I want to use a md5() hash as > unique identifier driven through a session and now I think I can > definitely do this > (I´m concatting all the primary key data on page 1 (results in a unique > string) then I run md5() on it and hope it remains unique) > > If you don´t want to transport the data out of (eg. 3 combined) primary > keys but you need an *unique* identifier, which remains unique even if > data is similar and of arbitrary length and so on > > I´m just unsure when md5() will produce a collision (means match any of > a previous key) using sequential numbers (only *one* primary key, numeric). > I´m sure that this will work until a certain point, but I don´t know > which it is, perhaps I´ll test it out some day. > > This proc should catch it at any point: > > for ($i=1;;$i++) { > $n[md5($i)]=TRUE; > if (sizeof($n)!=$i) die("got it: $i"); } > > but I think everyones maschine will run out of vmem before finding $i :) > (I stopped at 500MB) > > regards > >

« previous php.dev (#25353) next »