note 27344 added to function.md5
| From: | dmarsh dot no dot spam dot please at spscc dot ctc dot edu | Date: | Mon, 02 Dec 2002 20:27:30 +0000 |
| Subject: | note 27344 added to function.md5 | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-40275@lists.php.net to get a copy of this message | ||
Recommended readed: OpenSSL from O'reilly! It has chapters on SSL and PHP!! but it also covers
cryptography in more depth (chapters 1 and 2 are highly recommended to all here!). It has lots of
good information! Talks in depth about lots of stuff that I cannot begin to explain here.
MD5 is a repeatable hashes / digest process. Taking something of unknown size or content and
reducing it to a known size but retaining a high degree of unknown content. A good hash / digest is
said to alter the output significantly
changing ~50% of the bits in the "fixed-in-size" output stream) in the event of changing
one bit (at random) from the "unknown-in-size" input stream (or even changing the length
of the input stream by one bit*/byte, *=with padding if necessary)
MD5 is such a hash / digest. Other than that, it doesn't do much on it's own.
MD5 is a cheap way to test a file transfer (like a CRC32). If either the file or the MD5 is
downloaded with errors, the chances that the MD5 of the file and the "PUBLIC" copy of the
MD5 will match is highly unlikely. Both would have to error in a highly unpredictable way. However
relying of MD5s as a way to validate that the file hasn't been tamptered with (tainted) is not
good. If you can download the file from one place and a public MD5 from a second place, you at least
are using a 3rd party method to attempt to validate the file's contents against tainting.
MD5 can ONLY be used to validate the contents against tainting if there is something secret
(private) between the two end-points.
Lets examine MD5 in a typical and extremely effective email validating process. The two parties via
a trusted method exchange a word / phrase / password (something private) that hopefully nobody else
knows.
The first party publically composes an email with an MD5. But instead of sending that MD5. the MD5
is used against this word / phrase / password (private) in a Message Authentication Code (MAC), or
better Hash-MAC (HMAC) (see http://www.rsasecurity.com/rsalabs/faq/2-1-7.html)
One way would be to MD5 the word / phrase / password (private) part and the public part (the message
body) as two different MD5's. the MD5 the two MD5s together as a single MD5 and send the
composite MD5 in the public.
The receiver can (using all available parts, the private part, public part and the composite MD5)
authenicate (testing against the computed part) the message hasn't been tampered during
transit. The message body and the composite MD5 is sent in plain text, yet the contents have been
authenicated with a high level of confidence. No encryption was used.
MD5 is often used to authenicate parts of encrypted streams and thus is the reason why many confuse
MD5 as encryption (or even authenication) rather than what it is. A hash / digest.
An alternate to MD5 is SHA1. The output size of SHA1 is a little bigger (I think 164bits). More
bits, means a higher degree of complexity. 128 bits is concidered minimim by experts in the
field.... For cipher lengths and symmetric key sizes (due to computational power now available for
brute force attacks).
--Doug
--
http://www.php.net/manual/en/function.md5.php
http://master.php.net/manage/user-notes.php?action=edit+27344
http://master.php.net/manage/user-notes.php?action=delete+27344
http://master.php.net/manage/user-notes.php?action=reject+27344