note 47822 deleted from function.md5 by mazzanet
| From: | mazzanet@php.net | Date: | Mon, 03 Oct 2005 09:29:30 +0000 |
| Subject: | note 47822 deleted from function.md5 by mazzanet | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-96258@lists.php.net to get a copy of this message | ||
Note Submitter: Kevin L
----
Correction regarding MD5's security:
A method of producing collisions in MD5 and related algorithms has been discovered that is more
efficient than brute-force. What this means is that an attacker can produce two strings that hash
to the same result in a "reasonable" amount of time.
This does NOT mean that an attacker can a) decrypt an MD5 hash or b) find another string that will
MD5 to the same value. So MD5 protected passwords cannot be attacked by this method.
Note that all hashes have collisions in them-- reducing an infinite set of inputs to a finite set of
outputs must have duplicates.