This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

@@ -4,7 +4,7 @@
- Could we simply split up a message and sign parts?
![1649192960.png](img/1649192960.png)\
![1649192960.png](img/1649192960.png)
A lot of faff for signing large files
@@ -16,7 +16,7 @@ A lot of faff for signing large files
2. Fixed output length
3. Pre-image resistance (one way)
4. Second pre-image resistance
- If we have a hashed message, we cannot find another message with the same hash
- If we have a hashed message, we cannot find another message with the same hash
5. Collision resistance
#### Pre-image Resistance
@@ -24,7 +24,7 @@ A lot of faff for signing large files
- Hash functions must be one-way
- Given a hash of a message $H(x)$ it must be infeasible to calculate $x$
- Less applicable to digital signatures
- Crucial to password storage and key derivation
- Crucial to password storage and key derivation
#### Second Pre-image Resistance
@@ -37,7 +37,7 @@ A lot of faff for signing large files
![1649193645.png](img/1649193645.png)
Oscar finds a weak message (one of the messages is known ahead of time), he replaces the message $x_1$ with $x_2$. Now Oscar can send a signed message to Alice
Oscar finds a weak message (one of the messages is known ahead of time); he replaces the message $x_1$ with $x_2$. Now Oscar can send a signed message to Alice
#### Collision Resistance
@@ -80,8 +80,8 @@ P(n)&=(1-\frac{1}{365})\cdot (1-\frac{2}{365})\dots (1-\frac{n-1}{365})
$$
- The probability of at least one collision is $1 – P(\textrm{no collision})$.
- The probability of a collision with only 23 people is ~50%!
- For 40 people it’s ~90%
- The probability of a collision with only 23 people is ~50%!
- For 40 people it’s ~90%
- The same principle applies to hash functions, the more hashes computed, the more likely a collision becomes
![1649194470.png](img/1649194470.png)
@@ -93,4 +93,4 @@ $$
- You will find a collision after approx $\sqrt{(2^n)}=2^{\frac n2}$ random attempts
- This means that your bit length needs to be double the size of your desired security margin
- `SHA-256` therefore offers equivalent security to `AES 128`
- left at `25:55`
- left at `25:55`