[Webkit-unassigned] [Bug 168774] Add a test verifying cache deduplication is not sensitive to SHA1 collision attack

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Sat Feb 25 01:46:05 PST 2017


https://bugs.webkit.org/show_bug.cgi?id=168774

Antti Koivisto <koivisto at iki.fi> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
 Attachment #302662|0                           |1
        is obsolete|                            |

--- Comment #46 from Antti Koivisto <koivisto at iki.fi> ---
Created attachment 302755
  --> https://bugs.webkit.org/attachment.cgi?id=302755&action=review
now with php script to generate the colliding files in memory

This patch contains non-colliding versions of the files only:

> shasum shattered-nocollision-*
5439274cf677fe3b7c51264f88a5ecee97319ee9  shattered-nocollision-1.pdf
7fdd163dc21064b7f26e1199fc560ee6e0307498  shattered-nocollision-2.pdf

make-sha1-collision.php turns them into colliding ones with simple string replacement.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.webkit.org/pipermail/webkit-unassigned/attachments/20170225/4a6f5228/attachment.html>


More information about the webkit-unassigned mailing list