1 Feb 2002 02:03
Re: I-D ACTION:draft-ietf-pkix-okid-00.txt
Paul Hoffman / IMC <phoffman <at> imc.org>
2002-02-01 01:03:15 GMT
2002-02-01 01:03:15 GMT
At 12:28 AM +0100 2/1/02, Jean-Marc Desperrier wrote: >Paul Hoffman / IMC wrote: > >> > So the document should be changed to consider the hash of the >>certificate >> > instead of only the hash of the public key (and of the algorithm >> > identifier). >> >> You then make Mallory's job many orders of magnitude easier. Instead >> of having to create 2^79 key pairs, he only has to create 2^79 hashes >> looking for one that matches Alice's OKID. > >No. >Clearly if finding a collision does not suffice for Mallory in the >first case, >but that he has to find a collision for valid data, in that case a >valid key, then >in the second case, he also has to find a collision for valid data, >therefore a >valid certificate. >And the second case is as a minimum as difficult as the first, >because there must >be a valid key inside the certificate. > >If just finding a collision is dangerous, not matter if the data it >comes from can >be parsed as valid, then the two cases are perfectly equal. We disagree here. Given Alice's OCID (it is now a cert ID, not a key(Continue reading)
RSS Feed