Re: dpkg-sig support wanted?
* Jochen Voss:
> On Tue, Nov 29, 2005 at 02:08:45PM +0100, Goswin von Brederlow wrote:
>> According to slashdot articles you can generate human readable files
>> (like the Packages file) with md5sum collision in ~45minutes on a
>> modern cpu now.
> I found the example at http://www.cits.rub.de/MD5Collisions/ quite
> impressive. They have two different valid PostScript files with
> identical MD5 sums. I don't know how much computing time they used,
None, many of these examples were created before the collision
generation tools were generally available. The "exploit" uses some
properties of Postscript files which make them not very desirable for
storing electronic documents which cannot be altered. For example, it
is possible to create a Postscript file whose output, when printed,
varies from printer to printer.
(Note the "rub.de" part of the URL. A clear warning sign.)