Re: MD5 collisions found - alternative?


it is true that collisions have been found in md5 (and a lot of other hash functions of that `family', cfr. the links you mention).

this means that the hash functions should certainly no longer be used in applications relying on the collision-resistance of the hash function, e.g., everything where md5withRsa is used should be replaced (note that md5 was considered deprecated already mid-nineties), but the verification of password hashes, such as used in pam, rely on the hash function's oneway-feature rather than on its collision-resistance...

On Tue, 24 Aug 2004, Robert Trebula wrote:


Maybe you have already noticed - collisions have been found in MD5 hashing algorithm:


My question is: Is there an easy way to make my debian sid installation use something else (better) than md5 for various things? Namely SHA-1 with some longer output in PAM.

