Re: Digital signing of printed documents

* John Hasler wrote:

> Alphonse Ogulla writes:
> > I wish to get your views on how I can implement a system that will
> > capture text of a financial document that is to be printed, run a hash
> > algorithm (SHA-1) over the document text...
> I suggest that you use SHA-2.  SHA-1 may no longer be secure.

On the gpg mailing list they basically came to the conclusion that SHA-1
is *weaker* than previously thought based on the fact that collisions
can be found in SHA-1 in 2**69 hash operations, much less than the
brute-force attack of 2**80 operations based on the hash length.

but...... 2**69 however, is still quite strong [1] ;-)


[1] Depends on your definition of the word "strong" :-)

