<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>2009 Reports</title>
    <link>http://eprint.iacr.org/forum/list.php?9</link>
    <description><![CDATA[Discussion forum for Cryptology ePrint Archive reports posted in 2009.
Please put the report number in the subject.

]]></description>
    <language>EN</language>
    <pubDate>Wed, 13 May 2009 14:36:18 -0600</pubDate>
    <lastBuildDate>Wed, 13 May 2009 14:36:18 -0600</lastBuildDate>
    <category>2009 Reports</category>
    <generator>Phorum 5.1.22</generator>
    <ttl>600</ttl>
    <item>
      <title>Re: 2009/033</title>
      <link>http://eprint.iacr.org/forum/read.php?9,72,89#msg-89</link>
      <author>Orr</author>
      <description><![CDATA[A difference in the MSB, affects only other MSBs.

(in other words - the MSBs do not affect any other bit but the MSBs).

And for a given message (just fix the 31 LSBs of each message word and the entire chaining value), the MSBs of the eight output chaining value are a linear combination of the 16 message MSBs.

Because this is the case, it is easy to find collisions (just solve the required linear equations), second preimages (given a specific input to the compression function, flip the correct MSBs to obtain the same output).

Also, using the De Canniere and Rechberger attack from Crypto 2006, it is possible to find preimages of the compression function in time complexity of about 32*2^8.

(some of these observations were verified by Tor).]]></description>
      <category>2009 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?9,72,89#msg-89</guid>
      <pubDate>Wed, 13 May 2009 14:36:18 -0600</pubDate>
    </item>
    <item>
      <title>Re: 2009/033</title>
      <link>http://eprint.iacr.org/forum/read.php?9,72,88#msg-88</link>
      <author>yesmaeili</author>
      <description><![CDATA[I got from the point claimed by Orr that collision attack or/and a second preimage attack can be easily done. I would be appreciate Orr if he explains more.
Is your points related to the weaknesses properties of T-Functions?]]></description>
      <category>2009 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?9,72,88#msg-88</guid>
      <pubDate>Thu, 30 Apr 2009 03:10:59 -0600</pubDate>
    </item>
    <item>
      <title>2009/033</title>
      <link>http://eprint.iacr.org/forum/read.php?9,72,72#msg-72</link>
      <author>Orr</author>
      <description><![CDATA[The MSBs are treated in a linear manner.

Thus, a collision attack and a second preimage attack on the hash function are easily done.]]></description>
      <category>2009 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?9,72,72#msg-72</guid>
      <pubDate>Fri, 23 Jan 2009 10:52:50 -0700</pubDate>
    </item>
  </channel>
</rss>
