How easy is it in 2022 to find a SHA1 collision?

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • fastcoll

  • You can generate collisions in seconds.

    https://github.com/brimstone/fastcoll

    There's plenty of others, that one was just a random one I picked.

  • git

    Git Source Code Mirror - This is a publish-only repository and all pull requests are ignored. Please follow Documentation/SubmittingPatches procedure for any of your improvements. (by bk2204)

  • He was told weeks after git was published, I guess 2005. Sorry, no link handy.

    They are working on it since 2017. https://github.com/bk2204/git/commits/transition-stage-4/Doc...

    Not that it's particularly urgent...

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • collisions

    Hash collisions and exploitations

  • You want to download a Linux Distro with hash digest of value ABC. I'm somewhat interested in people using that linux distro so I tamper the distro to introduce a tracking mechanism that also produces ABC when hashed. You download the distro, verify that the hash is indeed ABC and install it.

    A more structured answer to your question is available here https://github.com/corkami/collisions (he also put together a presentation that I can't find right now).

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts