Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Jules Merit
there is a backdoor when a score of 4, what data produces it i have no idea. On Sun, Feb 26, 2017 at 9:25 AM, Bakul Shah wrote: > https://arstechnica.com/security/2017/02/watershed- > sha1-collision-just-broke-the-webkit-repository-others-may-follow/ > >

[9fans] Proof of concept inertial scrolling on macOS with devdraw/acme

2017-02-26 Thread marius a. eriksen
It’s surprisingly pleasant to use (with a Mac laptop, a Magic Trackpad or aMagic Mouse) Demo here: https://www.youtube.com/watch?v=1XJFJ4coS48=youtu.be commit d782c880d4ca30fcacddfbab298dad82fe8277c3 Author: marius a. eriksen Date: Sat Feb 25 21:48:50 2017 -0800

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Charles Forsyth
It's curious that svn "corrupts" the repository, if that's really what they mean, when two leaf files collide. An index or directory colliding with a file would be more understandable. On 26 February 2017 at 18:16, Charles Forsyth wrote: > > On 26 February 2017 at

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Charles Forsyth
On Sun, 26 Feb 2017, 18:49 Bakul Shah, wrote: > The links are to different files. > Not on Gmail at least look to see where each link points. Both are to -2 in the message I see on Gmail. Unless it cleverly optimised the"identical" content!

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Charles Forsyth
On 26 February 2017 at 17:30, Jules Merit wrote: > there is a backdoor when a score of 4, what data produces it i have no > idea. > where is that? I had a quick look but couldn't find it.

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Bakul Shah
On Sun, 26 Feb 2017 19:57:53 GMT Charles Forsyth wrote: > > > The links are to different files. > > > > Not on Gmail at least look to see where each link points. Both are to -2 > in the message I see on Gmail. Unless it cleverly optimised the"identical" > content!

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Kim Shrier
I have had a personal project on my list of "things to do when I have time", is to redo venti using sha256. Does any body see any problems with doing that? Kim

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Jadon Bennett
On Sun, Feb 26, 2017 at 07:57:53PM +, Charles Forsyth wrote: > On Sun, 26 Feb 2017, 18:49 Bakul Shah, wrote: > > > The links are to different files. > > > > Not on Gmail at least look to see where each link points. Both are to -2 > in the message I see on Gmail. Unless

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Charles Forsyth
On 26 February 2017 at 17:25, Bakul Shah wrote: > Venti is similarly corruptible, right? Since the checksum is over just the > content. If you downloaded https://shattered.io/static/shattered-1.pdf > and >

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Bakul Shah
On Sun, 26 Feb 2017 18:25:34 GMT Charles Forsyth wrote: > > It's curious that svn "corrupts" the repository, if that's really what they > mean, when two leaf files collide. > An index or directory colliding with a file would be more understandable. The only known

Re: [9fans] SHA-1 collision and venti

2017-02-26 Thread Bakul Shah
The links are to different files. The pdfs look identical except for color background. The diff bytes are 193..320. The rest is the same so your first 8k byte checksum would be the same. > On Feb 26, 2017, at 10:16 AM, Charles Forsyth > wrote: > > >> On 26