Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would collisions in MD5 really matter in case of legal documents? How would you use it to forge a contract? Take original, make alterations, then add data to the non-visible part of the file until hashes match? Wouldn't that be easy to detect? "What is that 15 Kb of stuff doing there? It is not normally part of pdf that any sane program would write."

Or are there some more sophisticated methods?



I can imagine (and therefore we should assume that the attacker can imagine with far more craftiness) several ways of hiding junk in a PDF.

E.g. How about in any binary content - embedded fonts, images etc.

My big concern is that in this scenario an attacker may have years to create an attack. One small part of designing a security protocol is understanding timeliness constraints.


So just use plain text.


The wordiness of legalese may actually be a place to pad. Also, extraneous terms and clauses that might sound plausible and have no bearing on what's actually being claimed.

Collision attacks are mitigated by careful examination coupled with a forbidding of extraneous data and a skepticism about possibly extraneous data - but I am not comfortable assuming they are defeated by it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: