2014-05-18 19:56:26 +08:00
在Google Scholar 上有她的《Collisions for Hash Functions MD4, MD5, HAVAL-128 and RIPEMD》这篇论文,大意应该是这样的:
对任何原文P及其hash值D, 她这个算法能在1小时内找到另一个明文P' ,使P'的hash值 D'=D
On IBM P690, it takes about one hour to find such M and M' , after that, it takes only 15 seconds to 5 minutes to find Ni and Ni', so that ( M,Ni ) and (M' , Ni' ) will produce the same hash same value. Moreover, our attack works for any given initial value.