Conversation
Notices
-
Embed this notice
Fish of Rage (sun@shitposter.world)'s status on Friday, 21-Feb-2025 07:50:57 JST Fish of Rage
@scathach at work I thought I found a sha3 hash collision, but it turned out to be a bug in our vendor's sha3 implementation, I reported it to them on github and they deleted everything and then gave me free swag to shut up. I got a hoodie and stickers but for a few hours there I thought I found a sha3 collision. - Haelwenn /элвэн/ :triskell: and feld like this.
-
Embed this notice
Fish of Rage (sun@shitposter.world)'s status on Friday, 21-Feb-2025 07:54:54 JST Fish of Rage
@scathach they completely replaced the entire sha3 implementation in a new release of their library without telling anyone that the older versions had a huge vulnerability lol. crypto company Haelwenn /элвэн/ :triskell: likes this. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Friday, 21-Feb-2025 08:42:32 JST Haelwenn /элвэн/ :triskell:
@sun @scathach Quite wonder how you can screw it up that badly when there's pretty good test vectors for checksums like SHA3… although well you can also just not run those. -
Embed this notice
Fish of Rage (sun@shitposter.world)'s status on Friday, 21-Feb-2025 08:50:57 JST Fish of Rage
@lanodan @scathach The explanation is actually pretty boring, it has to do with the extremely loose typing of JavaScript and poor input validation. Haelwenn /элвэн/ :triskell: likes this. -
Embed this notice
saint podiatron (goatmeal@shitposter.world)'s status on Friday, 21-Feb-2025 11:26:14 JST saint podiatron
@sun @scathach what would you even do if you found a sha3 hash collision? I would be so mad. it could have been a winning lottery number or a photo of michelle obama when she was pregnant but nooooo Fish of Rage likes this. -
Embed this notice
Fish of Rage (sun@shitposter.world)'s status on Friday, 21-Feb-2025 11:26:43 JST Fish of Rage
@goatmeal @scathach it would be my one way irrevocable pussy pass