2015-10-30 00:53
sipa changed the topic of #bitcoin-wizards to: This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development |
http://bitcoin.ninja/ | This channel is logged. | For logs and more information, visit
http://bitcoin.ninja
00:05
PRab has quit [Quit: ChatZilla 0.9.93 [Firefox 51.0.1/20170125094131]]
00:07
davasny has quit [Read error: Connection reset by peer]
00:08
rusty2 has joined #bitcoin-wizards
00:11
davasny has joined #bitcoin-wizards
00:12
davasny is now known as Guest1160
00:12
Guest1160 has quit [Remote host closed the connection]
00:14
handlex has joined #bitcoin-wizards
00:15
alpalp has joined #bitcoin-wizards
00:15
alpalp has joined #bitcoin-wizards
00:15
alpalp has quit [Changing host]
00:19
NewLiberty has joined #bitcoin-wizards
00:22
kenshi84 has quit [Ping timeout: 260 seconds]
00:25
kenshi84 has joined #bitcoin-wizards
00:32
marcoagner has quit [Ping timeout: 268 seconds]
00:40
handlex has quit [Quit: handlex]
01:02
dnaleor has quit [Quit: Leaving]
01:03
dnaleor has joined #bitcoin-wizards
01:05
Giszmo has quit [Ping timeout: 260 seconds]
01:14
alpalp has quit [Ping timeout: 240 seconds]
01:21
Giszmo has joined #bitcoin-wizards
01:34
dodomojo has joined #bitcoin-wizards
01:34
CheckDavid has quit [Quit: Connection closed for inactivity]
01:37
goksinen_ has quit [Ping timeout: 255 seconds]
01:46
handlex has joined #bitcoin-wizards
01:54
Ylbam has quit [Quit: Connection closed for inactivity]
02:15
alpalp has joined #bitcoin-wizards
02:15
alpalp has joined #bitcoin-wizards
02:15
alpalp has quit [Changing host]
02:24
Giszmo has quit [Quit: Leaving.]
02:30
Koalapi12 has joined #bitcoin-wizards
02:42
jtimon has quit [Remote host closed the connection]
02:54
Koalapi12 has left #bitcoin-wizards ["Leaving"]
02:54
go1111111 has joined #bitcoin-wizards
03:07
NewLiberty has quit [Ping timeout: 240 seconds]
03:08
NewLiberty has joined #bitcoin-wizards
03:08
dodomojo has quit [Remote host closed the connection]
03:11
adlai has quit [Ping timeout: 257 seconds]
03:11
echonaut has quit [Remote host closed the connection]
03:11
echonaut has joined #bitcoin-wizards
03:14
adlai has joined #bitcoin-wizards
03:16
dodomojo has joined #bitcoin-wizards
03:30
handlex has quit [Quit: handlex]
04:04
alpalp has quit [Ping timeout: 240 seconds]
04:12
dodomojo has quit [Remote host closed the connection]
04:14
Starduster has joined #bitcoin-wizards
04:29
Dizzle has joined #bitcoin-wizards
04:35
lmacken has quit [Ping timeout: 240 seconds]
04:56
Newyorkadam has joined #bitcoin-wizards
05:00
legogris has quit [Remote host closed the connection]
05:00
pro has quit [Quit: Leaving]
05:00
legogris has joined #bitcoin-wizards
05:05
PaulCape_ has joined #bitcoin-wizards
05:05
PaulCapestany has quit [Ping timeout: 240 seconds]
05:26
chjj has quit [Ping timeout: 260 seconds]
05:30
aburan_ has quit [Remote host closed the connection]
05:44
go1111111 has quit [Ping timeout: 240 seconds]
05:49
TheSeven has quit [Ping timeout: 240 seconds]
05:49
cluelessperson has quit [Ping timeout: 240 seconds]
05:49
TheSeven has joined #bitcoin-wizards
05:50
pero0 has joined #bitcoin-wizards
05:56
cluelessperson has joined #bitcoin-wizards
05:57
lclc has joined #bitcoin-wizards
06:03
go1111111 has joined #bitcoin-wizards
06:08
instagibbs has quit [Ping timeout: 240 seconds]
06:18
instagibbs has joined #bitcoin-wizards
06:26
lclc has quit [Ping timeout: 240 seconds]
06:32
paveljanik has joined #bitcoin-wizards
06:32
paveljanik has joined #bitcoin-wizards
06:32
paveljanik has quit [Changing host]
06:45
cannon-c has joined #bitcoin-wizards
06:57
rusty2 has quit [Ping timeout: 240 seconds]
07:04
aburan_ has joined #bitcoin-wizards
07:12
MoALTz has joined #bitcoin-wizards
07:25
Dizzle has quit [Quit: Leaving...]
07:44
BashCo has quit [Remote host closed the connection]
07:44
lclc has joined #bitcoin-wizards
07:52
lclc_ has joined #bitcoin-wizards
07:55
lclc has quit [Ping timeout: 260 seconds]
07:59
lclc has joined #bitcoin-wizards
08:01
lclc_ has quit [Ping timeout: 240 seconds]
08:02
cannon-c has quit [Quit: Page closed]
08:05
BashCo has joined #bitcoin-wizards
08:06
lclc_ has joined #bitcoin-wizards
08:09
lclc has quit [Ping timeout: 260 seconds]
08:12
Ylbam has joined #bitcoin-wizards
08:12
lclc_ has quit [Read error: Connection reset by peer]
08:13
lclc has joined #bitcoin-wizards
08:20
lclc_ has joined #bitcoin-wizards
08:21
Newyorkadam has quit [Quit: Newyorkadam]
08:23
lclc has quit [Ping timeout: 240 seconds]
08:28
lclc has joined #bitcoin-wizards
08:30
lclc_ has quit [Ping timeout: 260 seconds]
08:33
lclc has quit [Read error: Connection reset by peer]
08:34
lclc has joined #bitcoin-wizards
08:42
lclc_ has joined #bitcoin-wizards
08:44
lclc has quit [Ping timeout: 268 seconds]
08:55
lclc_ has quit [Ping timeout: 260 seconds]
09:02
lclc_ has joined #bitcoin-wizards
09:06
lclc has joined #bitcoin-wizards
09:08
edvorg has joined #bitcoin-wizards
09:08
chjj has joined #bitcoin-wizards
09:09
lclc_ has quit [Ping timeout: 260 seconds]
09:11
jannes has joined #bitcoin-wizards
09:21
lclc_ has joined #bitcoin-wizards
09:23
lclc has quit [Ping timeout: 260 seconds]
09:25
go1111111 has quit [Ping timeout: 240 seconds]
09:34
lclc has joined #bitcoin-wizards
09:37
lclc_ has quit [Ping timeout: 255 seconds]
09:38
edvorg has quit [Remote host closed the connection]
09:39
aburan_ has quit [Quit: Ex-Chat]
09:40
edvorg has joined #bitcoin-wizards
09:42
lclc_ has joined #bitcoin-wizards
09:44
lclc has quit [Ping timeout: 255 seconds]
09:51
lclc_ has quit [Ping timeout: 260 seconds]
09:53
lclc has joined #bitcoin-wizards
09:56
AaronvanW has joined #bitcoin-wizards
09:56
lclc_ has joined #bitcoin-wizards
09:58
lclc has quit [Ping timeout: 240 seconds]
10:03
lclc has joined #bitcoin-wizards
10:05
lclc_ has quit [Ping timeout: 240 seconds]
10:16
edvorg has quit [Remote host closed the connection]
10:17
lclc_ has joined #bitcoin-wizards
10:19
lclc has quit [Ping timeout: 255 seconds]
10:19
edvorg has joined #bitcoin-wizards
10:21
jl2012 has joined #bitcoin-wizards
10:24
Ylbam has quit [Quit: Connection closed for inactivity]
10:25
lclc_ has quit [Ping timeout: 260 seconds]
10:31
priidu has quit [Ping timeout: 268 seconds]
10:31
Ylbam has joined #bitcoin-wizards
10:42
priidu has joined #bitcoin-wizards
10:49
laurentmt has joined #bitcoin-wizards
10:52
chjj has quit [Ping timeout: 240 seconds]
10:54
laurentmt has quit [Quit: laurentmt]
11:11
pero0 has quit [Remote host closed the connection]
11:15
nu11p7r has quit [Ping timeout: 240 seconds]
11:18
Alina-malina_ has joined #bitcoin-wizards
11:26
Alina-malina_ has quit [Changing host]
11:26
Alina-malina_ has joined #bitcoin-wizards
11:28
Alina-malina_ is now known as Alina-malina
11:47
lclc has joined #bitcoin-wizards
11:57
NewLiberty has quit [Ping timeout: 268 seconds]
11:57
Sosumi has quit [Quit: Bye]
11:58
lclc has quit [Ping timeout: 240 seconds]
12:05
BashCo_ has joined #bitcoin-wizards
12:08
BashCo has quit [Ping timeout: 240 seconds]
12:10
wallet42 has joined #bitcoin-wizards
12:18
NewLiberty has joined #bitcoin-wizards
12:18
mountaingoat has quit [Ping timeout: 240 seconds]
12:30
Cory has quit [Ping timeout: 240 seconds]
12:31
mountaingoat has joined #bitcoin-wizards
12:33
MaxSan has joined #bitcoin-wizards
12:37
Guest91228 has joined #bitcoin-wizards
12:37
Guest91228 has quit [Read error: Connection reset by peer]
12:45
norotartagen has quit [Read error: Connection timed out]
12:46
mountaingoat has quit [Ping timeout: 260 seconds]
12:46
Guest91228 has joined #bitcoin-wizards
12:47
norotartagen has joined #bitcoin-wizards
12:51
norotartagen has quit [Max SendQ exceeded]
12:51
Guest91228 has quit [Remote host closed the connection]
12:53
norotartagen has joined #bitcoin-wizards
12:56
Guest91228 has joined #bitcoin-wizards
12:56
norotartagen has quit [Max SendQ exceeded]
12:56
Guest91228 has quit [Read error: Connection reset by peer]
12:57
norotartagen has joined #bitcoin-wizards
13:03
Aranjedeath has quit [Ping timeout: 240 seconds]
13:04
mountaingoat has joined #bitcoin-wizards
13:07
c0rw1n has quit [Ping timeout: 240 seconds]
13:09
lclc has joined #bitcoin-wizards
13:10
btcdrak has quit [Ping timeout: 240 seconds]
13:11
btcdrak has joined #bitcoin-wizards
13:13
norotartagen has quit [Read error: Connection timed out]
13:14
c0rw1n has joined #bitcoin-wizards
13:20
c0rw1n has quit [Ping timeout: 240 seconds]
13:21
oleksiyp has joined #bitcoin-wizards
13:22
Guest91228 has joined #bitcoin-wizards
13:25
Guest91228 has quit [Remote host closed the connection]
13:26
nu11p7r has joined #bitcoin-wizards
13:33
c0rw1n has joined #bitcoin-wizards
13:36
c0rw1n_ has joined #bitcoin-wizards
13:36
pero has joined #bitcoin-wizards
13:37
Cory has joined #bitcoin-wizards
13:39
c0rw1n has quit [Ping timeout: 260 seconds]
13:43
Cory has quit [Ping timeout: 260 seconds]
13:45
Uglux has joined #bitcoin-wizards
13:45
Uglux has quit [Changing host]
13:45
Uglux has joined #bitcoin-wizards
13:46
thom is now known as thom2
13:47
thom has joined #bitcoin-wizards
13:47
Cory has joined #bitcoin-wizards
13:49
Cory has quit [Remote host closed the connection]
13:50
oleksiyp has quit [Ping timeout: 260 seconds]
13:53
Giszmo has joined #bitcoin-wizards
13:57
NewLiberty has quit [Ping timeout: 255 seconds]
13:57
Cory has joined #bitcoin-wizards
14:04
Cory has quit [Remote host closed the connection]
14:07
Cory has joined #bitcoin-wizards
14:12
Cory has quit [Ping timeout: 240 seconds]
14:13
c0rw1n_ has quit [Ping timeout: 260 seconds]
14:13
c0rw1n_ has joined #bitcoin-wizards
14:14
CheckDavid has joined #bitcoin-wizards
14:15
Cory has joined #bitcoin-wizards
14:18
Cory has quit [Remote host closed the connection]
14:27
Guest91228 has joined #bitcoin-wizards
14:30
Guest91228 has quit [Remote host closed the connection]
14:34
Guest91228 has joined #bitcoin-wizards
14:36
Chris_Stewart_5 has quit [Quit: WeeChat 0.4.2]
14:37
Guest91228 has quit [Remote host closed the connection]
14:39
c0rw1n_ is now known as c0rw1n
14:48
c0rw1n has quit [Quit: Leaving]
14:49
c0rw1n has joined #bitcoin-wizards
14:51
Guest91228 has joined #bitcoin-wizards
14:52
nu11p7r has quit [Quit: WeeChat 1.4]
14:52
nu11p7r has joined #bitcoin-wizards
14:53
nu11p7r has left #bitcoin-wizards [#bitcoin-wizards]
14:53
nu11p7r has joined #bitcoin-wizards
14:55
Chris_Stewart_5 has joined #bitcoin-wizards
14:56
NewLiberty has joined #bitcoin-wizards
15:03
Guest49686 has joined #bitcoin-wizards
15:11
Davasny has joined #bitcoin-wizards
15:12
BashCo_ has quit [Remote host closed the connection]
15:12
Davasny is now known as Guest54747
15:12
BashCo has joined #bitcoin-wizards
15:16
BashCo has quit [Ping timeout: 255 seconds]
15:30
Guyver2 has joined #bitcoin-wizards
15:31
Guest54747 is now known as davasny
15:40
lclc has quit [Ping timeout: 260 seconds]
15:40
BashCo has joined #bitcoin-wizards
15:42
Guest91228 has quit [Remote host closed the connection]
15:45
Guest91228 has joined #bitcoin-wizards
16:01
pro has joined #bitcoin-wizards
16:06
MaxSan has quit [Quit: Leaving.]
16:26
paveljanik has quit [Quit: Leaving]
16:29
Aranjedeath has joined #bitcoin-wizards
16:34
paveljanik has joined #bitcoin-wizards
16:51
abpa has joined #bitcoin-wizards
17:06
lclc has joined #bitcoin-wizards
17:10
lmacken has joined #bitcoin-wizards
17:10
lmacken has joined #bitcoin-wizards
17:10
lmacken has quit [Changing host]
17:14
CheckDavid has quit [Quit: Connection closed for inactivity]
17:17
jannes has quit [Remote host closed the connection]
17:18
moli_ has quit [Ping timeout: 260 seconds]
17:19
moli_ has joined #bitcoin-wizards
17:20
moli_ has quit [Remote host closed the connection]
17:20
moli_ has joined #bitcoin-wizards
17:28
<
adam3us >
did anyone figure out how these guys
https://alf.nu/SHA1 are able to produce arbitrary image (within some size constraints) two pdfs containing user selected images, instantly with full sha1 hash collisions?
17:29
<
gmaxwell >
adam3us: yes, they used the collision to twiddle some pdf metadata that switched between the two different images.
17:30
<
adam3us >
derp. that makes sense.. both images are in both files.. they can select presentation by a single collision.
17:30
NewLiberty has quit [Ping timeout: 260 seconds]
17:30
<
kanzure >
the collision covers the contents of the images though
17:31
<
gmaxwell >
oh there is a site that lets you use any image? okay I don't get that. Does it work?
17:31
<
kanzure >
(i have tested it twice)
17:31
<
adam3us >
it works.
17:32
<
adam3us >
kanzure no i think not they have a diagram which shows pointers
17:32
<
gmaxwell >
Oh MD extension property
17:32
<
kanzure >
yes but it's a hash over the whole file
17:32
<
gmaxwell >
so say I can produce a prefix a and prefix b which collide.
17:33
<
gmaxwell >
now I can produce a||xy b||xy for any xy which will also collide.
17:33
<
adam3us >
so i think there is a forward reference.
17:33
pero has left #bitcoin-wizards ["Leaving"]
17:33
<
gmaxwell >
and A and B differ in a way that selects if x or y is displayed.
17:34
<
gmaxwell >
Do you follow?
17:34
<
adam3us >
exactly. i thought that's what you were saying ^^ further up. but that would explain it. they dont do a good job of explaining in the paper nor site that i saw.
17:34
<
waxwing >
ah. so it basically requires that the "code" has some 'hiding' property (like comments) s.t. not all changes are visible
17:34
<
adam3us >
length extension...
17:35
<
gmaxwell >
waxwing: Yes, this particular trick does.
17:35
<
adam3us >
waxwing i dont know the details, but they say in the paper or on the site it involves some advanced jpeg hacking and tweaking until they found a variant that is generally interpreted reliably across pdf viewers.
17:35
<
waxwing >
gmaxwell: i take it from that there are other tricks you can play to achieve this result
17:40
<
gmaxwell >
so interesting, the google demo can actually be used to attack people.
17:41
<
gmaxwell >
I have a vulnerblity to go report.
17:50
handlex has joined #bitcoin-wizards
17:54
<
petertodd >
gmaxwell: there's even a demo of it used to make two colliding HTML docs, as HTML parsers are rather lenient...
17:55
<
petertodd >
gmaxwell: (*lots* of people have noticed what you just noticed!)
17:55
<
gmaxwell >
yea, I just found a pratical vulnerabiltiy based on this and have reported it.
17:55
<
petertodd >
ah cool!
17:56
<
petertodd >
did you see how webkit's svn repo got hosed because someone checked in shattered-?.pdf?
17:59
dnaleor has quit [Ping timeout: 260 seconds]
18:00
<
gmaxwell >
okay wikimedia doesn't worry about it so much that I need to keep it private, so I'll share here what I just reported and they've started acting to fix is this: Deleted files on wikipedia are indexed by sha1. So if you make a PDF pair where one shows kittens and the other shows shock porn, you upload the first and get it deleted (e.g. by failing to provide copyright information) then upload th
18:00
<
gmaxwell >
e second, and it gets deleted because its shock porn... then you scream bloody murder that the admin deleted your image of kittens and lied about it being shock porn... the deletion archive will show the first image. :P
18:01
<
gmaxwell >
I recommended that for a quick fix they just look for the shattered prefix and block uploading that.
18:03
handlex has quit [Quit: handlex]
18:11
Marquess_Loaf has quit [Quit: Connection closed for inactivity]
18:11
dnaleor has joined #bitcoin-wizards
18:13
norotartagen has joined #bitcoin-wizards
18:16
grubles has joined #bitcoin-wizards
18:17
Aranjedeath has quit [Ping timeout: 240 seconds]
18:20
Aranjedeath has joined #bitcoin-wizards
18:20
handlex has joined #bitcoin-wizards
18:21
MaxSan has joined #bitcoin-wizards
18:23
<
fluffypony >
so the trick is in the JPG, really, not the PDF so much
18:30
handlex has quit [Quit: handlex]
18:34
harrymm has quit [Remote host closed the connection]
18:38
harrymm has joined #bitcoin-wizards
18:50
MaxSan has quit [Ping timeout: 260 seconds]
18:58
EvilHero_ has joined #bitcoin-wizards
19:05
EvilHero_ has quit [Ping timeout: 260 seconds]
19:06
laurentmt has joined #bitcoin-wizards
19:13
laurentmt has quit [Quit: laurentmt]
19:15
lclc has quit [Ping timeout: 240 seconds]
19:41
null_radix has quit [Excess Flood]
19:41
null_radix has joined #bitcoin-wizards
19:59
EvilHero_ has joined #bitcoin-wizards
20:13
bsm117532 is now known as Guest48944
20:13
Guest48944 has quit [Killed (card.freenode.net (Nickname regained by services))]
20:14
bsm117532 has joined #bitcoin-wizards
20:41
NewLiberty has joined #bitcoin-wizards
20:48
EvilHero_ has quit [Ping timeout: 255 seconds]
20:53
EvilHero_ has joined #bitcoin-wizards
20:56
Guest49686 is now known as schmidty
21:01
uiuc-slack has joined #bitcoin-wizards
21:03
wizkid057 has quit [Excess Flood]
21:03
uiuc-slack1 has quit [Write error: Connection reset by peer]
21:03
Starduster_ has joined #bitcoin-wizards
21:05
Starduster has quit [Ping timeout: 240 seconds]
21:08
wizkid057 has joined #bitcoin-wizards
21:12
go1111111 has joined #bitcoin-wizards
21:13
bsm1175322 has joined #bitcoin-wizards
21:29
go1111111 has quit [Ping timeout: 255 seconds]
21:31
Aranjedeath has quit [Ping timeout: 240 seconds]
21:42
EvilHero_ has quit [Ping timeout: 260 seconds]
21:59
EvilHero_ has joined #bitcoin-wizards
21:59
GreenIsMyPepper has quit [Ping timeout: 258 seconds]
22:00
espes__ has quit [Ping timeout: 252 seconds]
22:00
Marquess_Loaf has joined #bitcoin-wizards
22:01
espes__ has joined #bitcoin-wizards
22:02
EvilHero_ has quit [Remote host closed the connection]
22:03
GreenIsMyPepper has joined #bitcoin-wizards
22:03
Uglux has quit [Ping timeout: 240 seconds]
22:08
EvilHero_ has joined #bitcoin-wizards
22:10
EvilHero_ has quit [Read error: Connection reset by peer]
22:11
espes__ has quit [Remote host closed the connection]
22:12
LeMiner has quit [Read error: Connection reset by peer]
22:14
JackH has quit [Remote host closed the connection]
22:15
GreenIsMyPepper has quit [Ping timeout: 240 seconds]
22:15
huseby has quit [Ping timeout: 276 seconds]
22:17
espes__ has joined #bitcoin-wizards
22:18
Guyver2 has quit [Quit: :)]
22:23
GreenIsMyPepper has joined #bitcoin-wizards
22:28
GreenIsMyPepper has quit [Ping timeout: 240 seconds]
22:32
sipa has joined #bitcoin-wizards
22:38
GreenIsMyPepper has joined #bitcoin-wizards
22:40
huseby has joined #bitcoin-wizards
22:43
Aranjedeath has joined #bitcoin-wizards
22:46
Ylbam has quit [Ping timeout: 240 seconds]
22:49
Ylbam has joined #bitcoin-wizards
22:53
NewLiberty has quit [Ping timeout: 255 seconds]
22:54
rodarmor has quit [Read error: Connection reset by peer]
22:55
PsychoticBoy has quit [Ping timeout: 276 seconds]
22:55
jl2012 has quit [Ping timeout: 240 seconds]
22:58
Ylbam has quit [Read error: Connection reset by peer]
23:01
jl2012 has joined #bitcoin-wizards
23:04
Ylbam has joined #bitcoin-wizards
23:05
PsychoticBoy has joined #bitcoin-wizards
23:11
rodarmor has joined #bitcoin-wizards
23:14
jtimon has joined #bitcoin-wizards
23:19
jtimon has quit [Remote host closed the connection]
23:21
tromp has quit [Read error: Connection reset by peer]
23:21
tromp has joined #bitcoin-wizards
23:42
wasi has quit [Ping timeout: 240 seconds]
23:49
jtimon has joined #bitcoin-wizards
23:53
GreenIsMyPepper has quit [Ping timeout: 240 seconds]
23:53
GreenIsMyPepper has joined #bitcoin-wizards
23:56
wasi has joined #bitcoin-wizards