Attacks on Cryptographic Hashes in Internet Protocols
RFC 4270, “Attacks on Cryptographic Hashes in Internet Protocols”, is an Informational document published in December 2005 by P. Hoffman, B. Schneier. The canonical text is published by the RFC Editor.
Abstract
Recent announcements of better-than-expected collision attacks in popular hash algorithms have caused some people to question whether common Internet protocols need to be changed, and if so, how. This document summarizes the use of hashes in many protocols, discusses how the collision attacks affect and do not affect the protocols, shows how to thwart known attacks on digital certificates, and discusses future directions for protocol designers. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4270 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4269 The SEED Encryption Algorithm
- RFC 4268 Entity State MIB
- RFC 4267 The W3C Speech Interface Framework Media Types: application/voicexml+xml, application/ssml+xml, application/srgs, application/srgs+xml, application/ccxml+xml, and application/pls+xml
- RFC 4266 The gopher URI Scheme
- RFC 4265 Definition of Textual Conventions for Virtual Private Network Management
- RFC 4264 BGP Wedgies
- RFC 4262 X.509 Certificate Extension for Secure/Multipurpose Internet Mail Extensions Capabilities
- RFC 4261 Common Open Policy Service Over Transport Layer Security