Technology Review - Published By MIT
Advertisement

TR Editors' blog

Insights, opinions, and our editors' analysis of the latest in emerging technologies.

Blog Topics

Recent Posts

Recent Comments

  • djweber : This specific case is in all likelihood a complete scam. The assistant is the one decides what...
  • walt : I hope those students learn that "burn...volts" makes no sense.
  • doanwon : My first thought is whenever the magnetic field aligns the coil, it will exert a force parallel...
  • plasticdoc : This is just one subject which could be used to prevent boredom when teaching young students the...
  • bildan : The ground systems depend on where you are and what equipment you have.  It can be either fully...
  • ... : Students showcase a new wave of biological machines.
  • ... : Very informative...  I enjoyed and learned.
  • ... : Wow!!! I have view your article and this is interesting and very useful. I need any more...
  • nancy16 : When doing research on cancer. Scientist should not indulge in whether the cancer was inherited...
  • david k : There is strong history of the street view as art.  Ed Ruscha took photos along the Sunset Strip...
Advertisement
Monday, November 17, 2008

The Nostradamus Attack

When does cryptography collide with the work of Nostradamus?
By Erica Naone

As early as November 2007, a group of security researchers predicted that Barack Obama would be elected president this month. But before you get too impressed, you should know that they also created predictions for John McCain, Ralph Nader, and Paris Hilton. Anyone can come up with a bunch of bum predictions, but what matters here is that the researchers came up with a scheme that could have allowed them to present any one of these predictions as their single guess.

The researchers created the scheme to illustrate a point about cryptographic hash functions, which are key building blocks of secure protocols on the Internet, including those used for e-commerce. Cryptographic hash functions reduce a message of any size to a "digital fingerprint" of a set size, which can then be used as a stand-in for the original. The idea is that, from the fingerprint, it won't be possible to derive the original message. It also shouldn't be easy to find "collisions"--two messages that produce the same fingerprint. These fingerprints can be used as digital signatures. In other words, I could send you the fingerprint as proof of my prediction, and then reveal the prediction itself at a later time.

The researchers' predictions, which all look like perfectly ordinary PDF files, are a virtuosic example of producing collisions. Every one of the researchers' predictions has the same fingerprint when using the cryptographic hash function MD5, which was broken in 2005 by Xiaoyun Wang, a professor at the Center for Advanced Study at Tsinghua University, in China, and her coauthors. The researchers' Web page explains the work in more detail.

For more about cryptographic hash functions, look for a story tomorrow about the current search for a new standard algorithm.

Comments

  • Interpretation of Nostradamus
    This blog gave me the best chuckle of the day.

    There have been so many variant interpretations of the "predictions" made by Nostradamus that it seems to require a peculiar brain function hash to churn out a presumed tie of some actual event to a passage in Nostradamus' cryptic writings.

    Most appropriate title I've seen in a long time!
    Rate this comment: 12345

    wbdeville
    11/18/2008
    Posts:14
    Avg Rating:
    5/5
Advertisement

Log In

Forgot your password?     Register »
Advertisement
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
•  Subscribe
Save 36%
•  Table of Contents
•  MIT News
» Gift Subscription
» Digital Subscription
» Reprints, Back Issues
» Subscribe
» Table of Contents
» MIT News

More Technology News from Forbes

Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.