Technology Review - Published By MIT
Advertisement

TR Editors' blog

Insights, opinions, and our editors' analysis of the latest in emerging technologies.

Blog Topics

Recent Posts

Recent Comments

  • BigD : /facepalm
  • mland : doesn't it bother anyone that bacteria can be treated like legos? what if these get loose? how...
  • kstauff : So let me get this straight:  we're borrowing money from the Chinese to create a stimulus package...
  • ... : Well done!  This reminds me of the seeds from the South American Tipu tree we have in our...
  • Erica... : Thanks for this, dbkane! That's a funny coincidence.
  • ... : Stat above may be incorrect. Reports suggest most eWaste collected in the US is exported abroad....
  • TooMany : Many people think they have the flu when they just have a cold.  Perhaps there are mild cases,...
  • TooMany : Do you find more long-term thinking in our glib approach to coming disaster than you find in the...
  • dbkane : Serge Belongie, the vocalist and guitar player in the second video clip in the YouTube video...
  • billdyszel : The vast majority of the e-waste that leaves the US goes to Canada, where it is smelted, because...
Advertisement
Monday, November 17, 2008

The Nostradamus Attack

When does cryptography collide with the work of Nostradamus?
By Erica Naone

As early as November 2007, a group of security researchers predicted that Barack Obama would be elected president this month. But before you get too impressed, you should know that they also created predictions for John McCain, Ralph Nader, and Paris Hilton. Anyone can come up with a bunch of bum predictions, but what matters here is that the researchers came up with a scheme that could have allowed them to present any one of these predictions as their single guess.

The researchers created the scheme to illustrate a point about cryptographic hash functions, which are key building blocks of secure protocols on the Internet, including those used for e-commerce. Cryptographic hash functions reduce a message of any size to a "digital fingerprint" of a set size, which can then be used as a stand-in for the original. The idea is that, from the fingerprint, it won't be possible to derive the original message. It also shouldn't be easy to find "collisions"--two messages that produce the same fingerprint. These fingerprints can be used as digital signatures. In other words, I could send you the fingerprint as proof of my prediction, and then reveal the prediction itself at a later time.

The researchers' predictions, which all look like perfectly ordinary PDF files, are a virtuosic example of producing collisions. Every one of the researchers' predictions has the same fingerprint when using the cryptographic hash function MD5, which was broken in 2005 by Xiaoyun Wang, a professor at the Center for Advanced Study at Tsinghua University, in China, and her coauthors. The researchers' Web page explains the work in more detail.

For more about cryptographic hash functions, look for a story tomorrow about the current search for a new standard algorithm.

Comments

  • Interpretation of Nostradamus
    This blog gave me the best chuckle of the day.

    There have been so many variant interpretations of the "predictions" made by Nostradamus that it seems to require a peculiar brain function hash to churn out a presumed tie of some actual event to a passage in Nostradamus' cryptic writings.

    Most appropriate title I've seen in a long time!
    Rate this comment: 12345

    wbdeville
    11/18/2008
    Posts:14
    Avg Rating:
    5/5
Advertisement

Log In

Forgot your password?     Register »
Advertisement
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
•  Subscribe
Save 36%
•  Table of Contents
•  MIT News
» Gift Subscription
» Digital Subscription
» Reprints, Back Issues
» Subscribe
» Table of Contents
» MIT News

More Technology News from Forbes

Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.