SHA-1 collisions now at 2^{52}?

Eric Rescorla ekr at
Thu Apr 30 17:37:18 EDT 2009

McDonald, Hawkes and Pieprzyk claim that they have reduced the collision
strength of SHA-1 to 2^{52}.

Slides here:

Thanks to Paul Hoffman for pointing me to this.


