SHA-1 collisions now at 2^{52}?

Perry E. Metzger perry at
Thu Apr 30 19:31:26 EDT 2009

Eric Rescorla <ekr at> writes:
> McDonald, Hawkes and Pieprzyk claim that they have reduced the collision
> strength of SHA-1 to 2^{52}.
> Slides here:
> Thanks to Paul Hoffman for pointing me to this.

This is a very important result. The need to transition from SHA-1 is no
longer theoretical.


The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at

More information about the cryptography mailing list