Skip to content
Why is a raven like a writing desk?

Thoughts both confusing and enlightening.

Why is a raven like a writing desk?

Thoughts both confusing and enlightening.

SHA-1 Followup

elbeno, 19 February, 200529 July, 2007

More re the SHA-1 result:

  • Around $30M (give or take a few million) should build you a machine to find a collision in a few days.
  • What previously took (say) the NSA 40 years to figure out now takes about a week.
  • A second preimage attack is theoretically 2106, according to a Schneier paper.

If a registered game developer conspires with the XBox linux guys, the birthday attack (269) is quite possible. Actually this raises an interesting point similar to the Nintendo vs Codemasters wrangles of the late 80s (if I’m remembering that correctly). Imagine you are a big publisher that has its own manufacturing processes and doesn’t want to rely on MS. Here’s what you do (would this work?):

  1. Spend around $30m to get a machine to find a collision. (Expensive, but $30m isn’t so much more than the cost of developing a big title – depends what this is worth to you).
  2. Write 2 XBEs – one is a game you have in dev, one is a generic loader program.
  3. Make it so that the SHA-1 hashes of the 2 XBEs collide. (Assumedly not too hard; use the machine, and adjust a bit of random padding on both until you get a collision.)
  4. Publish the game as normal through MS. They sign the game. But the crucial point is that the same signature that is now on the game will also fool a retail XBox into loading your generic loader program.
  5. Job done – you now have a loader program that you can use to run any game, without having to submit anything else to MS. Let the legal battles begin…
Games Windows & MS

Post navigation

Previous post
Next post

Related Posts

IF Alert!

3 October, 200529 July, 2007

October is with us again, and that means the 11th Annual Interactive Fiction Competition is here. This year we have: 17 Z-code 7 TADS (including 1 TADS3) 2 Glulx 1 Hugo, 1 Alan, 5 Adrift And of course, 3 Windows native executables. Well I’m not holding out much hope for…

Read More

World of Warcraft

24 January, 200529 July, 2007

For a while there I was sorely tempted. Then, luckily for me, there was a spate of server problems, and Blizzard have stopped selling it for the time being. I read this morning that there is a last shipment in EB today, but the moment has passed. I can congratulate…

Read More

just fine them already

5 July, 200629 July, 2007

The EU has to back up its threat with action, and soon. The verdict is not so different to that of the US DoJ. But the eventual outcome of that case proved the DoJ toothless – where are they now? Now the EU has a chance to prove to the…

Read More

Comment

  1. gen_witt says:
    24 February, 2005 at 12:23 pm

    This works until they special case your key in a (forced) BIOS/kernel update. Interesting idea though, I also think that it _should_ be legal under the interoperability part of the DMCA, although who knows what's actually legal and what's illegal.

    (http://livejournal.com/users/gen_witt)

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

©2026 Why is a raven like a writing desk? | WordPress Theme by SuperbThemes