logoalt Hacker News

adastra22yesterday at 6:40 PM1 replyview on HN

You're assuming a hash preimage attack, which would be a complete break of the cryptosystem. (Your link only works on the toy implementation given.)


Replies

teravoryesterday at 7:16 PM

there is no preimage attack involved.

while you cannot take control over the hash output you can bias it because you have multiple tries. that's how bitcoin mining works too...

for cryptographic applications any bias can be engineered to be fatal in one way or another.