2016 · 107 citations · 13 references
In response to high-profile attacks that exploit hash function collisions, software vendors have started to phase out the use of MD5 and SHA-1 in third-party digital signature applications such as X.509 certificates. However, weak hash constructions continue to be used in various cryptographic constructions within mainstream protocols such as TLS, IKE, and SSH, because practitioners argue that their use in these protocols relies only on second preimage resistance, and hence is unaffected by collisions. This paper systematically investigates and debunks this argument.
13
The Art of Computer Programming
G.E. Whitesides · Nuclear Science and Engineering · 1970 · 6.1K citations
A monte carlo method for factorization
J. M. Pollard · BIT Numerical Mathematics · 1975 · 400 citations
A cross-protocol attack on the TLS protocol
Nikos Mavrogiannopoulos, Fréderik Vercauteren, Vesselin Velichkov et al. · 2012 · 64 citations