Anonymous (nobody@replay.com)
Wed, 15 Jul 1998 21:33:13 +0200
> I guess I don't see why the ratio of sim time to hash time is useful.  
> Presumably the attacker can duplicate the generator and feed that to the
> hash.  They have to do it many times to find the collision.  
Put briefly, while we assume that no mathematical algorithm (like checking
results of simulations for collisions) can make a collision faster than a
birthday attack, I don't think we assume that an algorithm involving a
physical blackbox (like checking actual results for collisions) can't. 
The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:20:24 ADT