Delivery-Date: Thu, 08 Jan 2015 11:55:03 -0500
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.8 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED,
	RP_MATCHES_RCVD,URIBL_BLOCKED autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id 938F31E038E
	for <archiver@seul.org>; Thu,  8 Jan 2015 11:55:01 -0500 (EST)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id 3EB9C325D2;
	Thu,  8 Jan 2015 16:54:58 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id 22018325C5
 for <tor-talk@lists.torproject.org>; Thu,  8 Jan 2015 16:54:55 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at 
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id zVpA_c3rMKnw for <tor-talk@lists.torproject.org>;
 Thu,  8 Jan 2015 16:54:55 +0000 (UTC)
Received: from firemail.de (firemail.de [46.182.20.5])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by eugeni.torproject.org (Postfix) with ESMTPS id C86CF322C4
 for <tor-talk@lists.torproject.org>; Thu,  8 Jan 2015 16:54:54 +0000 (UTC)
Received: from N130 (p5DDDE61F.dip0.t-ipconnect.de [93.221.230.31])
 by firemail.de (b1gMailServer) with ESMTPS id 0D7F1945
 for <tor-talk@lists.torproject.org>; Thu, 08 Jan 2015 17:53:15 +0100 (CET)
X-ESMTP-Authenticated-User: 0001846A
Date: Thu, 8 Jan 2015 17:54:43 +0100
From: SecTech <tech@firemail.de>
To: tor-talk@lists.torproject.org
Message-ID: <20150108175443.42c9ff44@N130>
In-Reply-To: <20150107132537.31717@web007.roc2.bluetie.com>
References: <20150107132537.31717@web007.roc2.bluetie.com>
X-Mailer: [No Data]
MIME-Version: 1.0
Subject: Re: [tor-talk] New Software: P2P filesharing designed to use Tor
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

I don't meant to change the hash funktion from SHA-1 to SHA-256, I
meant to hash the 100 KB blocks and the higher level hashes with SHA-1
and to provide a SHA-256 hash that is generated from the file itself
too.
Because two hashes are more secure than one, even if one of them is
broken, because if someone can find a collision in one hash he can't
find a collision in the second at the same time.

The two hash method is only mode secure than a single hash, if someone
can't reverse calculate an information out of the hash. But SHA-1 is so
far I know only vulnarable to collisions at some specific conditions.

Maybe it will be mode secure to use RIPE-MD 160 for hashing the tree
hashes and provide a SHA-256 hash for the whole file too.


- -- 
SecTech <tech@firemail.de>
GPG-ID: 0x364CFE05

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJUrrZXAAoJENR4jiM2TP4FMbQP/jg8gBN+5xiSrx7rVOn/EvEl
OLzEUsrOwNWZ2nbDz2GRMWTRmieBxRxnpp8IYkWjVry7h2hEkfAGTWTF1zlj5KPJ
wNHxBb6Mlw9vlW79nnEdtgkANHgnlrxG/Gg0OYfV8YYquf5OMHvkXVwhv02U4sSr
NxpIFTCg98gXX5297Prn5Ro/n1IECmJuCnh2+qNMB0GdZSwPB3L210/nltkhGcBI
QV1jHc/AevLD4/QgdtV3iYmAHrIrmJ1wdXrlTMQXmmjQcuKL5keFBFXyWjwLBJeW
RO/SK+ph6WCIQrl9CZds3VNvDdR42gb8H8JftGUJv5hyEgiWTfnyD5tCFKi2XBg2
WzzZ+1kebeO0BDTZupgKQqwPc4aG/YrThk3EIX+YJ0vDqIyweTU01SLvapZ/TVS2
zqfroqZTJ43i1j/s275fUyQohUuPlAsViVLt3sOY/REfHwxxYfiiLrp8IEuZWRlT
w6jFxEwvao8o2UJXJ/fFsnJZG47JoXXTcNA8jvNxEqdzzCVrDFm3yWj+ftO+KxsI
nMrdAkvYEG3K7prw+5RY9RvSeRh7WSaaOfcTBFtk5S4d/dWwknTSgN4uFksgvbdy
dMrWNcBXPinLC6YNjKZZ6dTYll13jtC+RwuSmkjDjeOV6PWyiunyr6n6zP5tVZ4j
bGH914P8fcG3+mVuvLK6
=y6wA
-----END PGP SIGNATURE-----
-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

