upvote
No, or we would have said so. It means that by relaxing the equations schedule somewhat, we are able to find a pair of differing messages that produce the same digest. However, we only relax the schedule a little bit, we still enforce 59 out of 64 schedule equations through the full 64 rounds - which is why we're only 92% of the way through to breaking it and not 100% of the way as we are with MD5. Importantly, we are not yet implementing the most advanced technique of Wang-style message modification, and we therefore expect that someone will be able to satisfy all 64 equations soon. This will result in an actual full-schedule, full-round collision. The previous record was only just 39 rounds out of 64 rounds, leaving 25 rounds, usually each of which mixes the message up completely. As mentioned in the paper, this attacks the problem from a different direction.
reply
I don't believe a word of this.
reply