upvote
OK, produce a SHA-2 collision.
reply
In a successful exploit, the algo is rarely what's broken. As for SHA-2 itself, I would argue that man didn't make it any more than man made the additive identity; it was simply defined and used.
reply
Why a collision? Abuse it where it is being used. Infect the chain of certificates that guarantees that the hash you are checking is actually the one you want. Send a million legit documents with bad hashes, so that the forged one looks like another legit one. Infect the library that calculates hashes so that these specific documents have a special hardcoded hash.
reply
Because man made SHA-2, so it must be breakable. I don't dispute that there are systems humans make that are breakable (that would be weird given my career).
reply
deleted
reply