Author Topic: SHA-1  (Read 7692 times)

Offline Cassiel

  • Administrator
  • Hero Member
  • *****
  • Posts: 1574
    • Email
SHA-1
« on: January 31, 2011, 04:18:50 PM »
Right, now the release is out the way what's the consensus on making the inclusion of SHA-1 hashes on all new DATs "official"?

We had discussed previously, but I don't recall a final resolution (since the release was looming). As DiaboĊ‚ has already noticed, we already have a mix of DATs with SHA-1 included (as well as CRC32 and MD5 of course) in both main and ISO, as well as nearly all in PIX.

Having hashes for CRC32, MD5 and SHA-1 in each DAT just gives a bit more flexibility, albeit with a small size increase.

So.... make it an official rule for all new/updated DATs moving forward?



Offline Aral

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 414
Re: SHA-1
« Reply #1 on: January 31, 2011, 10:38:51 PM »
Yeah Cassiel we made the decision just after the 2010-01 release of PIX to include SHA-1 hashes and it has been a good move IMO.  We found that we had a couple of PDF's with the same CRC but different SHA-1's.

I support the decision to use it in the main branch.

Offline PandMonium

  • Administrator
  • Hero Member
  • *****
  • Posts: 1332
Re: SHA-1
« Reply #2 on: February 01, 2011, 11:37:51 PM »
As Aral said, due to the crc32 hash length, different files are much more prone to collisions. This problem was in part already solved by using MD5, SHA1 is just an improvement on that.

I already said i agree with the addition of SHA1, other projects already made the change (from md5 to sha1) long ago. My only question is if there is a need to keep both (md5, sha1), given their nature.

Maybe we should keep both, based on the goal of our project and thinking that they can be useful for anyone (how?), although it will make dats a bit bigger.

So, include sha1 in your dats, at least until we decide to change it again one day and deprecate both to use SHA-512 or Whirlpool :P

Offline Aral

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 414
Re: SHA-1
« Reply #3 on: February 02, 2011, 10:38:03 AM »
great news :)

Offline Symmo

  • TOSEC Contributor
  • Jr. Member
  • **
  • Posts: 55
Re: SHA-1
« Reply #4 on: February 03, 2011, 01:31:03 PM »
I would keep md5 seeing that some p2p use them .
So u could still scan for a md5 on such networks etc..

Try this as your wallpaper if you are new :-) http://symmo.net/tosec/tosectnc.png

Offline Cassiel

  • Administrator
  • Hero Member
  • *****
  • Posts: 1574
    • Email
Re: SHA-1
« Reply #5 on: February 03, 2011, 02:02:09 PM »
Symmo,

MD5 won't be removed. The idea is to include CRC32, MD5 and SHA-1, and let the end user decide what hash they want to use.

Choice/flexibility = good   :)

Offline Symmo

  • TOSEC Contributor
  • Jr. Member
  • **
  • Posts: 55
Re: SHA-1
« Reply #6 on: February 03, 2011, 03:32:49 PM »
Hi cassiel
was just responding to My only question is if there is a need to keep both (md5, sha1), given their nature.
Then again maybe i read it wrong .

Try this as your wallpaper if you are new :-) http://symmo.net/tosec/tosectnc.png

Offline Cassiel

  • Administrator
  • Hero Member
  • *****
  • Posts: 1574
    • Email
Re: SHA-1
« Reply #7 on: February 03, 2011, 04:36:25 PM »
Oh, I see....  :)

Offline PandMonium

  • Administrator
  • Hero Member
  • *****
  • Posts: 1332
Re: SHA-1
« Reply #8 on: February 03, 2011, 08:26:13 PM »
You didn't! It was really a question to discover what others think about it and if there is a clear advantage or disadvantage in doing so. :P

Offline TKaos

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 539
Re: SHA-1
« Reply #9 on: February 03, 2011, 08:48:28 PM »
Well which DAT tool I can use to create SHA-1+MD5 DATs?
TIM don't have this option and I dislike creating DATs with clrmame cause it takes ages.

Offline PandMonium

  • Administrator
  • Hero Member
  • *****
  • Posts: 1332
Re: SHA-1
« Reply #10 on: February 03, 2011, 10:50:12 PM »
Maybe you can use Dat Workshop or some tool like that...
If not i guess we can finally have a really small app to create dats, specific to TOSEC that would even be a bit easier to use...

Offline Cassiel

  • Administrator
  • Hero Member
  • *****
  • Posts: 1574
    • Email
Re: SHA-1
« Reply #11 on: February 03, 2011, 11:42:18 PM »
I did! Just meant I now realise he responding to your question....    ;)

Offline Cassiel

  • Administrator
  • Hero Member
  • *****
  • Posts: 1574
    • Email
Re: SHA-1
« Reply #12 on: February 03, 2011, 11:48:25 PM »
TKaos - DatUtil can create DATs too (I think). Why you think CMP slow though? That's certainly not been my experience (especially compared to dinosaur TIM!). Maybe an overly aggressive AV app is causing the slowdown? Just an idea....

PandMonium - I love the idea of a TOSEC branded DAT creation tool though..... go on, you know it makes sense! Why waste your time at Uni doing actual work towards your qualifications when you can spend it on something important such as this....   ;)

Offline Aral

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 414
Re: SHA-1
« Reply #13 on: February 04, 2011, 08:45:00 AM »
LOL ;)