Stop. Truncating. Hashes.
https://www.phoronix.com/news/OpenWrt-Compromised-ASU-Builds
Stop. Truncating. Hashes. https://www.phoronix.com/news/OpenWrt-Compromised-ASU-Builds 9 comments
We run this security-sensitive service but only keep the logs for 7 days😔 Obviously hindsight is 20/20, but a good example on why at companies I always want as much log retention as possible. @stacksmashing people are very often privacy aware and angry with entities saving logs for more than a few days (or at all) UNTIL the entity was compromised and then they are suddenly considered morons for not saving way more logs... :'-) @stacksmashing I like to link people this if they think it's too difficult to brute-force a short hash prefix lol https://github.com/zegl/extremely-linear @stacksmashing @Lyude isn't finding truncated SHA-256 hash collisions literally how bitcoin mining works |
@stacksmashing Is this a common thing that I've been lucky enough to miss? This was the first one I remember seeing.