SHA256 vulnerability
github.com
github.com
https://en.wikipedia.org/wiki/One-way_compression_function#D...
"A notable property of the Davies–Meyer construction is that even if the underlying block cipher is totally secure, it is possible to compute fixed points for the construction"
That is all that has been done here.
[UPDATE] I was wrong. Turns out this is not a vulnerability at all:
https://crypto.stackexchange.com/questions/48580/fixed-point...
Even if it's true I'm not sure I understand how broad this attack vector could be. Can we generate collisions for any given hash or just a subset?
Given that SHA256 is used in cryptocurrencies it makes me even more skeptical, it could be an attempt at making the market crash with some FUD I guess.
I ran the example. Then I looked at the code. Then I ran random test vectors against hashlib.sha256.
It's not a slam-dunk, but if it's a hoax it's a damn good hoax.
The author effectively hard-coded values.
Really? How?
[UPDATE] Heh, you're right.
https://crypto.stackexchange.com/questions/48580/fixed-point...