Authors: Vincent Rijmen, Elisabeth Oswald


We report on the experiments we performed in order to assess the
security of SHA-1 against the attack by Chabaud and Joux. We present some ideas for optimizations of the attack and some properties of the message expansion routine.
Finally, we show that for a reduced version of SHA-1, with 53
rounds instead of 80, it is possible to find collisions in less
than 2^{80} operations.

ePrint: https://eprint.iacr.org/2005/010

