Skip this advertisement >
Please wait while the page is being loaded
Friday | 16 May, 2008
ARN

News

Research reveals flaw in storage algorithm
Chris Mellor (Techworld) 25 August, 2004 15:17:10

ARN Directory | Distributors relevant to this article
ARN Directory | Vendors relevant to this article
Related Stories
  • +

    Bugs put widely used DNS software at risk 27 April, 2006 08:17:38

    Researchers have discovered new vulnerabilities in the widely used DNS server software.
    A number of flaws in the software that is used to administer the Internet's DNS (domain name system) has been discovered by researchers at Finland's University of Oulu.
  • +

    Researchers find security flaw in SHA-1 algorithm 17 February, 2005 12:05:32

    Scientists in China have written a paper describing a way to breaking SHA-1, an algorithm used for secure online communications.
    Security experts are warning that a security flaw has been found in a powerful data encryption algorithm, dubbed SHA-1, by a team of scientists from Shandong University in China. The three scientists are circulating a paper within the cryptographic research community that describes successful tests of a technique that could greatly reduce the speed with which SHA-1 could be compromised.
  • +

    Mimosa debuts e-mail discovery 17 August, 2006 07:55:24

    Mimosa Systems this week unveiled legal discovery and compliance modules for its e-mail archiving and continuous data protection software.
  • +

    Experts warn some CAS arrays at risk 08 February, 2005 11:31:16

    Security experts are warning against the use of a flawed hashing algorithm, MD5, for digital signatures to store data securely on increasingly popular content addressed storage (CAS) systems.
  • +

    StorageTek gets serious about CAS 04 November, 2004 08:20:35

    Storage Technology (StorageTek) is adding content-addressable store technology (CAS) to its range of storage products. According to an industry source, StorageTek is taking technology from Permabit and will announce an OEM deal in two weeks' time.

Researchers have discovered a flaw in the MD5 algorithm that is used to provide a unique signature for data.

Xiaoyun Wang, a Chinese expert, and three colleagues have discovered the flaw in the hash function algorithm, which is used in applications, such as EMC's Centera content-addressable file store. The flaw was revealed at the Crypto 2004 conference.

A duplicated hash value is called a collision. Such a hash function is not un-crackable. It relies for its effectiveness on the great amount of time required to break it. Until the Chinese team's work, several million hours of compute time would have been needed. They showed that it could be done within a few hours on a standard PC.

If MD5 is flawed then data uniqueness cannot be guaranteed. Thus, for example, Centera's ability to guarantee data integrity would be compromised and compliance regimes based on it could no longer be trusted. MD5 is also used by the Apache web server to guarantee integrity of downloadable source code data on mirror sites. Sun also uses it in its Solaris fingerprint database to assure the integrity of downloadable binary files.

Another hash function algorithms also used in data integrity applications, were also shown to be vulnerable at the same conference. However the SHA-1 vulnerability is not as severe as that shown with MD5.

What is the real effect of this?

The MD5 flaw could be used by a malicious hacker to get corrupted code onto unsuspecting users' machines by means of a forged hash code that deceives the affected server into treating the corrupted code as safe.

As an instance of this it is reported by Byte and Switch that Val Bercovici, Network Appliance’s chief technical architect of ILM data protection and compliance solutions, thinks there is now a problem with content-addressed storage - single-instance storage as he puts it. The MD5 flaw provides hackers with a shortcut method to crack the algorithm.

What might happen is that a hacker could generate a script to create a binary file with the same content address as an existing file. This cloned file could be sent to the hacker as an e-mail attachment, which gets stored in an MD5-based system. Then the hacker mails out the original file, which happens to contain sensitive or secret data. Because its hash value is the same as the cloned attachment the MD5 system doesn't store it. There is then no record of the secret data being sent out.

While theoretically possible in the future this is not what the four Chinese researchers actually showed, according to Roy Sanford, EMC’s VP of CAS, mentioned in the same report. They showed random files could have duplicate addresses. They didn't generate a file which specifically had the same address as a target file. He also points out that Centera uses MD5 plus another EMC algorithm which has not been shown to be vulnerable. Centera files have not been demonstrated to be compromised.

Crypto 2004's chairman, Jim Hughes, is reported elsewhere as commenting that MD5 is now compromised and data integrity methods using it had better move on to use better algorithms.

ARN Directory | Distributors relevant to this article
ARN Directory | Vendors relevant to this article
Market Place

ARN Member Login

 
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
ARN news
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Australian water treatment company uses four GFI products to protect its network

OSMOFLO, an Australian company, implemented a suite of four GFI products to protect its network from viruses and spam, to monitor and control internet usage and to save time and money on faxing.

Sponsored Links