1. 4
  1.  

  2. [Comment removed by author]

    1. 4

      I think one of the replies is also really informative:

      To abuse this property you need to get the state of the hash to match a state you get when running the decryption of the blockcipher underlying the compression function. Finding such a match requires a meet-in-the-middle attack with cost $2^{n/2}$ and thus isn’t cheaper than finding a collision.

    2. 8

      I feel like an “inaccurate” tag would be in order.

      1. 5

        It feels slightly odd that there’s an “incorrect” downvote for posts, but no “incorrect” flag for articles.

        1. 2

          I’d add it if it existed :D