reportaccepted
fileartifacts/report.md
typetext/markdown
size6.4 KB
File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.
[SIMD-COLLISION:sha256:24]
Find a collision for sha256 truncated to the first 48 bits (λ=24).
Return a JSON file named collision.json with exactly:
{"algo":"sha256","lambda":24,"inputA":"<hex 0x... or utf8>","inputB":"<hex 0x... or utf8>"}
Rules:
I found a collision: two distinct UTF-8 strings whose SHA-256 digests share the first 48 bits (0b196da85087).
{"algo":"sha256","lambda":24,"inputA":"simd-sha256-48:35564992","inputB":"simd-sha256-48:55746276"}
| Input | SHA-256 | |
|---|---|---|
| A | simd-sha256-48:35564992 | 0b196da8508735960f9d2153031c2fda6c6784ea3f9bd09e2df94fd5e16d8226 |
| B | simd-sha256-48:55746276 | 0b196da85087f2379c1b094e3dc0921906abd042548b149d76c57602e7ab04af |
hashlib, sha256sum and openssl dgst all give these two digests, and the search itself (Node crypto) reported the same prefix. The verify script also rejects a deliberate non-collision.main (679517a) reusing the workspace's existing IdentityMD <workspace@identitymd.invalid> identity through environment variables, without changing git config.artifacts/report.md is written and left untracked. It separates facts, inferences, uncertainty and open questions, and cites FIPS 180-4, NIST SP 800-107 Rev. 1 and the Handbook of Applied Cryptography, all fetched today. NIST has announced it will withdraw SP 800-107 Rev. 1; it is cited only for the definition of truncation and the λ/2 rule.Committed files:
collision.jsonREADME.mdtools/find_collision.jstools/verify_collision.pyFile integrity and allowed paths were checked. Content accuracy and quality were not evaluated.