Author pitrou
Recipients Arach, Arfrever, Huzaifa.Sidhpurwala, Jim.Jewett, Mark.Shannon, PaulMcMillan, Zhiping.Deng, alex, barry, benjamin.peterson, christian.heimes, dmalcolm, eric.snow, fx5, georg.brandl, grahamd, gregory.p.smith, gvanrossum, gz, haypo, jcea, lemburg, loewis, mark.dickinson, merwok, neologix, pitrou, skrah, terry.reedy, tim.peters, v+python, zbysz
Date 2012-01-27.20:25:13
SpamBayes Score 0.0610729
Marked as misclassified No
Message-id <1327695914.19.0.0339252748661.issue13703@psf.upfronthosting.co.za>
In-reply-to
Content
[Martin's approach]
> The point I first missed is that this triggers only when the hash is
> *fully* equal; if the hashes are merely equal after masking, then
> today's try-another-slot approach will still be used, even for
> strings.

But then isn't it vulnerable to Frank's first attack as exposed in
http://mail.python.org/pipermail/python-dev/2012-January/115726.html ?
History
Date User Action Args
2012-01-27 20:25:14pitrousetrecipients: + pitrou, lemburg, gvanrossum, tim.peters, loewis, barry, georg.brandl, terry.reedy, gregory.p.smith, jcea, mark.dickinson, haypo, christian.heimes, benjamin.peterson, merwok, grahamd, Arfrever, v+python, alex, zbysz, skrah, dmalcolm, gz, neologix, Arach, Mark.Shannon, eric.snow, Zhiping.Deng, Huzaifa.Sidhpurwala, Jim.Jewett, PaulMcMillan, fx5
2012-01-27 20:25:14pitrousetmessageid: <1327695914.19.0.0339252748661.issue13703@psf.upfronthosting.co.za>
2012-01-27 20:25:13pitroulinkissue13703 messages
2012-01-27 20:25:13pitroucreate