A security researcher discovers a vulnerability in a custom cryptographic protocol. The protocol uses a hash function for message integrity, but instead of using a keyed hash (like HMAC), it concatenates the secret key with the message and then hashes the result (e.g., H(key || message)). Which cryptographic attack is this construction primarily vulnerable to?
- APreimage attack
- BSecond preimage attack
- CLength extension attack
- DCollision attack
Show answer & explanationAnswer & explanation
Correct answer: C. Length extension attack
Concatenating the key before the message (H(key || message)) makes the construction vulnerable to length extension attacks. For hash functions built using Merkle-Damgård construction (like MD5, SHA-1, SHA-2), an attacker who knows the hash output and the length of the original message (and key) can append arbitrary data to the message and calculate a valid hash for the extended message without knowing the secret key.
Why the other options are wrong
- A. A preimage attack aims to find a message that produces a given hash, which is not the primary vulnerability of this construction.
- B. A second preimage attack aims to find a different message that produces the same hash as a known message, also not the primary vulnerability here.
- D. A collision attack aims to find two different messages that produce the same hash, but this specific construction vulnerability is about extending a message, not finding collisions.
Length Extension Attack
A length extension attack is a type of cryptographic attack where an attacker can use a hash value for a secret key and a message to calculate the hash value of a new message that includes the original message plus some chosen data, without knowing the secret key. It applies to hash functions built on the Merkle-Damgård construction when the key is prepended to the message.
- Applicable to Merkle-Damgård hashes (MD5, SHA-1, SHA-2).
- Exploits H(key || message) construction.
- Allows extending message and computing new valid hash.
- Mitigated by HMAC or H(message || key) or H(key || message || key).
Memory trick: Preimages find input, collisions find pairs, length extension extends.