I know it is not trivial but to start off with a known broken hash would be a big mistake in my opinion. There have been some pretty impressive demos regarding this.
A collision in under a minute would seem to me to qualify as 'broken' for all practical purposes of this particular has function for the purpose of proving a document was not modified after it was signed.
That that minute is still a substantial number of cycles is not too relevant given the importance of the documents that are being modified, it counts as a 'non-expense'.
Comments
I know it is not trivial but to start off with a known broken hash would be a big mistake in my opinion. There have been some pretty impressive demos regarding this.
http://cryptography.hyperlink.cz/MD5_collisions.html
A collision in under a minute would seem to me to qualify as 'broken' for all practical purposes of this particular has function for the purpose of proving a document was not modified after it was signed.
That that minute is still a substantial number of cycles is not too relevant given the importance of the documents that are being modified, it counts as a 'non-expense'.