Security Engineering MD nicht mehr → sha-256 preimage attacks → h(x) = y, find x collision attacks → h(x) = h(x’), find x, x’