# SHA-256 collision truncated to 48 bits

The locally verified collision is saved in [collision.json](../collision.json).
The inputs are literal UTF-8 strings with no trailing newline or zero byte.

| Field | inputA | inputB |
| --- | --- | --- |
| Input | `identitymd-sha256-48:2529407` | `identitymd-sha256-48:14013952` |
| Byte length | 28 | 29 |
| SHA-256 | `982915e7a9c29943c3a92478787f91a152cfdac962fe052297f900b3d91ea35d` | `982915e7a9c2a37130deb136c85bc2e61ce0a6a78b80ae9ff07c95f829fe9a38` |
| First 48 bits, MSB | `982915e7a9c2` | `982915e7a9c2` |

## Method and attributable evidence

[search.py](search.py) enumerated ASCII strings `identitymd-sha256-48:N`, starting
with N=0, and stored each SHA-256 six-byte prefix in an open-addressed table.
It found the pair after 14,013,953 hash evaluations; the measured search-loop
duration was 39.345 seconds, excluding table allocation.

[verify.py](verify.py) reads the delivered JSON, checks its exact key set,
algorithm and lambda, decodes the inputs, asserts their byte strings differ,
and recomputes both complete digests using Python hashlib and the OpenSSL CLI.
The two interfaces agreed on both complete digests. The CLI reported
OpenSSL 3.0.13 (30 Jan 2024). Run from the repository root:

```sh
python3 artifacts/verify.py
```

Observed verification output:

```text
inputA: bytes=28 sha256=982915e7a9c29943c3a92478787f91a152cfdac962fe052297f900b3d91ea35d
inputB: bytes=29 sha256=982915e7a9c2a37130deb136c85bc2e61ce0a6a78b80ae9ff07c95f829fe9a38
PASS: distinct inputs; shared first 48 bits = 982915e7a9c2
```

## Conclusion and limits

The observed digest equality over the first six bytes establishes the requested
48-bit truncated collision (lambda=24). The full SHA-256 digests differ.
These are local measurements, not an independent review: hashlib and the CLI
may share an OpenSSL implementation. SIMD verification was not available in
this environment, so its acceptance remains unobserved. No external research
claims or estimated digests are used as evidence.
