# SHA-256 first-48-bit collision

## Result

The two distinct inputs in [collision.json](../collision.json) have identical
SHA-256 prefixes of 48 bits (six bytes, or 12 hexadecimal digits):
`982915e7a9c2`. The requested lambda is 24.

Inputs are literal UTF-8 strings, without quotation marks, trailing newline,
or NUL terminator:

| Field | Input |
| --- | --- |
| inputA | `identitymd-sha256-48:2529407` |
| inputB | `identitymd-sha256-48:14013952` |

Full SHA-256 digests, computed locally:

```text
inputA: 982915e7a9c29943c3a92478787f91a152cfdac962fe052297f900b3d91ea35d
inputB: 982915e7a9c2a37130deb136c85bc2e61ce0a6a78b80ae9ff07c95f829fe9a38
```

## Method and attributable evidence

A local C search enumerated decimal counters starting at zero, hashing UTF-8
messages of the form `identitymd-sha256-48:<counter>` with the installed OpenSSL
library. A hash table indexed the first six digest bytes and checked matching
prefixes. It found the pair after 14,013,953 candidate messages; this count
excludes additional hash computations used to check occupied table slots.

The delivered [verify.py](../verify.py) recomputes both full digests with Python's
standard-library `hashlib`, checks the exact JSON field set and parameters,
checks that decoded input bytes differ, and compares the first six bytes.
Run from the repository root:

```sh
python3 verify.py
```

Observed output:

```text
inputA SHA-256: 982915e7a9c29943c3a92478787f91a152cfdac962fe052297f900b3d91ea35d
inputB SHA-256: 982915e7a9c2a37130deb136c85bc2e61ce0a6a78b80ae9ff07c95f829fe9a38
PASS: distinct inputs; shared 48-bit MSB prefix: 982915e7a9c2
```

Each input was also passed as exact UTF-8 bytes through standard input to
`openssl dgst -sha256` (OpenSSL 3.0.13). Both returned the full digests above.
These are original local measurements, with reproducible evidence in the
delivered input file and verifier; no external factual sources are needed.

## Interpretation and limits

The matching leading six bytes establish the requested truncated collision.
The remaining bytes differ: this is not a full SHA-256 collision. The checks
were separate invocations, not an independent third-party review; Python and
the OpenSSL command line may share an underlying cryptographic implementation.
SIMD verification was not available or run here, so its eventual acceptance
remains unobserved. No uncertainty remains in the locally observed prefix
equality, subject to the correctness of those local hashing implementations.
