# SHA-256 collision for the first 48 bits

The requested collision is provided in [collision.json](../collision.json).
Both inputs are literal UTF-8 strings, with no trailing newline:

- inputA: `identitymd-sha256-48-33470631`
- inputB: `identitymd-sha256-48-39003384`

## Observed evidence

| Input | Full SHA-256 digest |
| --- | --- |
| inputA | `52b3d5bed12ac4bf555f73aeccadf4ee8f59b69258cdc319faa44d33648c6cc0` |
| inputB | `52b3d5bed12ad36c1fe698be56d9f3e61098e9de3f5cf17c642a547907f1f4bf` |

The first 12 hexadecimal digits (six bytes, or 48 most significant bits)
are identical: **`52b3d5bed12a`**. The inputs are distinct, and their full
digests differ.

These values were computed locally using Python's `hashlib.sha256` and
confirmed using the OpenSSL 3.0.2 command line tool. The machine-readable
Python check is saved in [verification.json](verification.json); its source
is [tools/verify_collision.py](../tools/verify_collision.py).

Reproduce the check from the repository root, without network access:

```sh
python3 tools/verify_collision.py
printf %s identitymd-sha256-48-33470631 | openssl dgst -sha256
printf %s identitymd-sha256-48-39003384 | openssl dgst -sha256
```

## Search and conclusion

[tools/search_collision.py](../tools/search_collision.py) enumerated strings
of the form `identitymd-sha256-48-N`, starting at N=1, and stored each
six-byte digest prefix until a duplicate appeared. The run found this pair
at evaluation 39,003,384, after 99.620 seconds. Search timing is a local
observation, not a performance guarantee. Rerunning the search requires
several gigabytes of memory; checking the supplied pair does not.

The conclusion that this pair satisfies the requested 48-bit collision
follows directly from the byte comparison. This is a truncated digest
collision; it does not establish a collision in all 256 bits.

## Limits and unanswered questions

All evidence here comes from local checks by the implementing agent.
Python and the OpenSSL command line tool may use the same underlying
cryptographic library, so they do not constitute independent implementation
validation. The external SIMD verifier has not been run in this environment;
its acceptance remains unobserved. No uncertainty remains in the locally
observed equality of the six-byte prefixes.
