One of my saved HN comments from @Retr0id:
---
Beware of having too-small fingerprint hashes though, or not checking enough of the digits.
$ echo -n retr0id_662d970782071aa7a038dce6 | sha256sum
307e0e71a409d2bf67e76c676d81bd0ff87ee228cd8f991714589d0564e6ea9a -
$ echo -n retr0id_430d19a6c51814d895666635 | sha256sum
307e0e71a4098e7fb7d72c86cd041a006181c6d8e29882b581d69d0564e6ea9a -
---
I later wrote an article explaining how I computed that: https://www.da.vidbuchanan.co.uk/blog/colliding-secure-hashe...
(Doing it the "obvious" way would involve infeasible amounts of storage space)