4 ms·
"1) Taking longer is not an indication of strength of the algorithm. Just like banging your head into a wall, multiple times isn't the best way to pass through
by Chronos 17y ago
"1) Taking longer is not an indication of strength of the algorithm. Just like banging your head into a wall, multiple times isn't the best way to pass through it."
You do realize that this is how all modern "cryptographically secure" hash functions work, right? For that matter, so do the symmetric-key block ciphers that hashes are closely related to. All of them simply use S-boxes to obfuscate the numbers, followed by repeated "rounds" of simple bitwise primitives (bitshift, and, xor, perhaps addition modulo a power of 2). There's no inherent mathematical reason why combinations of these simple functions should be strong, when each function individually is weak.
This is precisely why cryptography is such a tricky field to work in.
- mey 17y agoAgain, the "rounds" do not indicate execution time, thus execution time is not a good determination of how "secure" a hashing function is. There is inherent mathematical reasons why the combinations of the functions should be strong. It's why s-boxes are accepted practice. Agreed, cryptography is a tricky field. All the more reason to stick to systems that are carefully reviewed by experts smarter them myself and you.