4 ms·
SeaHash is obviously not cryptographic (nor is SipHash), but I hope it is a secure PRF (i.e. the keys cannot be extracted), and this was the best attack I was a
by ticki_ 10y ago
SeaHash is obviously not cryptographic (nor is SipHash), but I hope it is a secure PRF (i.e. the keys cannot be extracted), and this was the best attack I was able to construct. Still, it isn't a practical attack, but I suppose it is possible to improve.
Note that I am not a cryptographer, and my only piece of advice is: For the sake of god, don't use hash functions not designed for cryptographic security, if you need cryptographic security. It's that simple.
- tptacek 10y agoSipHash is a cryptographic hash with a pretty good pedigree. The distinction between SipHash and Blake2 is more subtle than "cryptographic vs not".
- dom0 10y agoSure. For starters SipHash targets a lower-end spectrum of device (in a way) than Blake2, and is also less flexible. Since SipHash produces a 64 bit digest it isn't suitable for many applications in the first place. The two also differ significantly in other cryptographic properties, making Blake2 a more secure and easier (safer) to apply choice. I would tend to say that SipHash is, in a cryptographic context, more an "if you know what you're doing" choice, and not at all a general purpose [cryptographic] hash function.
- ticki_ 10y agoNo, it's not a cryptographic hash function. It's a MAC function. The paper clearly states that it is not collision resistant.
- kibwen 10y agoI believe that you and tptacek may be using differing definitions of "cryptographic", because he tends to knows what he's talking about when it comes to cryptography (e.g. https://gist.github.com/tqbf/be58d2d39690c3b366ad https://gist.github.com/tqbf/be58d2d39690c3b366ad).
- ticki_ 10y agoOh, well. What I think of as "cryptographic hash function" is a function resistent to pre-image attack, second pre-image attack, and collision generation. Neither of those are satisfied by SipHash, and can thus not classify as a cryptographic hash function by the normal definition.
- tptacek 10y agoIt's a cryptographic hash function, but not one suitable for all of the same applications as SHA2. It has security characteristics that other hash-table hashes (for instance) lack.
- ticki_ 10y agoIf you know the key, it is as weak as it gets (as the paper notes too, you can construct collisions easily if the key is known), so I disagree.