4 ms·
No, it's not a cryptographic hash function. It's a MAC function. The paper clearly states that it is not collision resistant.
by ticki_ 10y ago
No, it's not a cryptographic hash function. It's a MAC function.
The paper clearly states that it is not collision resistant.
- kibwen 10y agoI believe that you and tptacek may be using differing definitions of "cryptographic", because he tends to knows what he's talking about when it comes to cryptography (e.g. https://gist.github.com/tqbf/be58d2d39690c3b366ad https://gist.github.com/tqbf/be58d2d39690c3b366ad).
- ticki_ 10y agoOh, well. What I think of as "cryptographic hash function" is a function resistent to pre-image attack, second pre-image attack, and collision generation. Neither of those are satisfied by SipHash, and can thus not classify as a cryptographic hash function by the normal definition.
- tptacek 10y agoIt's a cryptographic hash function, but not one suitable for all of the same applications as SHA2. It has security characteristics that other hash-table hashes (for instance) lack.
- ticki_ 10y agoIf you know the key, it is as weak as it gets (as the paper notes too, you can construct collisions easily if the key is known), so I disagree.