3 ms·
SHA-224, SHA-256, SHA-384 and SHA-512 is any one better than another? for instance, the way AES-256 and -192 are considered potentially less secure than 128, a
by rubyrescue 16y ago
SHA-224, SHA-256, SHA-384 and SHA-512
is any one better than another? for instance, the way AES-256 and -192 are considered potentially less secure than 128, at least according to something i read from Schneier a while back.
- tptacek 16y agoThere are attacks against AES-256 that haven't been extended back to smaller key sizes. If you're typing the letters S-H-A-2-5-6 into your code, you're doing something wrong; you should be using GPG, or Keyczar, or some other high-level interface that has chosen the algorithms for you and deployed them safely. That said, the standard practice today in new software that will be audited is SHA256. All this web page says is "don't use SHA1".
- cperciva 16y agoIf you're typing the letters S-H-A-2-5-6 into your code, you're doing something wrong... Oh come on. This comment wasn't entirely unreasonable when it was about AES, but saying that nobody should use SHA256 directly is just plain silly. How do you verify that the FreeBSD ISO image you downloaded is intact if not by typing # sha256 FreeBSD-7.3-RELEASE-amd64-disc1.iso
- rubyrescue 16y agoAgreed, first of all, it wouldn't compile with all those dashes...
- cperciva 16y agoThe only attacks against AES-256 are related-key attacks, and you need to screw up pretty profoundly in order to be affected by those. The only justification for using anything other than SHA-256 as a hash is if you know that you're only ever going to run on 64-bit machines, in which case SHA-512 might be preferable (it's defined in terms of 64-bit arithmetic and is faster than SHA-256 on 64-bit machines).