3 ms·
This is wrong. There is no faster way for preimage attacks with truncated SHA-2. http://crypto.stackexchange.com/questions/9435/is-truncating-a-sha512-hash-to-
by Nutomic 10y ago
This is wrong. There is no faster way for preimage attacks with truncated SHA-2.
http://crypto.stackexchange.com/questions/9435/is-truncating-a-sha512-hash-to-the-first-160-bits-as-secure-as-using-sha1 http://crypto.stackexchange.com/questions/9435/is-truncating...
- hvidgaard 10y agoI never said that, at all. I explicitely say At best you reduce the brute force complexity, at worst you enable pre-image attacks. One thing I hate about crypto talk is statements like this So, truncating one of the SHA-2 functions to 160 bits is around 2^20 times stronger when it comes to collision resistance. Which is all too broad. What if SHA-1 is down to 2^10, is truncated SHA-2 2^30? Does it mean we have proved that no weakness exist in SHA-2? A correct statement would simply be that no known attack exists on truncated SHA-2 yet.