3 ms·
You seem to be operating under the same sort of "cryptographic hash functions are magic!" delusions as Linus. CRC and SHA1 both produce a uniform distribution.
by bascule 10y ago
You seem to be operating under the same sort of "cryptographic hash functions are magic!" delusions as Linus.
CRC and SHA1 both produce a uniform distribution. SHA1 does not magically do this better because cryptography. The only things that make CRC and SHA1 are any different are:
- SHA1 produces a longer tag (of course CRC256 is a thing)
- SHA1 is hardened against preimage attacks
- SHA1 was intended to be secure against collision attacks (not anymore!)
SHA1, truncated to 32 or 64-bits, will produce a distribution just as uniform as CRC.
In a non-security setting, we can pick the size of the tag based on the rough number of objects we'd like to be able to store before we'd expect to see a collision (i.e. the birthday bound). If that number is ~4 billion, then CRC64 is sufficient.