3 ms·
As someone neutral about the subject, my summary of the discussion looks a bit different. stouset claimed that there is no practical advantage of using SHA-3 o
by smarnach 9y ago
As someone neutral about the subject, my summary of the discussion looks a bit different.
stouset claimed that there is no practical advantage of using SHA-3 over SHA-512/256. He gave three main arguments:
1. SHA-3 is slower.
2. SHA-3 was subject to less cryptanalysis.
3. Virtually all respected cryptographers do not recommend SHA-3 over SHA-2.
On the other hand, baby claimed that there are practical advantages of using SHA-3 over SHA-2. However, even after reading the thread twice, I couldn't find out what they are supposed to be. (I'm leaving out the LEA here, since it does not affect SHA-512/256 either.)
Baby claimed that argument 2 was debunked, but the supporting link pointed to a thread that stated nothing to that effect. He also claimed that argument 3 carries no weight since it's an appeal to authority. While an appeal to authority is not a valid scientific argument, it's about the best practical argument you can make as a non-cryptographer when choosing cryptographic algorithms.
- baby 9y agoThis prompted me to post my thoughts here: https://cryptologie.net/article/400/maybe-you-shouldnt-skip-sha-3/ https://cryptologie.net/article/400/maybe-you-shouldnt-skip-...