4 ms·
> The reality is that you should use SHA-3. I'm making this as a broad recommendation for people who do not know much about cryptography. You can't go wrong wit
by nilved 9y ago
> The reality is that you should use SHA-3. I'm making this as a broad recommendation for people who do not know much about cryptography. You can't go wrong with the NIST's standard.
https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG
- smitherfield 9y agoIf your claim is that SHA-3 contains an NSA backdoor, that's an extraordinary claim requiring extraordinary evidence.[1] In the case you link to, the NSA was publicly the author and the backdoor was "obvious" nearly from the start. [1] Or else a conspiracy theory. Not that conspiracy theories are never true; I'd be surprised but not shocked if this one were.
- nilved 9y agoNo, my claim is simply that NIST sponsorship is not a good reason to use it.
- smitherfield 9y agoFair enough, although I'd still say it is; hashes that've received the NIST's imprimatur have all been above-average compared to their contemporaries, and none of them appear to have any intentional weaknesses.
- tptacek 9y agoThis is the (very) rare case in which a cite to Dual_EC makes some sense.
- JoachimS 9y agoIt wasn't obvious enough to prevent it from slipping into being not only a NIST standard, but also standards by ANSI and ISO. Quite a lot of people around the world that accepted it.
- smitherfield 9y agoWell, anyone familiar with standards bodies knows broken behavior gets written into standards[1] all the time. But at least the crypto standards bodies are quick to deprecate. [1] The drafting of which is based on bikeshedding/NIH internal politics.
- baby 9y agoOh yeah I should rephrase that :D