4 ms·
> two identify objects by content HMAC (one of them uses an SQL database), the other uses a mix of incrementing integers and a random string for different use c
by rootlocus 9y ago
> two identify objects by content HMAC (one of them uses an SQL database), the other uses a mix of incrementing integers and a random string for different use cases.
If those two are using SHA-1, like git, you are still using a standard. The third one however sounds like a potential mess.
- dchest 9y agoIf those two are using SHA-1, like git, you are still using a standard Lovely, so I can officially claim I use a standard that is required by many commenters here if I just hash random bytes! Should I use a NIST-approved standard or maybe GOST hash function will work? Can I use the output of ChaCha20? If so, I'll be happy to read 16 bytes from /dev/urandom. The third one however sounds like a potential mess. Thanks for your analysis!
- rootlocus 9y ago> Lovely, so I can officially claim I use a standard that is required by many commenters here if I just hash random bytes! Stop pretending that you don't understand what a cryptological hash function is, or that using a strong crypto function is the same as rolling your own, or that using the hash function on your input is the same as running it on random bytes. > Thanks for your analysis! Thanks for the anecdotal evidence.