3 ms·
Wait, I thought the author was saying to use this _after_ using a more secure hash function, not instead of it. Why wouldn't you do that?
by CephalopodMD 8y ago
Wait, I thought the author was saying to use this _after_ using a more secure hash function, not instead of it. Why wouldn't you do that?
- vidarh 8y agoYes, the author specifically points out that there are really two separate steps here: a hash function, and scaling that result down to the number of bits needed at the current number of hash slots. He's arguing that the fibonacci approach is both faster than modulo and at the same time is better when the input is bad. He's certainly not arguing it replaces a good hash when you can provide one. More pointing out that if writing a general hash table implementation you need to expect bad inputs, and since you need to scale the result down anyway you might as well improve on the input if you can do so very cheaply.
- jrochkind1 8y agoIt's about "hash tables" (ie associative arrays, HashMap), right? Is security even an issue in hash functions for this purpose? I honestly don't know, it's not obvious to me that it is.
- jrootabega 8y agoPerhaps for DOS resistance like the hashdos vulnerability from 2011? https://nakedsecurity.sophos.com/2011/12/28/large-percentage-of-websites-vulnerable-to-hashdos-denial-of-service-attack/ https://nakedsecurity.sophos.com/2011/12/28/large-percentage...