5 ms·
From the email discussion: > to support SHA-256, we would simply use the system's crypto libraries ... I think this is probably the single strongest argument f
by dev_dull 8y ago
From the email discussion:
> to support SHA-256, we would simply use the system's crypto libraries ... I think this is probably the single strongest argument for sha256. "It's just there".
Sounds reasonable and well... boring. Just the kind of technical decisions I like
- arusahni 8y ago> dev_dull Checks out. :)
- slavik81 8y agoWhat was the case against SHA-512/256? It's the same size as SHA-256, is faster on 64-bit hardware, and is often more difficult to attack. It's just a truncated SHA-512 hash, which is widely supported. The only drawback I know of is that it's slower than SHA-256 on 32-bit hardware. edit: I found the email where they compared 256-bit hash functions [1]. It seems Apple Common Crypto, gcrypt and NSS don't implement SHA-512. A new twist to the performance story is that OpenSSL's SHA-256 is faster than SHA-512/256 in the AMD Ryzen tests, possibly due to the recent introduction of hardware support. [1]: https://public-inbox.org/git/20180609224913.GC38834@genre.crustytoothpaste.net/ https://public-inbox.org/git/20180609224913.GC38834@genre.cr...
- wvh 8y agoWell, sha512 with different initialisation vectors. Even OpenSSL doesn't support sha512_256 yet, but it's coming in the next major release.
- slavik81 8y agoThanks. I hadn't realized it started with a different initial value. That small difference really cuts down on availability of implementations.
- BjoernKW 8y agoAbsolutely. "Use boring solutions" has become a bit of a mantra for me. Only build something yourself if it serves as a key differentiator or has the potential to do so. Otherwise, use off-the-shelf tools.