3 ms·
I'd expect very few clients to negotiate using SHA-384. It's widely viewed as overkill compared to SHA-256, and it hurts performance. I'm not saying it invalid
by ReidZB 7y ago
I'd expect very few clients to negotiate using SHA-384. It's widely viewed as overkill compared to SHA-256, and it hurts performance.
I'm not saying it invalidates the benchmark results or anything—I just wanted to address your "not used" question.
- brobinson 7y agoIsn't SHA-256 vulnerable to length extension attacks?
- unscaled 7y agoYes, but so is SHA-384 and that is not relevant for the TLS context.
- MerryMage 7y ago384 is not vulnerable to length extension attacks precisely because it is truncated. The output is not he full internal state. The speed advantage of SHA-512 and the advantage of truncation is why some more exotic variants like SHA-512/256 (SHA-512 truncated to 256 bits) are used in newer protocols.
- dagenix 7y agoSHA-384 can actually be faster than SHA-256 is some cases. The reason is that SHA-256 used 64 rounds with 32 bit words, while SHA-384 uses 80 rounds with 64 bit words. So, each block processed by SHA-384 is twice as big but uses less than twice as many rounds.
- ReidZB 7y agoOh yes, definitely. But SHA-384's output is 128 bits wider, which uses more bandwidth. Although for the AEAD ciphersuites, it doesn't make much of a difference, admittedly.
- dagenix 7y agoThere is the not so widely used SHA-512/256 for that case - the speed of the 64 bit variants with a 256 bit output.