5 ms·
SHA-256 and SHA-512 are both in the same family (SHA-2). Latacora says to use SHA-2. If you can get away with it, SHA-512/256 instead of SHA-256. But they're a
by CiPHPerCoder 7y ago
SHA-256 and SHA-512 are both in the same family (SHA-2).
Latacora says to use SHA-2. If you can get away with it, SHA-512/256 instead of SHA-256. But they're all SHA-2 family hash functions.
https://latacora.micro.blog/2018/04/03/cryptographic-right-answers.html#hashing-algorithm https://latacora.micro.blog/2018/04/03/cryptographic-right-a...
No need to bikeshed this. But if you must: SHA-512/256 > SHA-384 > SHA-512 = SHA-256
If you're wondering, "Why is SHA-384 better than SHA-512 and SHA-256?" the answer is the same reason why SHA-512/256 is the most preferred option: https://blog.skullsecurity.org/2012/everything-you-need-to-know-about-hash-length-extension-attacks https://blog.skullsecurity.org/2012/everything-you-need-to-k...
Additionally, the Intel SHA extensions target SHA1 and SHA-256 (but not SHA-512), which makes SHA-256 faster than SHA-512 on newer processors.
Isn't crypto fun?
- fireflash38 7y agoI read the blog, but it doesn't really expand on why SHA224/384 aren't vulnerable to that attack, can you explain (or link to some place that does?)
- CiPHPerCoder 7y agoBecause they're already truncated. SHA-384 is SHA-512 with a different IV (which doesn't affect LEAs) truncated to 384 bits (which gives you 128 bits of resistance against LEAs). SHA-224 is the same story but with SHA-256 instead (and only 32 bits of LEA resistance).
- tptacek 7y agoA length-extension attack works by taking the output of a hash and using it as the starting point for a new hash; you can do this even for hashes of messages you haven't seen, minting new related hashes. Truncated SHA-2 hashes don't output the whole hash, and so you aren't given enough information to start a new related hash.
- colanderman 7y agoI'm super confused. Are SHA-256 and SHA256 different, and if so, why in the world would this be considered a sane naming scheme? If not, I completely do not understand the inequation you wrote, which seemingly lists SHA-256 (and -512) multiple times.
- faceplanted 7y ago"SHA-512/256" is a single entity
- timdumol 7y agoYou're probably confused by "SHA-512/256", which does not mean SHA-512 or 256, but rather a truncated version of SHA-512: https://en.wikipedia.org/wiki/SHA-2 https://en.wikipedia.org/wiki/SHA-2 in the third paragraph.
- Ajedi32 7y agoSo why would a truncated version of SHA-512 be better than SHA-512? And why is SHA-512 = SHA-256?
- CiPHPerCoder 7y agoTruncated hash functions are not vulnerable to length-extension attacks. Length-extension attacks are relevant when you design a MAC by passing a secret and then a message to a hash function, where only the message is known. Truncating the hash (which is what SHA-512/256 and SHA-384 do to SHA-512) removes the ability to grab an existing hash H(k || m) (where k is unknown and m might be known) and append junk because a truncated hash does not contain sufficient information to recover the full state of the hash function in order to append new blocks.
- p1mrx 7y agoWhy do SHA-512/160 and SHA-512/128 not exist? They could be useful as drop-in replacements for SHA1 and MD5.
- rurban 7y agoI would rather call them AMD extensions, because you would only find them in all used AMD Rome style processors (Epic, Ryzen, Threadripper) but not in any useful Intel processor, but Goldmont (ie cheap Laptops).