3 ms·
The two hashes aren't compatible, so a hash of the same message will yield two different hashes under BLAKE2 and BLAKE3. As far as I can tell, BLAKE2 has effec
by beefhash 7y ago
The two hashes aren't compatible, so a hash of the same message will yield two different hashes under BLAKE2 and BLAKE3.
As far as I can tell, BLAKE2 has effectively all the properties BLAKE3 has (arbitrary output length, keyed hash mode), so the upgrade for communications boils down to negotiating/determining which of the two hash functions to use over the wire (with all the downsides that come with agility of cryptographic primitives); for stored hashes, they have to be recomputed and replaced (or you could store a flag is BLAKE2/is BLAKE3 and update them as you touch hashes, kind of similar to how password hashes are swapped at login time).
Note that BLAKE3 existing doesn't break BLAKE2. It's perfectly fine to just keep trucking BLAKE2, it's just that BLAKE3 has better performance characteristics that make it very attractive.