3 ms·
> This is a hash designed for non-cryptographic use The Readme specifically says "you can modify it to yield 128-bits or more if you want a cryptographically s
by remcob 6y ago
> This is a hash designed for non-cryptographic use
The Readme specifically says "you can modify it to yield 128-bits or more if you want a cryptographically secure hash."
Which is a problematic statement, because it is not designed for cryptography even if you extended the output to 256 bit. It's not the output length that makes it cryptographicaly secure. (Rather it's the difference between "you won't find collisions by accident" and "you won't find collisions even if you try really hard using very sophisticated math", but there are more requirements.)
This is similar to the issues with a different hash by the same Github user posted two weeks ago:
https://news.ycombinator.com/item?id=23103521 https://news.ycombinator.com/item?id=23103521
Making fast non-cryptographic hash functions is a fun challenge and I appreciate the projects, but please, please do not make any claims about cryptographic properties!
- deleted 6y ago[deleted]
- fantastisch 6y agoheh. Funny > it is not designed for cryptography even if you extended the output to 256 bit. You don't know that. > This is similar to the issues Can you break either of these? > Making fast non-cryptographic hash functions is a fun challenge Fun challenge? I checked out your portfolio and I didn't see any. > I appreciate the projects I didn't see your star. It seems more like you're jealous. And trying to make yourself feel better how about your imposter syndrome, by saying someone's work is not all that under the disguise of a public service. For a "smart guy" that's a little easy don't you think? So how about this, I've got a fun challenge for you. Have a shot at breaking either of these, because if you can't, you can't really claim it's insecure, can you?
- fantastisch 6y agoyou need others to not make crypto claims, but you're so sure making your crypto claim that it's not cryptographic. it's always easy to front as an expert spectator and believe others work is no good. why don't you back it up with some effort? I believe it is a crypto hash. so..a fun challenge? how about this for a fun challenge, why don't you post a cryptanalysis and I'll link it from the README. Thanks for the beamsplitter link! maybe it is designed as a crypto hash