3 ms·
This scares me. > I could run it out to md5 and trim the first n chars but that’s not going to be very unique. What? MD5 going to be orders of magnitude bette
by Xk 16y ago
This scares me.
> I could run it out to md5 and trim the first n chars but that’s not going to be very unique.
What? MD5 going to be orders of magnitude better than what he's given.
> Storing a truncated checksum in a unique field means that the frequency of collisions will increase geometrically as the number of unique keys for a base 62 encoded integer approaches 62^n.
Well, duh. That's a given. And his solution won't do any better.
> I’d rather do it right than code myself a timebomb.
Doing it right would be using a real hash. Not something you came up with over a cup of coffee.
> Pretty random-looking, huh?
If that's his idea of testing for randomness... Use any randomness test and I guarantee you MD5 will preform better and faster.
> This is a minimum security technique.
This is the best piece of advice in the whole piece. Please never ever use this for something you want to be secure. I haven't tried to break it (maybe I'll do that over the weekend), but giving it a first glance I would be willing to bet anyone with some skill would be able to do so.
"Anyone, no matter how unskilled, can design an algorithm that he himself cannot break." -- Bruce Schneier
- KevBurnsJr 16y agoIf I want a string thats 5-6 chars (for, say, a URL shortener), truncating an MD5 is a bad idea since it IS random. These keys are GUARANTEED to be unique. You can run all the way up to 62^n without any key conflicts. If you truncated an MD5 to 3 characters, by 62^3/2 you'd have a 50% chance of collision.
- Xk 16y agoOkay, sure, but that's trivial. You've just created a bijection from Z[62^5] to Z[62^5]. I could just use "X+1 mod 62^5" and get the same effect, minus some fake attempt at security.
- oakenshield 16y agoWho says you have to truncate? Split it into four 4 byte chunks and xor them.
- Xk 16y agoYou won't get any better with that. Even if MD5 was a true source of randomness, the problem is still that you've only got 32 bits, so you'd expect a collision after 2^16 with a random function. Besides, xoring the other bits does nothing to increase the security on non-broken hashing functions. Take the extreme case of xoring every bit to generate either a 0 or a 1. You've put a lot of effort into generating that single bit, but it's no more random than if you just took the lsb of the hash.
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]