3 ms·
If I want a string thats 5-6 chars (for, say, a URL shortener), truncating an MD5 is a bad idea since it IS random. These keys are GUARANTEED to be unique. You
by KevBurnsJr 16y ago
If I want a string thats 5-6 chars (for, say, a URL shortener), truncating an MD5 is a bad idea since it IS random.
These keys are GUARANTEED to be unique. You can run all the way up to 62^n without any key conflicts.
If you truncated an MD5 to 3 characters, by 62^3/2 you'd have a 50% chance of collision.
- Xk 16y agoOkay, sure, but that's trivial. You've just created a bijection from Z[62^5] to Z[62^5]. I could just use "X+1 mod 62^5" and get the same effect, minus some fake attempt at security.
- oakenshield 16y agoWho says you have to truncate? Split it into four 4 byte chunks and xor them.
- Xk 16y agoYou won't get any better with that. Even if MD5 was a true source of randomness, the problem is still that you've only got 32 bits, so you'd expect a collision after 2^16 with a random function. Besides, xoring the other bits does nothing to increase the security on non-broken hashing functions. Take the extreme case of xoring every bit to generate either a 0 or a 1. You've put a lot of effort into generating that single bit, but it's no more random than if you just took the lsb of the hash.