3 ms·
Correct, the truncated versions of SHA2 are secure against length extension.
by pbsd 5y ago
Correct, the truncated versions of SHA2 are secure against length extension.
- maqp 5y agoSo SHA224 and SHA384? They're not exactly common. SHA256 is pretty much the standard and SHA512 is usually used for hashing larger files due to the larger block size and thus faster speed. I don't think I've ever seen 224/384 used anywhere.
- SAI_Peregrinus 5y agoSHA224, SHA384, and SHA512/256 (yes, that's NOT the same as SHA512/SHA256, it's SHA512 truncated to 256 bits) are the truncated versions of SHA2. Rarely used. Confusingly named (in the case of SHA512/256).
- tialaramex 5y agoImportantly SHA-512/256 does not mean "Either of these two different functions" but instead another function, which is similar to (but slightly different from) performing SHA-512 and then throwing away all but 256 bits. This prevents length extension because you've thrown away 256 bits the attacker needs to perform their attack.
- aidenn0 5y agoSHA-512/256 is what I default to since it is faster than SHA-256 but doesn't have the ridiculously long hash length of SHA-512
- adrian_b 5y agoIt is faster on any 64-bit CPU without hardware SHA256, i.e. on most Intel CPUs. On CPUs with hardware SHA256 (AMD Zen, 64-bit ARM, some recent Intel CPUs), SHA256 is faster.
- adrian_b 5y agoFor processors that have hardware SHA256 (AMD Zen, most 64-bit ARM, some Intel models), SHA224 can be computed with the same instructions. For 64-bit CPUs without hardware SHA256, SHA512 & SHA384 are the fastest and they have identical speed (as only the values of some constants differ, while the algorithm is the same). Most libraries and hash utilities implement all these variants, so any variant can be chosen without problems.
- deleted 5y ago[deleted]