5 ms·
SHA-256 is vulnerable to a length extension attack. This is well-known to cryptographers; it doesn’t matter for some applications and can be worked around in o
by anderskaseorg 4y ago
SHA-256 is vulnerable to a length extension attack. This is well-known to cryptographers; it doesn’t matter for some applications and can be worked around in others. But it still catches some developers unaware.
https://en.wikipedia.org/wiki/Length_extension_attack https://en.wikipedia.org/wiki/Length_extension_attack
- deleted 4y ago[deleted]
- phh 4y agoI didn't expect such attacks to exist, thanks for bringing that up. However that Wikipedia page seem to say sha-256 is ok since it's truncated?
- CBLT 4y agoSha-224 and Sha-384 are the truncated versions of Sha-256 and Sha-512 respectively. My boring hash function of choice is Sha-384. The Sha-512 computation is faster on Intel hardware, and ASICS to crack it are far more expensive than Sha-256 because of bitcoin. If you're hashing passwords or something, use a "harder" hash like Argon2 or Scrypt.
- adrian_b 4y agoSHA-512 is faster only on Skylake derivatives up to Comet Lake and on older Intel Core CPUs. On Intel Atom starting with Apollo Lake (2016) and on Intel Core starting with Ice Lake (2019) and on all AMD Zen CPUs (2017), SHA-256 is implemented in hardware and it is much faster than SHA-512.
- Dylan16807 4y agoSHA-256 is not truncated. "SHA-512/256" is truncated. It means you do SHA-512 (with a different starting state) and then throw out half.
- tptacek 4y agoThere are increasingly few situations in which length extension really matters, because we know more about designing protocols than we did 20 years ago; even code that uses SHA3 or Blake2 tends to still use HMAC. Further, there are standard variants of SHA2 that don't have length extension (they're truncated and don't disclose their full state). It's better to not have length extension properties than to have them, but it's not really a big part of the desiderata.
- flatiron 4y agoI’m always confused when people slam sha on hmac. Is there a realtime sha back door I’m missing? Even sha 1 takes days/months to break.
- tptacek 4y agoI don't understand what you're asking here. Don't use HMAC as a password hash? HMAC keys should be a long string of uncorrelated bits, not ASCII strings?
- AtNightWeCode 4y agoIt is often worked around. But from what I understand the length extension issue was raised during the design but ignored. Hashing is not encryption but some of the recommended encryption standards are so complicated that it is a risk just by itself. SHA-384 is a truncated SHA-512. From the claims of sec people it does not offer more security when it comes to length attacks. But from how the algo works I would assume that it does. Nist is also plain wrong about their calculations. Cause how long it takes to calculate a specific hash depends on the hardware available, not what theory books says. It may in practice be faster to calculate a hash with more bits.
- adastra22 4y agoBitcoin mining uses double SHA256 which is not subject to length extension attacks. (Not that it matters, because bitcoin block headers are fixed length.)