9 ms·
SHA-3 to Be Announced
- swordswinger12 14y agoI think NIST should have a big Apple-esque unveiling event for new crypto. I for one am that excited about SHA-3.
- DanBC 14y agoThat's a good idea. There's a risk of creating hype among people who don't know enough to be able to make a decision, but who do have power to make that decision. (http://dilbert.com/strips/comic/1995-11-17/ http://dilbert.com/strips/comic/1995-11-17/)
- thrill 14y agoI can envision a great Samsung-ish commercial about waiting in line to get the new hash - one of you creative types could have fun with that spoof (of a spoof)
- gojomo 14y agoAnd to retire SHA-1, they can put it on the back of a 747 to fly it past major cities and national landmarks on a farewell tour.
- helper 14y agoI'm a bit surprised that Schneier is advocating for "no award". Even if the SHA-3 candidates are not fundamentally better than SHA-512, we really do need a standardized algorithm that has built in protection from length extension attacks.
- kbolino 14y agoIs there something about HMAC, which can augment any hash function, that makes it insufficient for the task?
- moonboots 14y agoA hash function immune to length extension attacks is more fool-proof than HMAC because there is no additional construct required. It's also faster because it requires no additional passes over data.
- tptacek 14y agoYes. HMAC is very slow. Also, length extension is a pernicious and scary little property to have lurking around your crypto designs; you want it gone.
- apawloski 14y agoIf I remember correctly (I may not), two SHA-2 functions (SHA-224 and SHA-384?) aren't vulnerable to length extension attacks. While I agree with you that this is an immediately important feature, I don't think Bruce's premise (that SHA-2 is still pretty good) is invalid. Perhaps like you though, I don't understand why a new standard can't be incremental. I think it's silly to wait until something major happens to change.
- brazzy 14y agoThe problem with a new standard is that it may induce many to start using it on the grounds that "newer is better", which may not actually be the case: the SHA-2 algorithms have withstood more scrutiny so far.
- masklinn 14y ago> If I remember correctly (I may not), two SHA-2 functions (SHA-224 and SHA-384?) aren't vulnerable to length extension attacks. Interesting, is that because they only return part of the final state (by slicing sha-256 and sha-512) where unsliced 256 and 512 return all of the algorithm's running state as its result?
- exDM69 14y agoI implemented the Skein hash in a crypto class at my uni. What is remarkable about that hash is that it has a "hash tree" mode which provides an interesting opportunity for parallelization and doing hashing of partial data. In contrast, many traditional hash algorithms are inherently sequential by nature. On the other hand, as Mr. Schneier points out in the article, the Skein hash utilizes a modified Threefish block cipher, while many of the SHA-3 contestants were AES-based (edit: seems like none of the finalists are). Now we have a hardware AES implementation shipping in mainstream processors, so it gives an edge to the AES-based hash functions out there. edit: I went through the list of finalists and it seems none of them actually use the whole AES block cipher, although several of them use AES S-boxes or other parts of AES.
- dchest 14y agoWe show that the 4-lanes SHA-256 is faster than the two SHA3 finalists (BLAKE and Keccak) that have a published tree mode implementation. http://eprint.iacr.org/2012/476.pdf http://eprint.iacr.org/2012/476.pdf [PDF] As for AES instruction -- Skein and BLAKE are still faster http://bench.cr.yp.to/results-sha3.html http://bench.cr.yp.to/results-sha3.html
- exDM69 14y agoGood stuff, thanks for getting out some good sources.
- Zenst 14y agoI believe they worked towards speed mostly and whilst AES is in alot of hardware the basis of there design was to be hardware independant and with that in mind you can see why no design bias was placed upon what is or not currently enabled in some hardware. In a world were we still have no standard in ragards of BIG or LITTLE ENDIAN then you can see they took the right approach. Only aspect that Mr Schneier has not highlighted and which you touched upon is that some of the hashing finalists are faster and in that they will in brute force comparisions be not as good. That is another consideration, albeit one of limited time as you already said AES is now in some hardware as instructions and how long since AES being a standard has that taken. But the whole ability to work on partial blocks and that is what you need to do to gain from parallelisation does open up a while new ballgame in modifiying hashed code and returning the same hash. Now if you can pick a partial block size and then do a brute force test modifying from 0-FF each byte of the block incrementaly for the every permutation and only get a match on the original then that will by design be the one I'd be picking, i'm sure they will be testing each parallel finalist in that way. But personaly if they all pass that test then why pick one winner and have them all as part of the standard SH-3.[1-5]. After all if they all work well then having the choice can only add to the entropy we call security these days.
- deleted 14y ago[deleted]
- dochtman 14y agodjb thought in March it was going to be Keccak: https://twitter.com/hashbreaker/status/183552364953878528 https://twitter.com/hashbreaker/status/183552364953878528
- Zenst 14y agoInteresting that the reason for SHA-3 has been missed in that the finalists offer no better way to hash with the main difference being some are faster and some slower than the best SH2 variations. What does this mean, well in effect no extra value is being directly offered, sure some have extra abilities by design like being more able to liberate parallel processing by sbeing able to split the data to be hashed into chunks and work on partial blocks of the final data and use the results to get the final hash result. That is nice. But when it comes to brute forcing then being faster works against you, also the ability to work on partial chunks of the data allows you to modify the code and rechecking the partial hash for the part your changing until you get the same result, this alows you to do nasty things to code and get the official hash answear alot easier than having to rehash the end result every time and getting the same result or modifying the code to get the same result (usualy have area you jump over all nop and modify that to influence the hash, but more sane ways to do this but offtopic). So in essence any hash that can be run faster in any way will make it weaker in terms of brut forcing (yes I know people assume there passwords will be the last one on the list to be checked bia brute forcing and assume if it takes 10 years to test all variations then there password is 10 years strong, you see the flaw in mentality there). Now NIST still have an opertunity here and it is a simple, tried and tested approach and that would be to have all finalists winners and have them all in the standard as variations. This then allows end users/admins to pick there variation of choice or even perish the thought allow mixed usage so say your /etc/password file could have some users using one variation, others using another, etc. Whilst it add's no obvious extra benifit, it will allow more variations and in that fallbacks/choice and that is what n BIT encryption/hashing is all about, each bit being a choice in a way. So in summary I believe NIST should let them all win and have SH3.n with n being the variation of finalist, let them all win, choice is good and that is what n bit encryption is after all, extra choices.
- tptacek 14y agoUgh. Being faster does not work against secure hash functions! Holding all else equal, faster is invariably better. What you're thinking of are password hashes, which are a variant/application of key derivation functions (KDFs). KDFs often use secure hash functions, which is where the confusion comes from. You want your core crypto to be as fast as it conceivably can be, because you want to be making progress towards a state where all communications are encrypted by default.
- Zenst 14y agoOut of interest these hash functions can be implemented in very few bytes with 100 being mooted for this skien hash. With that in mind when it comes to brute forcing I do wonder if it would be possible to just brute force a better solution easier than brute forcing a hash, I say that in jest. But it does make you reliase how much empressive stuff you can do in just a few bytes and what else is out there.
- JeremyBanks 14y agoSchneier picked a very misleading headline here. I was wary when I saw that the NIST page he links regarding the timeline still hasn't been updated since June, and then I saw him reply in the comments: "> When will SHA3 be announced? Were you given special information the rest of us don't have access to? I have no inside information on when SHA-3 will be announced. My guess is that they've made the decision, and are going over the final rationale again and again. My guess is that it won't be Skein." Even though this is the original title, I'd prefer the HN title be edited to something about Schneier hoping NIST will pick no SHA-3.
- anglebaby 14y agoI ended u taking thm back fr Bose QC 15. A night and day difference. The Bose Noise Canceling is amazing <a href="http://www.cheapbeatsbydrdre.org/>cheap http://www.cheapbeatsbydrdre.org/>cheap beats by dre</a> and the sound incredibly crisp.dr dre headphones do nt work wll a headset If ou r wllng to pay fr style thy lok great but dont expect $300 worth f greatness.In sound quality Beats i equal t Bose. Their<a href="http://www.cheapbeatsbydrdre.org/>cheap http://www.cheapbeatsbydrdre.org/>cheap beats</a> ar two down sides to th BEATS beats studio. One Collapsing the BEATS headphones t fit into the carrying case. The demos BEAT headphones<a href="http://www.cheapbeatsbydrdre.org>monster http://www.cheapbeatsbydrdre.org>monster headphones</a> I hv sn t everl bestbuy stores r ll broken at that joint area. If yur careful in closing the BEATS headphones u will n no issues. The thr issue Noise Cancellation fr th BEATS headphones re not ther s thy claim.. True Noise Cancellation ar with th Bose 15 nd Bose Quiet 3. 0 (which I al own).They're simply amazing.
- anglebaby 14y agoI ended u taking thm back fr Bose QC 15. A night and day difference. The Bose Noise Canceling is amazing [url=http://www.cheapbeatsbydrdre.org/]cheap http://www.cheapbeatsbydrdre.org/]cheap beats by dre[/url] and the sound incredibly crisp.dr dre headphones do nt work wll a headset If ou r wllng to pay fr style thy lok great but dont expect $300 worth f greatness.In sound quality Beats i equal t Bose. Their[url=http://www.cheapbeatsbydrdre.org/]cheap http://www.cheapbeatsbydrdre.org/]cheap beats[/url] ar two down sides to th BEATS beats studio. One Collapsing the BEATS headphones t fit into the carrying case. The demos BEAT headphones[url=http://www.cheapbeatsbydrdre.org]monster http://www.cheapbeatsbydrdre.org]monster headphones[/url] I hv sn t everl bestbuy stores r ll broken at that joint area. If yur careful in closing the BEATS headphones u will n no issues. The thr issue Noise Cancellation fr th BEATS headphones re not ther s thy claim.. True Noise Cancellation ar with th Bose 15 nd Bose Quiet 3. 0 (which I al own).They're simply amazing.
- anglebaby 14y agoI ended u taking thm back fr Bose QC 15. A night and day difference. The Bose Noise Canceling is amazing cheap beats by dre and the sound incredibly crisp.dr dre headphones do nt work wll a headset If ou r wllng to pay fr style thy lok great but dont expect $300 worth f greatness.In sound quality Beats i equal t Bose. Theircheap beats ar two down sides to th BEATS beats studio. One Collapsing the BEATS headphones t fit into the carrying case. The demos BEAT headphonesmonster headphones I hv sn t everl bestbuy stores r ll broken at that joint area. If yur careful in closing the BEATS headphones u will n no issues. The thr issue Noise Cancellation fr th BEATS headphones re not ther s thy claim.. True Noise Cancellation ar with th Bose 15 nd Bose Quiet 3. 0 (which I al own).They're simply amazing.