5 ms·
That's why my projects use RIPEMD rather than SHA. I prefer my encryption algorithms to not be developed by an organization that has a vested interested in them
by rob05c 13y ago
That's why my projects use RIPEMD rather than SHA. I prefer my encryption algorithms to not be developed by an organization that has a vested interested in them being broken.
- jared314 13y ago> I prefer my encryption algorithms to not be developed by an organization that has a vested interested in them being broken. While I understand the sentiment, you should not be using them for encryption in the first place. RIPEMD and SHA are cryptographic hash functions.
- Dylan16807 13y agoUnless it's SHA3, but thankfully that wasn't designed by them.
- jared314 13y agoSHA3 (Keccak) is also a cryptographic hash function, and should not be used for encryption.
- Dylan16807 13y agoWhy not? It's designed for indefinite output.
- maaku 13y agoAre you trolling?
- Dylan16807 13y ago...no Keccak is a generic construction suitable for more than just hashing. Here, let me copy the first bullet point off their site. > As a sponge function, Keccak has arbitrary output length. This allows to simplify modes of use where dedicated constructions would be needed for fixed-output-length hash functions. It can be natively used for, e.g., hashing, full domain hashing, randomized hashing, stream encryption, MAC computation. In addition, the arbitrary output length makes it suitable for tree hashing. Note that Keccak has a significant amount of hidden state, and they proved that the sponge construction itself is secure as a function of how many bits are hidden.
- jared314 13y agoI think he is trolling, with just enough information to sound correct. The Keccak authors have proposed a "duplex construction"[1][2], using the arbitrary length inputs/outputs and the lack of a output transformation in the sponge construction, that could be used for authenticated encryption. The NIST has yet to included that use case in the SHA-3 standard. So, until there is enough solid understanding for its correct use and tested implementations with that use, it is just a hash function. [1] http://sponge.noekeon.org/ http://sponge.noekeon.org/ (end of the page) [2] http://sponge.noekeon.org/SpongeDuplex.pdf http://sponge.noekeon.org/SpongeDuplex.pdf
- Dylan16807 13y ago> So, until there is enough solid understanding for its correct use and tested implementations with that use, it is just a hash function. I don't understand the logic here. Isn't the use of Keccak as a hash function currently largely-untested too? I would think you'd avoid using it at all in a production system right now, but if you're willing to use the algorithm why not use all of its capabilities? And I'm not trolling.