4 ms·
> Poly1305 also saves network bandwidth, since its output is only 16 bytes compared to HMAC-SHA1, which is 20 bytes. You could also just truncate HMAC-SHA1 to
by awda 12y ago
> Poly1305 also saves network bandwidth, since its output is only 16 bytes compared to HMAC-SHA1, which is 20 bytes.
You could also just truncate HMAC-SHA1 to 16 bytes, right?
- tptacek 12y agoIf you wanted a slower, less secure MAC, yes.
- awda 12y agoIs 16-byte Poly1305 more secure than 16-byte HMAC-SHA1? (Actually curious. Citation: I've done all the matasano crypto challenges, and all of the stripe µctf stuff :).)
- tptacek 12y agoI believe so? Isn't there a 2^80 attack on SHA1? I think the bigger issue is that the security proof for a polynomial MAC is much clearer (and the MAC itself is much faster).
- userbinator 12y agoOn average a bruteforce attack will find a match halfway through the keyspace, so that would be 2^80 for SHA1... and only 2^64 for Poly1305 and anything else with a 128-bit width (that isn't broken in some other manner.)
- tveita 12y agoHalfway through the tag space of a 160-bit tag is 2^159. You're looking for an exact match, not just a collision.
- tveita 12y agoThe collision attack on SHA-1 should not threaten HMAC-SHA1. Even HMAC-MD5 hasn't been successfully attacked yet, AFAIK. Poly1305 is arguably less misuse-resistant, since it requires a nonce.
- tptacek 12y agoThat's typical of AEAD modes in general, though. GCM also requires a nonce.
- ahh 12y agoDo you have a decent reference for the proof of poly MACs?
- tptacek 12y agoYou can start at the Poly1305 paper and follow the cites all the way back to Wegman and Carter, or (somewhat more modern) to Krawczyk's "cryptographic CRCs". Or, if I may be permitted to once again coattail 'pbsd, start the other way: https://news.ycombinator.com/item?id=7317125 https://news.ycombinator.com/item?id=7317125
- tptacek 12y agoOh, by the way, if by µctf you're referring to µcorruption (our MSP430 CTF), that was Square, not Stripe. :)