5 ms·
Is 16-byte Poly1305 more secure than 16-byte HMAC-SHA1? (Actually curious. Citation: I've done all the matasano crypto challenges, and all of the stripe µctf st
by awda 12y ago
Is 16-byte Poly1305 more secure than 16-byte HMAC-SHA1? (Actually curious. Citation: I've done all the matasano crypto challenges, and all of the stripe µctf stuff :).)
- tptacek 12y agoI believe so? Isn't there a 2^80 attack on SHA1? I think the bigger issue is that the security proof for a polynomial MAC is much clearer (and the MAC itself is much faster).
- userbinator 12y agoOn average a bruteforce attack will find a match halfway through the keyspace, so that would be 2^80 for SHA1... and only 2^64 for Poly1305 and anything else with a 128-bit width (that isn't broken in some other manner.)
- tveita 12y agoHalfway through the tag space of a 160-bit tag is 2^159. You're looking for an exact match, not just a collision.
- tveita 12y agoThe collision attack on SHA-1 should not threaten HMAC-SHA1. Even HMAC-MD5 hasn't been successfully attacked yet, AFAIK. Poly1305 is arguably less misuse-resistant, since it requires a nonce.
- tptacek 12y agoThat's typical of AEAD modes in general, though. GCM also requires a nonce.
- ahh 12y agoDo you have a decent reference for the proof of poly MACs?
- tptacek 12y agoYou can start at the Poly1305 paper and follow the cites all the way back to Wegman and Carter, or (somewhat more modern) to Krawczyk's "cryptographic CRCs". Or, if I may be permitted to once again coattail 'pbsd, start the other way: https://news.ycombinator.com/item?id=7317125 https://news.ycombinator.com/item?id=7317125
- tptacek 12y agoOh, by the way, if by µctf you're referring to µcorruption (our MSP430 CTF), that was Square, not Stripe. :)