Re: SHA-1 vs. triple-DES for password encryption?

From: Ben Laurie (
Date: 11/25/02

    Steffen Dettmer wrote:
    > * David Wagner wrote on Tue, Nov 12, 2002 at 17:11 +0000:
    >>Craig Minton wrote:
    >>>2. 3DES may be used to create a one-way function by using the password
    >>>to encrypt some standard data.
    >>Watch out. This will limit the length of allowable passwords to some
    >>fixed upper bound -- maybe not a good idea.
    > Why that? You can do hashing with 3DES-CBC mode and AFIAK it's
    > sufficient to use the last output block.

    Because the key is fixed size.



