Re: Whirlpool 512-bit collisions?

From: Alan (a__l__a__n_at_hotmail.com)
Date: 06/15/05


Date: Wed, 15 Jun 2005 10:28:32 -0400

Matt Mahoney wrote:
> (1) most certainly does have collisions for most of the possible 512
> bit inputs. It is not a big security risk because the probability is
> only 2^-512 for any pair of inputs.

Often hash functions are used to "whiten" bits collected from an entropy
source. Since there are collisions, entropy is lost by hashing. (eg You
might put 512 bits of entropy in, but how much entropy is in the output?
Less than 512 bits if there are collisions) It would be useful to have
some measure of how much entropy is lost when hashing.

Alan



Relevant Pages

  • Entropy à la EPT
    ... ontogeny naturally instructs the building of living forms) the length of the ... is inversely proportional to the degree of "instructive entropy". ... interpretation of entropy and the "information theoretical type" ... Hole is lost. ...
    (sci.bio.evolution)
  • Re: Beginner fun challenge
    ... > That's not buffering as the entropy is lost. ... -- Andrew Koenig ...
    (sci.crypt)
  • Re: How to measure entropy?
    ... > Entropy with respect to what? ... Take a long run of about 100 mio. ... Well, this idea is a common approach, but has some drawback - if you hash ... into at least blocks and then hashing them, ...
    (sci.crypt)
  • Re: Whirlpool 512-bit collisions?
    ... It is not a big security risk because the probability is ... Since there are collisions, entropy is lost by hashing. ... Greg Rose ...
    (sci.crypt)
  • Re: expensive password hash
    ... If you're starting from a password, then the amount of entropy in the ... Assuming SHA1 is collision-resistant, ... Suppose there was a collision, i.e., some pair of possible ... passwords yields the same output when hashing 2^16 times. ...
    (sci.crypt)

Loading