Re: Using MGF1 for key generation
From: David Wagner (daw_at_taverner.cs.berkeley.edu)
Date: 08/01/05
- Next message: David Wagner: "Re: Josef Harne"
- Previous message: David Wagner: "Re: Using MGF1 for key generation"
- In reply to: Joseph Ashwood: "Re: Using MGF1 for key generation"
- Next in thread: Gregory G Rose: "Re: Using MGF1 for key generation"
- Reply: Gregory G Rose: "Re: Using MGF1 for key generation"
- Reply: Joseph Ashwood: "Re: Using MGF1 for key generation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 1 Aug 2005 17:51:01 +0000 (UTC)
Joseph Ashwood wrote:
>Generaly advice at this point is that MGF1 (based on SHA-1) should not be
>used for new designs due to the recent breaks in SHA-1,
Hmm. I guess I hadn't heard that one. Is there any justification?
My sense is that you shouldn't use SHA1 in new systems for its
collision-resistance, but it is fine to use SHA1-HMAC for its properties
as a pseudorandom function.
- Next message: David Wagner: "Re: Josef Harne"
- Previous message: David Wagner: "Re: Using MGF1 for key generation"
- In reply to: Joseph Ashwood: "Re: Using MGF1 for key generation"
- Next in thread: Gregory G Rose: "Re: Using MGF1 for key generation"
- Reply: Gregory G Rose: "Re: Using MGF1 for key generation"
- Reply: Joseph Ashwood: "Re: Using MGF1 for key generation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|