Re: strength of multiple hash functions



"Kristian Gjøsteen" <kristiag+news@xxxxxxxxxxxx> wrote in message
news:ep9ql7$1rs$1@xxxxxxxxxxxxxxxxxxxxx
Amit <amitabh123@xxxxxxxxx> wrote:
It is easy to prove (in the random oracle model) that the security
offered by H(.) is the same as that provided by SHA1.

In my opinion, a ROM proof offers no interesting insights in this case.

I think it does, ROM sets an upper bound for this, so it cannot be more
secure than SHA1.

So based on this we have:
1) It is no more secure than SHA1
2) It may be less secure than SHA1
3) It is slower than SHA1

So we have that it is worse than SHA1 in some metrics, and no better than
SHA1 in any metric. That's actually a fairly useful result.
Joe


.



Relevant Pages

  • Re: strength of multiple hash functions
    ... offered by His the same as that provided by SHA1. ... In my opinion, a ROM proof offers no interesting insights in this case. ...
    (sci.crypt)
  • Re: new /dev/random
    ... ]>output whose entropy is greater than 160-epsilon ... That's a definition of a condition that SHA1 might meet. ... ]is this property more plausible than the assumption that SHA1 is a secure ... ]This is a distribution on 256-bit strings. ...
    (sci.crypt)
  • Re: new /dev/random
    ... >output whose entropy is greater than 160-epsilon ... That's a definition of a condition that SHA1 might meet. ... is this property more plausible than the assumption that SHA1 is a secure ... This is a distribution on 256-bit strings. ...
    (sci.crypt)
  • Re: SHA-1 Variants
    ... Things like DES, and SHA1 were designed ... there is no reason to change something like SHA1 of DES ... unless you can come up with something that is provably secure. ... But we still don't have good provable security techniques for such ...
    (sci.crypt)
  • Re: Does Unstable become Testing?
    ... Hash: SHA1 ... > Testing simply empty until new programs gradually migrate from ...
    (Debian-User)