Re: Slow but secure has function for small data



Ertugrul Soeylemez wrote:

So even though Bellare's proof shows that HMAC is secure assuming that
the hash function is a PRF it seems that this assumption is not true
for MD4 and MD5, so I would be cautious about Joseph's proposal (at
least in theory) if I needed a reduction to a really well studied
problem that is believed to be hard.

Well, proofs cannot contradict each other, so what's the conclusion?
Of course they don't contradict each other.
The assumption that MD4 or MD5 behave like a PRF is not true.
Read the paper for details.


--
Krystian Matusiewicz
http://www.ics.mq.edu.au/~kmatus/
.



Relevant Pages

  • Re: This Weeks Finds in Mathematical Physics (Week 226)
    ... Schneier credits Rivest as the designer of MD4, saying Bert den Boer and Antoon Bosselaears successfully crpytanalysed the last of the algorithms three rounds, while Ralph Merkle successfully attacked the first two rounds. ... Schneier credits Rivest as strengthening MD4 with the result being MD5. ...
    (sci.physics.research)
  • Re: OT: MD4 encryption
    ... what is MD4 used for? ... and just replaced by MD5 and is no longer used? ... Shortly after MD4 was published a number of attacks were demonstrated against parts of it. ... SHA1 isn't without problems either and discussion rages on about what is the best cryptographic hash algorithm out there. ...
    (comp.sys.mac.system)
  • Re: compare-by-hash (was Re: sharing /etc/passwd)
    ... No, md4 and md5 are broken, in the sense that it's known how to ... das@VARK:~> hexdump md4c_1 ... The md5 data comes from the page ...
    (FreeBSD-Security)
  • Re: Crypto Mini-FAQ
    ... Here's one thing Hans Dobbertin wrote about MD5: ... "would be unwise to assume that the attack could not be ... It is instructive to read the history of MD4. ...
    (sci.crypt)