Re: MD5 Folding in kernel RNG

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Damien Miller
Date: Tuesday, December 28, 2010 - 1:48 am

On Mon, 27 Dec 2010, Kjell Wooding wrote:


I think it is intended to make preimage attacks more difficult.


I'm not aware of it being done elsewhere. Usually the recommendation is
to truncate, rather than fold hash output.

IMO we should reassess the output hash. Something like Whirlpool might be
significantly faster given its large block size.

-d
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
MD5 Folding in kernel RNG, Kjell Wooding, (Mon Dec 27, 6:07 pm)
Re: MD5 Folding in kernel RNG, Ted Unangst, (Mon Dec 27, 9:02 pm)
Re: MD5 Folding in kernel RNG, Damien Miller, (Tue Dec 28, 1:48 am)
Re: MD5 Folding in kernel RNG, Kjell Wooding, (Tue Dec 28, 1:08 pm)
Re: MD5 Folding in kernel RNG, Damien Miller, (Tue Dec 28, 1:45 pm)
Re: MD5 Folding in kernel RNG, Kjell Wooding, (Tue Dec 28, 2:42 pm)