Slashdot Mirror


A Competition To Replace SHA-1

SHA who? writes "In light of recent attacks on SHA-1, NIST is preparing for a competition to augment and revise the current Secure Hash Standard. The public competition will be run much like the development process for the Advance Encryption Standard, and is expected to take 3 years. As a first step, NIST is publishing draft minimum acceptability requirements, submission requirements, and evaluation criteria for candidate algorithms, and requests public comment by April 27, 2007. NIST has ordered Federal agencies to stop using SHA-1 and instead to use the SHA-2 family of hash functions."

4 of 159 comments (clear)

  1. Draft location by ErGalvao · · Score: 5, Informative

    The draft can be found (in PDF) here.

    --
    Er Galvão Abbott - IT Consultant and Developer
  2. Schneier Proposed this in 2005 by RAMMS+EIN · · Score: 5, Informative

    Schneier proposed such a competition in March 2005: http://www.schneier.com/crypto-gram-0503.html#1

    --
    Please correct me if I got my facts wrong.
  3. Re:Generic hashing is impractical by delt0r · · Score: 5, Informative

    You clearly don't know what a crytographic hash is about. And this is not what is ment by collisions resitant. What it means is that there is minum amount of work needed to produce a collision.

    There are a number of different type of collisions as well. Lets assume we have a 256-bit hash. There is the kind of colision where you just find *any* 2 strings that produce the same hash, which should require on avarage 2**128 "operations". A harder task is given a string and its hash find another string with the same hash. For a secure hash 256-bit hash function this will require on avarage 2**256 "operations".

    There are other properties that are important as well. Its a well established idea. Hashes are very very usefull and are used for a lot more that file verification and we know what properties they need. We are just not very good at producing very good hashes yet.

    --
    If information wants to be free, why does my internet connection cost so much?
  4. Re:Multiple Hash Functions by rbarreira · · Score: 4, Informative
    --

    The AACS key is NOT 0xF606EEFD628B1CA427BEA93A9CA9773F