[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Cfrg] Re: [saag] Bad day at the hash function factory



On Mon, Nov 01, 2004 at 09:45:17AM -0500, John Viega wrote:

> Davies-Meyer mode. That is not to say that Davies-Meyer with a
> stronger underlying block cipher wouldn't be better (e.g., Whirlpool),
> but it does suggest that it might be good to move to one of the other
> modes with similar security proofs, one that doesn't use the data
> being hashed as the block cipher key, such as Matyas-Meyer-Oseas. 

Actually Whirlpool uses the Miyaguchi-Preneel scheme, where the key used is
(IIRC) the H_{n-1}, not a chunk of the input.

-Jack

_______________________________________________
Cfrg mailing list
Cfrg at ietf.org
https://www1.ietf.org/mailman/listinfo/cfrg