Re: Val Henson's critique of hash-based content storage systems
- From
- H. Peter Anvin <hpa@zytor.com>
- Date
- Apr 29, 2005, 20:14 UTC
- Message-ID
- <42729591.8020108@zytor.com>
- In-Reply-To
- <loom.20050429T015434-928@post.gmane.org>
Rob Jellinghaus wrote:
> I assume most people here have read this, but just in case: > > http://www.usenix.org/events/hotos03/tech/full_papers/henson/henson.pdf >
I have to pull out the big flamethrower, especially against someone I consider a friend, but that paper is a classic example on how many people don't understand probability.
The *only* valid criticism in it is that we may not know enough about the future validity of cryptographic hash function, however, she also does not analyze the failure scenarios applicable to those kinds of failures barely at all.
In the end, the whole paper centers around "this makes me feel nervous", without really justifying it in any reasonable way.
It is just one of many papers on cryptoanalysis written by someone with no real background in the field. It really saddens me to see someone like Val fall into that particular trap.
-hpa