git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Hash algorithm analysis

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jul 26, 2018, 10:31 UTC
Message-ID
<nycvar.QRO.7.76.6.1807261221050.71@tvgsbejvaqbjf.bet>
In-Reply-To
<f5bb91e8-5189-7f61-e018-91447c42845e@noekeon.org>
Hi Joan,
On Sun, 22 Jul 2018, Joan Daemen wrote:
Show 8 quoted lines
> I wanted to react to some statements I read in this discussion. But
> first let me introduce myself. I'm Joan Daemen and I'm working in
> symmetric cryptography since 1988. Vincent Rijmen and I designed
> Rijndael that was selected to become AES and Guido Bertoni, Michael
> Peeters and Gilles Van Assche and I (the Keccak team, later extended
> with Ronny Van Keer) designed Keccak that was selected to become SHA3.
> Of course as a member of the Keccak team I'm biased in this discussion
> but I'll try to keep it factual.

Thank you *so* much for giving your valuable time and expertise on this subject.

I really would hate for the decision to be made due to opinions of people who are overconfident in their abilities to judge cryptographic matters despite clearly being out of their league (which includes me, I want to add specifically).

On a personal note: back in the day, I have been following the Keccak with a lot of interest, being intrigued by the deliberate deviation from the standard primitives, and I am pretty much giddy about the fact that I am talking to you right now.

> [... interesting, and thorough background information ...]
> 
> Anyway, these numbers support the opinion that the safety margins taken
> in K12 are better understood than those in SHA-256, SHA-512 and BLAKE2.
This is very, very useful information in my mind.
Show 19 quoted lines
> Adam Langley continues:
> 
> 	Thus I think the question is primarily concerned with performance and implementation availability
> 
> 
> Table 2 in our ACNS paper on K12 (available at
> https://eprint.iacr.org/2016/770) shows that performance of K12 is quite
> competitive. Moreover, there is a lot of code available under CC0
> license in the Keccak Code Package on github
> https://github.com/gvanas/KeccakCodePackage. If there is shortage of
> code for some platforms in the short term, we will be happy to work on that.
> 
> In the long term, it is likely that the relative advantage of K12 will
> increase as it has more potential for hardware acceleration, e.g., by
> instruction set extension. This is thanks to the fact that it does not
> use addition, as opposed to so-called addition-xor-rotation (ARX)
> designs such as the SHA-2 and BLAKE2 families. This is already
> illustrated in our Table 2 I referred to above, in the transition from
> Skylake to SkylakeX.

I *really* hope that more accessible hardware acceleration for this materializes at some stage. And by "more accessible", I mean commodity hardware such as ARM or AMD/Intel processors: big hosters could relatively easily develop appropriate FPGAs (we already do this for AI, after all).

> Maybe also interesting for this discussion are the two notes we (Keccak
> team) wrote on our choice to not go for ARX and the one on "open source
> crypto" at https://keccak.team/2017/not_arx.html and
> https://keccak.team/2017/open_source_crypto.html respectively.

I had read those posts when they came out, and still find them insightful. Hopefully other readers of this mailing list will spend the time to read them, too.

Again, thank you so much for a well-timed dose of domain expertise in this thread.

Ciao, Dscho

Previous: Adam LangleyNext: demerphq
Message 26 of 66 in “State of NewHash work, future directions, and discussion”
  1. brian m. carlsonJun 9, 2018
  2. Ævar Arnfjörð BjarmasonJun 9, 2018
  3. Hash algorithm analysisbrian m. carlson, Jun 9, 2018
  4. Jonathan NiederJun 11, 2018
  5. Linus TorvaldsJun 11, 2018
  6. Ævar Arnfjörð BjarmasonJun 11, 2018
  7. David LangJun 12, 2018
  8. Linus TorvaldsJun 12, 2018
  9. brian m. carlsonJun 11, 2018
  10. Gilles Van AsscheJun 12, 2018
  11. brian m. carlsonJun 13, 2018
  12. Gilles Van AsscheJun 15, 2018
  13. brian m. carlsonJul 20, 2018
  14. Jonathan NiederJul 21, 2018
  15. Ævar Arnfjörð BjarmasonJul 21, 2018
  16. brian m. carlsonJul 21, 2018
  17. Johannes SchindelinJul 21, 2018
  18. Linus TorvaldsJul 21, 2018
  19. brian m. carlsonJul 21, 2018
  20. Eric DeplagneJul 22, 2018
  21. brian m. carlsonJul 22, 2018
  22. Eric DeplagneJul 22, 2018
  23. Johannes SchindelinJul 26, 2018
  24. Joan DaemenJul 22, 2018
  25. Adam LangleyJul 22, 2018
  26. Johannes SchindelinJul 26, 2018
  27. demerphqJul 23, 2018
  28. Sitaram ChamartyJul 23, 2018
  29. demerphqJul 23, 2018
  30. Linus TorvaldsJul 23, 2018
  31. Stefan BellerJul 23, 2018
  32. Jonathan NiederJul 23, 2018
  33. Edward ThomsonJul 24, 2018
  34. Linus TorvaldsJul 24, 2018
  35. Jonathan NiederJul 24, 2018
  36. Junio C HamanoJul 24, 2018
  37. brian m. carlsonJul 24, 2018
  38. Johannes SchindelinJul 30, 2018
  39. Dan ShumowJul 30, 2018
  40. Jonathan NiederAug 3, 2018
  41. Joan DaemenSep 18, 2018
  42. Jonathan NiederSep 18, 2018
  43. Linus TorvaldsSep 18, 2018
  44. 0/2 document that NewHash is now SHA-256Ævar Arnfjörð Bjarmason, Jul 25, 2018
  45. 1/2 doc hash-function-transition: note the lack of a changelogÆvar Arnfjörð Bjarmason, Jul 25, 2018
  46. 2/2 doc hash-function-transition: pick SHA-256 as NewHashÆvar Arnfjörð Bjarmason, Jul 25, 2018
  47. Junio C HamanoJul 25, 2018
  48. Jonathan NiederJul 25, 2018
  49. Junio C HamanoJul 25, 2018
  50. 2/2 doc hash-function-transition: pick SHA-256 as NewHashÆvar Arnfjörð Bjarmason, Jul 26, 2018
  51. Jonathan NiederAug 3, 2018
  52. Junio C HamanoAug 3, 2018
  53. Linus TorvaldsAug 3, 2018
  54. Linus TorvaldsAug 3, 2018
  55. Ævar Arnfjörð BjarmasonAug 3, 2018
  56. Jonathan NiederAug 4, 2018
  57. brian m. carlsonAug 3, 2018
  58. brian m. carlsonJul 25, 2018
  59. Ævar Arnfjörð BjarmasonJun 11, 2018
  60. Johannes SchindelinJun 21, 2018
  61. brian m. carlsonJun 21, 2018
  62. Duy NguyenJun 11, 2018
  63. brian m. carlsonJun 12, 2018
  64. Jonathan NiederJun 11, 2018
  65. brian m. carlsonJun 12, 2018
  66. Jonathan NiederJun 12, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.