BugTraq
Combining Hashes Feb 18 2005 03:24PM
Kent Borg (kentborg borg org) (4 replies)
Re: Combining Hashes Feb 19 2005 11:32AM
Felix Cuello (felix qodiga com) (1 replies)
Re: Combining Hashes Feb 20 2005 04:40AM
Joel Maslak (jmaslak antelope net)
Re: Combining Hashes Feb 19 2005 10:11AM
exon (exon home se)
Re: [lists] Combining Hashes Feb 19 2005 05:14AM
Elliott Bäck (ecb29 cornell edu)
Re: Combining Hashes Feb 19 2005 04:54AM
Aaron Mizrachi (unmanarc) (aaron synacksecurity com) (2 replies)
Re: Combining Hashes Feb 20 2005 09:10PM
Ivan Krstic (krstic hcs harvard edu)
Re: Combining Hashes Feb 20 2005 05:30PM
Frank Knobbe (frank knobbe us)
On Sat, 2005-02-19 at 00:54 -0400, Aaron Mizrachi wrote:
> [...] The better
> method (i think) is: HASH(HASH(data)), because adds two layer... and have the
> same or more security than HASH(data).

That's not an improvement. If you can fiddle data so that the inner hash
has the same value as before the fiddling, the outer hash remains the
same as well -- doesn't give you anything except a false sense of
security. Kent's idea was better in that you would have to find common
collisions in both algorithms in order to keep both hashes.

Regards,
Frank

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus