ietf-openpgp
[Top] [All Lists]

Re: re-consideration of TIGER

2004-08-18 07:42:00

* <vedaal(_at_)hush(_dot_)com> wrote:
would it be reasonable to re-accept the non-sha based hashes, (e.g. TIGER)
as a potential backup hash for implementations/users that may wish to
begin doing so?

Unless the attack is not substantiated, wild actionism should be avoided.
Currently the attack looks like exploiting insufficient highest bit handling
of the internal state variables. This is a matter if the protocol applies a
random(!) padding directly before hashing.


<Prev in Thread] Current Thread [Next in Thread>