ietf-openpgp
[Top] [All Lists]

Re: A review of hash function brittleness in OpenPGP

2009-01-09 19:27:50

Jon Callas wrote:
(Let me put on my hash-designer's hat for a moment. In Skein, we  
created a one-pass MAC construction that can replace HMAC. It also has  
a proof of security.

I wish people would stop saying that things have "a proof of security".
Rot13 has a proof of security, but I don't want to use it. You need to
state what security properties you have proved.

-- 
http://www.apache-ssl.org/ben.html           http://www.links.org/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff