RE: CBV

"Seth Goodman" <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
> From: Tony Finch
> Sent: Thursday, May 06, 2004 7:28 AM
>
>

<...>

> Note that this simple form of hash is not as safe as you might expect. I'm
> told by a security expert: "MD5 and SHA-1 output an intermediate value of
> their computation from which a hash of the original string plus an
> extension can be calculated. They can therefore not be used safely to
> calculate a MAC as h(key, string), hence HMAC." So we should use RFC2104
> hashes.

This is big news if it is true.  I always thought SHA-1 was suitable for
HMAC's, but I would really like to know if it is not.  If what you are
saying is true, isn't it a problem for the existing SRS address format as
well?

--

Seth Goodman
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.