RE: CBV
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 6 May 2004, Seth Goodman wrote: > > From: Tony Finch > > Sent: Thursday, May 06, 2004 7:28 AM > > > > > > <...> > > > Note that this simple form of hash is not as safe as you might expect. I'm > > told by a security expert: "MD5 and SHA-1 output an intermediate value of > > their computation from which a hash of the original string plus an > > extension can be calculated. They can therefore not be used safely to > > calculate a MAC as h(key, string), hence HMAC." So we should use RFC2104 > > hashes. > > This is big news if it is true. I always thought SHA-1 was suitable for > HMAC's, but I would really like to know if it is not. If what you are > saying is true, isn't it a problem for the existing SRS address format as > well? I am not aware of this weakness. I have also done my research. I would like to see a proper reference for it. S. -- Shevek http://www.anarres.org/ I am the Borg. http://www.gothnicity.org/