|
Message-ID: <CAHmME9rzHfKxJkU+3+Xg-Wh48nYkhq7bH55RQVCmTXSTgJ2_VA@mail.gmail.com> Date: Fri, 16 Dec 2016 22:09:14 +0100 From: "Jason A. Donenfeld" <Jason@...c4.com> To: Daniel Micay <danielmicay@...il.com> Cc: kernel-hardening@...ts.openwall.com, Jean-Philippe Aumasson <jeanphilippe.aumasson@...il.com>, George Spelvin <linux@...encehorizons.net>, Andi Kleen <ak@...ux.intel.com>, David Miller <davem@...emloft.net>, David Laight <David.Laight@...lab.com>, Eric Biggers <ebiggers3@...il.com>, Hannes Frederic Sowa <hannes@...essinduktion.org>, Linux Crypto Mailing List <linux-crypto@...r.kernel.org>, LKML <linux-kernel@...r.kernel.org>, Andy Lutomirski <luto@...capital.net>, Netdev <netdev@...r.kernel.org>, Linus Torvalds <torvalds@...ux-foundation.org>, "Theodore Ts'o" <tytso@....edu>, Vegard Nossum <vegard.nossum@...il.com>, "Daniel J . Bernstein" <djb@...yp.to> Subject: Re: Re: [PATCH v5 1/4] siphash: add cryptographically secure PRF Hi Daniel, On Fri, Dec 16, 2016 at 9:44 PM, Daniel Micay <danielmicay@...il.com> wrote: > On Fri, 2016-12-16 at 11:47 -0800, Tom Herbert wrote: >> >> That's about 3x of jhash speed (7 nsecs). So that might closer >> to a more palatable replacement for jhash. Do we lose any security >> advantages with halfsiphash? > > Have you tested a lower round SipHash? Probably best to stick with the > usual construction for non-DoS mitigation, but why not try SipHash 1-3, > 1-2, etc. for DoS mitigation? > > Rust and Swift both went with SipHash 1-3 for hash tables. Maybe not a bad idea. SipHash2-4 for MD5 replacement, as we've done so far. This is when we actually want things to be secure (and fast). And then HalfSipHash1-3 for certain jhash replacements. This is for when we're talking only about DoS or sort of just joking about security, and want things to be very competitive with jhash. (Of course for 64-bit we'd use SipHash1-3 instead of HalfSipHash for the speedup.) I need to think on this a bit more, but preliminarily, I guess this would be maybe okay... George, JP - what do you think? Jason
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.