Perry E. Metzger (perry@piermont.com)
Mon, 29 Jun 1998 15:13:00 -0400
Cicero writes:
> Alex Alten <Andrade@netcom.com> wrote:
> >At 04:20 PM 6/24/98 -0400, mgraffam@mhv.net wrote:
> >>Uh.. why not just use a hash algoritm to hash a passphrase down to
> >>128 bits, if you really only want 64, just truncate it.
> >
> >Never truncate a hash, unless you understand its design.
> >
> >- Alex
>
> Can you give an example to illustrate your point? Are you saying that
> there are instances where truncating SHA-1 or MD5 can lead to a
> problem?
I'm actually under the impression that using a truncated hash output
in lieu of the hash produces a more secure result under many
circumstances.
.pm
The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:19:12 ADT