Re: HASH anyone?
Posted in 2010
On Wed, Feb 10, 2010 at 08:22, John Miller iii <miller3@us.ibm.com> wrote: > Can you please explain the difference between what you are asking > and column level encryption. > > Mike Magie wrote on 02/10/2010 07:31:46 AM: > > Oh and by hash I mean encyption hash, i.e. MD5 - not any other kind > of hash. > The primary difference between a hash of a value and the result of encrypting the same value is that the result of a hash is fully deterministic (you will always get the same value) whereas the encrypted column should be different every time (at least, for the first 2^56 or so repetitions; after that, you might get a couple of values the same by virtue of the Birthday Paradox). It would be good to have cryptographic hashes built into IDS and exposed - they are built-in in the cryptographic libraries (part of GSkit), but not exposed. We can debate whether MD5 should be used - it is not accepted for some purposes because it is too easy to create different texts that hash to the same result. However, were I doing it, I would provide MD5 (128 bits), and SHA1 (160 bits), and the SHA-2 suite (SHA-256, SHA-384, SHA-512). NIST is running a competition to determine a new SHA-3 suite, roughly like it did with the AES encryption. When that is finalized (late next year, IIRC), I would add that, too. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2008.0513 -- http://dbi.perl.org/ "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." NB: Please do not use this email for correspondence. I don't necessarily read it every week, even. Stephen Leacock<http://www.brainyquote.com/quotes/authors/s/stephen_leacock.html> - "I detest life-insurance agents: they always argue that I shall some day die, which is not so." --000e0cd1389688527f047f489986