Skip to content

Comment on Revisiting the “Cookieless Domain” Recommendationparent

Comments

Even a very serious attack against SHA-512 would be unlikely to render it as weak as RIPEMD-160 (compare even e.g. MD4, which is pretty thoroughly broken but the attacks still take compute time). If you have the bits, it's better to spend them on a longer hash rather than more hashes.

Even a very serious attack against SHA-512 would

What makes you think you can predict the consequences of an attack against SHA-512?

Don't put all your eggs in one basket.

What makes you think you can predict the consequences of an attack against SHA-512?

70 years of cryptographic history.

Don't put all your eggs in one basket.

Don't use cryptographic primitives in ways they weren't designed for. That's a surefire recipe for disaster.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.