In my previous post, I considered what good would come of using your method. Then I got to thinking if there were any bad effects of including the length. For small messages like passwords, the harm is obvious. It would make them easier to guess. I don't know about the harm for longer messages, but an information leak of any kind can't possibly be good.
I thought of using a salted hash of the length instead, but that wouldn't help.
In reply to Re: (OT)Speculation: 128-bit digest + 64-bit length (192-bits) is more reliable and unique than a 256-digest alone.
by ikegami
in thread (OT)Speculation: 128-bit digest + 64-bit length (192-bits) is more reliable and unique than a 256-digest alone.
by BrowserUk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |