in reply to (OT)Speculation: 128-bit digest + 64-bit length (192-bits) is more reliable and unique than a 256-digest alone.

In my previous post, I considered what good would come of using your method. Then I got to thinking if there were any bad effects of including the length. For small messages like passwords, the harm is obvious. It would make them easier to guess. I don't know about the harm for longer messages, but an information leak of any kind can't possibly be good.

I thought of using a salted hash of the length instead, but that wouldn't help.

  • Comment on Re: (OT)Speculation: 128-bit digest + 64-bit length (192-bits) is more reliable and unique than a 256-digest alone.