Prevention of algorithmic complexity attacks.
Hm. That is reasoning for randomising the seed for the hashing algorithm; but not reasoning for changing the hash algorithm itself.
It also doesn't explain why you would do it on a hash-by-hash basis rather than a per-process basis.
I don't get the reluctance to share this information?
In reply to Re^12: Hash order randomization is coming, are you ready?
by BrowserUk
in thread Hash order randomization is coming, are you ready?
by demerphq
For: | Use: | ||
& | & | ||
< | < | ||
> | > | ||
[ | [ | ||
] | ] |