Thread (70 messages) flat view 70 messages, 11 authors, 2016-12-18

Re: [kernel-hardening] Re: [PATCH v2 1/4] siphash: add cryptographically secure hashtable function

From: Daniel Micay <hidden>
Date: 2016-12-15 08:16:10
Also in: linux-crypto, lkml

On Thu, 2016-12-15 at 15:57 +0800, Herbert Xu wrote:
Jason A. Donenfeld [off-list ref] wrote:
quoted
Siphash needs a random secret key, yes. The point is that the hash
function remains secure so long as the secret key is kept secret.
Other functions can't make the same guarantee, and so nervous
periodic
key rotation is necessary, but in most cases nothing is done, and so
things just leak over time.
Actually those users that use rhashtable now have a much more
sophisticated defence against these attacks, dyanmic rehashing
when bucket length exceeds a preset limit.

Cheers,
Key independent collisions won't be mitigated by picking a new secret.

A simple solution with clear security properties is ideal.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help