[17107] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: how to phase in new hash algorithms?

daemon@ATHENA.MIT.EDU (Ian G)
Sun Mar 20 23:21:50 2005

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 21 Mar 2005 00:42:02 +0000
From: Ian G <iang@systemics.com>
To: "Steven M. Bellovin" <smb@cs.columbia.edu>
Cc: cryptography@metzdowd.com
In-Reply-To: <20050316170201.2BC253C04DC@berkshire.machshav.com>

Steven M. Bellovin wrote:

> So -- what should we as a community be doing now?  There's no emergency 
> on SHA1, but we do need to start, and soon.

The wider question is how to get moving on new hash
algorithms.  That's a bit tricky.

Normally we'd look to see NIST or the NESSIE guys
lead a competition.  But NESSIE just finished a
comp, and may not have the appetite for another.
NIST likewise just came out with SHA256 et al, and
they seem to have a full work load as it is trying
to get DSS-2 out.

How about the IACR?  Would they be up to leading
a competition?  I don't know them at all myself,
but if the Shandong results are heard at IACR
conferences, then maybe it's time to take on a
larger role.

Most of the effort could be volunteer, and it would
also be easy enough to schedule everything aligned
with the conference circuit.

Just a thought.  Anyone know anyone at the IACR?

iang
-- 
News and views on what matters in finance+crypto:
         http://financialcryptography.com/

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post