MD6 withdrawn from SHA-3 competition

Joseph Ashwood ashwood at
Thu Jul 2 23:51:47 EDT 2009

Sent: Wednesday, July 01, 2009 4:05 PM
Subject: MD6 withdrawn from SHA-3 competition

> Also from Bruce Schneier, a report that MD6 was withdrawn from the SHA-3
> competition because of performance considerations.

I find this disappointing. With the rate of destruction of primitives in any 
such competition I would've liked to see them let it stay until it is either 
broken or at least until the second round. A quick glance at the SHA-3 zoo 
and you won't see much left with no attacks. It would be different if it was 
yet another M-D, using AES as a foundation, blah, blah, blah, but MD6 is a 
truly unique and interesting design.

I hope the report is wrong, and in keeping that hope alive, the MD6 page has 
no statement about the withdrawl.

The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at

More information about the cryptography mailing list