Merkle Signature Scheme is the most secure signature scheme possible for general-purpose use

mheyman at gmail.com mheyman at gmail.com
Wed Sep 8 12:29:28 EDT 2010


On Fri, Sep 3, 2010 at 10:29 AM, Jack Lloyd <lloyd at randombit.net> wrote:
> On Fri, Sep 03, 2010 at 09:45:20AM +0100, Ben Laurie wrote:
>
> ...narrow-pipe designs have a huge null space for messages
> which are exactly as big as the compression function input
> size. For instance hashing inputs that are multiples of 512 bits,
> SHA-256 will only produce about 63% of the possible 2^256
> outputs.
>
So we deal with SHA-255.33 instead of SHA-256. Not a big enough
difference to worry about.
----
-Michael Heyman

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list