Re: md5() algorithm, probabilities

From: Date: Fri, 21 Jul 2000 12:30:31 +0000
Subject: Re: md5() algorithm, probabilities
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-25337@lists.php.net to get a copy of this message
On Fri, 21 Jul 2000, waldschrott wrote: > > Well, it depends on what you call "slow". Most cryptographical functions > > are not fast - they do a lot of complicated things. I'm not sure on > > comparative analysis of hash-functions, but I'm almost sure the above book > > should have some pointers on that. That's The Book in applied > > cryptography :) > > I´ve ordered that book and md5() isn´t what I´d call "slow" (I´ve > benchmarked now), perhaps I´d rather say "not fast". > To ensure that I´ve understood... > > after executing this for a arbitrary $l with a strlen *below* 128 Bits... > > for ($i=1;$i<=$tot;$i++) $n[md5($i)]=TRUE; > > ...sizeof($n) equals $tot The perfect hash function foo could be described this way: Applying a hash function foo to each, arbitrary-long member of a set consisting of n elements will generate n unique, m-bit long keys with a probability of 2^m/n. Note however that MD5 is not a perfect hash function. But it is good enough for your standard needs. > In other words it generates unique identifiers up to length of 128Bits Not up to length of 128 bits. It always generates a block consisting of exactly 128 bits. > I´ve tried with $tot=1000000 where every key was unique. PHP is not the proper tool to run brute force attacks against hash functions. Some would argue that brute force attacks against hash functions are pointless at all. - Sascha

« previous php.dev (#25337) next »