Re: md5() algorithm, probabilities
| From: | Sascha Schumann | Date: | Fri, 21 Jul 2000 12:30:31 +0000 |
| Subject: | Re: md5() algorithm, probabilities | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-25337@lists.php.net to get a copy of this message | ||
On Fri, 21 Jul 2000, waldschrott wrote:
> > Well, it depends on what you call "slow". Most cryptographical functions
> > are not fast - they do a lot of complicated things. I'm not sure on
> > comparative analysis of hash-functions, but I'm almost sure the above book
> > should have some pointers on that. That's The Book in applied
> > cryptography :)
>
> I´ve ordered that book and md5() isn´t what I´d call "slow" (I´ve
> benchmarked now), perhaps I´d rather say "not fast".
> To ensure that I´ve understood...
>
> after executing this for a arbitrary $l with a strlen *below* 128 Bits...
>
> for ($i=1;$i<=$tot;$i++) $n[md5($i)]=TRUE;
>
> ...sizeof($n) equals $tot
The perfect hash function foo could be described this way:
Applying a hash function foo to each, arbitrary-long member
of a set consisting of n elements will generate n unique,
m-bit long keys with a probability of 2^m/n.
Note however that MD5 is not a perfect hash function. But it
is good enough for your standard needs.
> In other words it generates unique identifiers up to length of 128Bits
Not up to length of 128 bits. It always generates a block
consisting of exactly 128 bits.
> I´ve tried with $tot=1000000 where every key was unique.
PHP is not the proper tool to run brute force attacks against
hash functions. Some would argue that brute force attacks
against hash functions are pointless at all.
- Sascha