Home Business IT Security Keccak wins the SHA-3 competition
Get all your tech news delivered to your mail box five days a week
iTWire UPDATE - it's FREE!


Following an extensive selection process, the winner of NIST's 5-year competition to select a new hash algorithm standard has been announced.

A hash algorithm is used to verify the contents of a message (perhaps a file or a document) as being unchanged. Consider it to be a validation signature; it is not encryption and has no part to play in protecting the contents of a message; merely proof that the message received was the same as the one transmitted.

This task is performed using a computationally complex algorithm that is impossible to reverse - of course it cannot be revered when a multi-megabyte source file will generate the same sized hash as a small text file. Furthermore, the slightest change to the source file (perhaps adding a single space character to the end of a document) will produce a totally different hash. Conversely, it is also important to be sure that there cannot be two different source files that produce the same hash (this is normally referred to as a collision).

Many observers had expected Bruce Schneier's Skein algorithm to win this competition although Schneier himself argued a week ago that there was no pressing need to select a winner at all; "It's probably too late for me to affect the final decision, but I am hoping for 'no award'."

He continued, "It's not that the new hash functions aren't any good, it's that we don't really need one. When we started this process back in 2006, it looked as if we would be needing a new hash function soon. The SHA family (which is really part of the MD4 and MD5 family), was under increasing pressure from new types of cryptanalysis. We didn't know how long the various SHA-2 variants would remain secure. But it's 2012, and SHA-512 is still looking good."

Many respondents to the blog disagreed with him, primarily on the basis that there was merit in having two unrelated standards which could be interchanged quickly. That way, if one was suddenly discovered to be 'broken,' the other could take up the workload with minimal interruption.

Later in a reply to his own blog post, Schneier opines, "I have no inside information on when SHA-3 will be announced. My guess is that they've made the decision, and are going over the final rationale again and again.

"My guess is that it won't be Skein."

He was correct.

Just a few hours ago Keccack (pronounced 'catch-ack') was announced by the US' National Institute of Standards and Technology (NIST) as the winner.

RECRUITMENT & RETENTION REPORT 2013

HIRE OR FIRE? BUY OR BUILD

2013 is well underway and Australian companies need to know whether they should invest in IT skills training or pay a premium for the people they need.

If you want to know which choices are being made in your sector, what skills are hard to find, which sectors intend to hire or fire and where the IT spend is going, this free report is must have.

GET YOUR REPORT NOW

David Heath

joomla statistics

David Heath has over 25 years experience in the IT industry, specializing particularly in customer support, security and computer networking. Heath has worked previously as head of IT for The Television Shopping Network, as the network and desktop manager for Armstrong Jones (a major funds management organization) and has consulted into various Australian federal government agencies (including the Department of Immigration and the Australian Bureau of Criminal Intelligence). He has also served on various state, national and international committees for Novell Users International; he was also the organising chairman for the 1994 Novell Users' Conference in Brisbane. Heath is currently employed as an Instructional Designer, building technical training courses for industrial process control systems.

Connect

http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=tf&c=19&mc=imp&pli=5460041&PluID=0&ord=[2000]&rtu=-1