top | item 45695719

Length-extension attacks are still a thing

2 points| charles_irl | 4 months ago |00f.net

1 comment

order

PaulHoule|4 months ago

There is HMAC but also you can defend against those attacks by throwing away some of the bits. For instance do SHA-512 and keep just the first 256 bits.