Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A 128-bit key is more than plenty; don't be ridiculous.

The prior partial sha1/md5 implementation usage was pretty dubious.

Siphash has significant performance improvements for things like syncookies and secure sequence numbers.

Your comment about knowing the address of the key and taking it out of kernel memory... wtf? If you can read arbitrary kernel memory, it's already game over. The whole attack model relies on ring 0 being ring 0.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: