Hi Daniel, On Fri, Dec 16, 2016 at 9:44 PM, Daniel Micay <danielmicay@xxxxxxxxx> wrote: > On Fri, 2016-12-16 at 11:47 -0800, Tom Herbert wrote: >> >> That's about 3x of jhash speed (7 nsecs). So that might closer >> to a more palatable replacement for jhash. Do we lose any security >> advantages with halfsiphash? > > Have you tested a lower round SipHash? Probably best to stick with the > usual construction for non-DoS mitigation, but why not try SipHash 1-3, > 1-2, etc. for DoS mitigation? > > Rust and Swift both went with SipHash 1-3 for hash tables. Maybe not a bad idea. SipHash2-4 for MD5 replacement, as we've done so far. This is when we actually want things to be secure (and fast). And then HalfSipHash1-3 for certain jhash replacements. This is for when we're talking only about DoS or sort of just joking about security, and want things to be very competitive with jhash. (Of course for 64-bit we'd use SipHash1-3 instead of HalfSipHash for the speedup.) I need to think on this a bit more, but preliminarily, I guess this would be maybe okay... George, JP - what do you think? Jason -- To unsubscribe from this list: send the line "unsubscribe linux-crypto" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html