Re: TFM needed ro R

David Rudder <drig@magicweb.com> Mon, 16 September 1996 16:36 UTC

Received: from cnri by ietf.org id aa14075; 16 Sep 96 12:36 EDT
Received: from neptune.hq.tis.com by CNRI.Reston.VA.US id aa09347; 16 Sep 96 12:36 EDT
Received: from neptune.tis.com by neptune.TIS.COM id aa16761; 16 Sep 96 12:17 EDT
Received: from relay.hq.tis.com by neptune.TIS.COM id aa16746; 16 Sep 96 12:13 EDT
Received: by relay.hq.tis.com; id MAA05963; Mon, 16 Sep 1996 12:16:29 -0400
Received: from sol.hq.tis.com(10.33.1.100) by relay.tis.com via smap (V3.1.1) id xma005955; Mon, 16 Sep 96 12:16:03 -0400
Received: from relay.hq.tis.com by tis.com (4.1/SUN-5.64) id AA10542; Mon, 16 Sep 96 12:15:17 EDT
Received: by relay.hq.tis.com; id MAA05947; Mon, 16 Sep 1996 12:16:01 -0400
Received: from ws5.magicweb.com(207.88.92.102) by relay.tis.com via smap (V3.1.1) id xma005930; Mon, 16 Sep 96 12:15:30 -0400
Received: (from drig@localhost) by drig.magicweb.com (8.6.12/8.6.9) id JAA02871; Mon, 16 Sep 1996 09:16:54 -0700
Date: Mon, 16 Sep 1996 09:16:48 -0700
From: David Rudder <drig@magicweb.com>
To: Ned Freed <Ned.Freed@innosoft.com>
Cc: pem-dev@tis.com
Subject: Re: TFM needed ro R
In-Reply-To: <01I9FPRGR3US8Y5I6P@INNOSOFT.COM>
Message-Id: <Pine.LNX.3.91.960916090432.2832A-100000@drig.magicweb.com>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: pem-dev-approval@neptune.tis.com
Precedence: bulk

On Fri, 13 Sep 1996, Ned Freed wrote:

> It is worse than Schneier says -- there are newer results now. See the current
> issue of RSA's CryptoBytes publication, Volume 2 Number 2, Summer 1996, for
> details. Online copies are available in
> http://www.rsa.com/rsalabs/cryptobytes/.

Hmm...looks bad.  

> 
> The bottom line is that new application should no longer specify MD5 as a MIC.
> And MD2 has been obsolete for some time. Use either SHA-1 or RIPEMD-160.
> (I prefer the former.)
> 
> 				Ned
> 
> 
> 

Okay, will do.  Does anyone have a reference for the RIPE-MD algorithm?  
The library I'm using doesn't have it and Applied Cryptography dedicates 
6.5 lines to it with no algorithm.  SHA I have.

Okay, so the various MDs are going to be included only for compatibility 
with old software.  But, I still need to support them.  This is probably 
opening a pandora's box, but which should I use by default, SHA or 
RIPE-MD?  Is one better than the other, does one or the other have nasty 
patents or weird export controls?

			-Dave
		   drig@magicweb.com

I got a coffee mug from Cray Research when they moved out.  Now I can 
drink my coffee while doing 63 other, unrelated tasks.