<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Don&#8217;t Hash Secrets</title>
	<atom:link href="http://benlog.com/articles/2008/06/19/dont-hash-secrets/feed/" rel="self" type="application/rss+xml" />
	<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/</link>
	<description>security, privacy, transparency.</description>
	<lastBuildDate>Thu, 04 Mar 2010 07:51:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: agilesWissen &#187; Some interesting links&#8230;</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-625627</link>
		<dc:creator>agilesWissen &#187; Some interesting links&#8230;</dc:creator>
		<pubDate>Thu, 04 Mar 2010 07:51:29 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-625627</guid>
		<description>[...] Don’t Hash Secrets [...]</description>
		<content:encoded><![CDATA[<p>[...] Don’t Hash Secrets [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Four short links: 5 February 2010 &#171; Murder Manual</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-625582</link>
		<dc:creator>Four short links: 5 February 2010 &#171; Murder Manual</dc:creator>
		<pubDate>Wed, 10 Feb 2010 07:07:15 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-625582</guid>
		<description>[...] Don&#8217;t Hash Secrets &#8212; One area of secure protocol development that seems to consistently yield poor design choices is the use of hash functions. What I&#8217;m going to say is not 100% correct, but it is on the conservative side of correct, so if you follow the rule, you (probably) can&#8217;t go wrong. You might be considered overly paranoid, but as they say, just because you&#8217;re paranoid doesn&#8217;t mean they&#8217;re not after you. So here it is: Don&#8217;t hash secrets. Never. No, sorry, I know you think your case is special but it&#8217;s not. No. Stop it. Just don&#8217;t do it. You&#8217;re making the cryptographers cry. [...]</description>
		<content:encoded><![CDATA[<p>[...] Don&#8217;t Hash Secrets &#8212; One area of secure protocol development that seems to consistently yield poor design choices is the use of hash functions. What I&#8217;m going to say is not 100% correct, but it is on the conservative side of correct, so if you follow the rule, you (probably) can&#8217;t go wrong. You might be considered overly paranoid, but as they say, just because you&#8217;re paranoid doesn&#8217;t mean they&#8217;re not after you. So here it is: Don&#8217;t hash secrets. Never. No, sorry, I know you think your case is special but it&#8217;s not. No. Stop it. Just don&#8217;t do it. You&#8217;re making the cryptographers cry. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Knowtu &#187; links for 2010-01-29</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-625033</link>
		<dc:creator>Knowtu &#187; links for 2010-01-29</dc:creator>
		<pubDate>Sat, 30 Jan 2010 01:06:45 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-625033</guid>
		<description>[...] Benlog » Don’t Hash Secrets Use HMAC: Hash-function Message Authentication Code. (tags: security DevelopmentWisdom) [...]</description>
		<content:encoded><![CDATA[<p>[...] Benlog » Don’t Hash Secrets Use HMAC: Hash-function Message Authentication Code. (tags: security DevelopmentWisdom) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Blue&#8217;s Blog &#187; Blog Archive &#187; Weekly Lifestream for January 28th</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-624922</link>
		<dc:creator>Eric Blue&#8217;s Blog &#187; Blog Archive &#187; Weekly Lifestream for January 28th</dc:creator>
		<pubDate>Fri, 29 Jan 2010 01:07:39 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-624922</guid>
		<description>[...] Shared Benlog » Don’t Hash Secrets. [...]</description>
		<content:encoded><![CDATA[<p>[...] Shared Benlog » Don’t Hash Secrets. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don&#8217;t Hash Secrets &#124; BlogHalt.com</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-624769</link>
		<dc:creator>Don&#8217;t Hash Secrets &#124; BlogHalt.com</dc:creator>
		<pubDate>Tue, 26 Jan 2010 11:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-624769</guid>
		<description>[...] Don’t Hash Secrets. A well written explanation from 2008 of why you must use hmac instead of raw SHA-1 when hashing against a secret. [...]</description>
		<content:encoded><![CDATA[<p>[...] Don’t Hash Secrets. A well written explanation from 2008 of why you must use hmac instead of raw SHA-1 when hashing against a secret. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Limitations of Hashing &#171; Exhaust the Iterator</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-624735</link>
		<dc:creator>Limitations of Hashing &#171; Exhaust the Iterator</dc:creator>
		<pubDate>Tue, 26 Jan 2010 01:04:53 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-624735</guid>
		<description>[...]    Don&#8217;t Hash Secrets (via). Informative, accessible article that sketches the limitations of hashing, even with a [...]</description>
		<content:encoded><![CDATA[<p>[...]    Don&#8217;t Hash Secrets (via). Informative, accessible article that sketches the limitations of hashing, even with a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stev.ie/ &#187; Blog Archive</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-624676</link>
		<dc:creator>stev.ie/ &#187; Blog Archive</dc:creator>
		<pubDate>Mon, 25 Jan 2010 12:20:36 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-624676</guid>
		<description>[...] Via. [...]</description>
		<content:encoded><![CDATA[<p>[...] Via. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: links for 2010-01-24 &#171; Breyten&#8217;s Dev Blog</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-624580</link>
		<dc:creator>links for 2010-01-24 &#171; Breyten&#8217;s Dev Blog</dc:creator>
		<pubDate>Sun, 24 Jan 2010 11:04:49 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-624580</guid>
		<description>[...] Benlog ? Don?t Hash Secrets (tags: hashing security crypto hmac) [...]</description>
		<content:encoded><![CDATA[<p>[...] Benlog ? Don?t Hash Secrets (tags: hashing security crypto hmac) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joel</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-521056</link>
		<dc:creator>Joel</dc:creator>
		<pubDate>Tue, 31 Mar 2009 07:07:05 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-521056</guid>
		<description>So, in other words: hashing isn&#039;t the magical hammer -- HMAC is!

Seriously, though, I was looking for a resource on the benefits of HMAC vs salted hashes, and this was perfect. Thanks!</description>
		<content:encoded><![CDATA[<p>So, in other words: hashing isn&#8217;t the magical hammer &#8212; HMAC is!</p>
<p>Seriously, though, I was looking for a resource on the benefits of HMAC vs salted hashes, and this was perfect. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anirvan</title>
		<link>http://benlog.com/articles/2008/06/19/dont-hash-secrets/comment-page-1/#comment-515242</link>
		<dc:creator>Anirvan</dc:creator>
		<pubDate>Thu, 19 Mar 2009 04:21:22 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=168#comment-515242</guid>
		<description>Thanks for this post. It was incredibly useful. You got me to switch from appending a secret to using an HMAC digest in an application I&#039;m working on.</description>
		<content:encoded><![CDATA[<p>Thanks for this post. It was incredibly useful. You got me to switch from appending a secret to using an HMAC digest in an application I&#8217;m working on.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
