| ... | ... | @@ -20,8 +20,10 @@ const mem = std.mem; |
| 20 | 20 | /// SipHash function with 64-bit output. |
| 21 | 21 | /// |
| 22 | 22 | /// Recommended parameters are: |
| 23 | /// - (c_rounds=4, d_rounds=8) for conservative security; regular hash functions such as BLAKE2 or BLAKE3 are usually a better alternative. |
| 23 | 24 | /// - (c_rounds=2, d_rounds=4) standard parameters. |
| 24 | | /// - (c_rounds=1, d_rounds=2) reduced-round function. Faster, no known implications on its practical security level. |
| 25 | /// - (c_rounds=1, d_rounds=3) reduced-round function. Faster, no known implications on its practical security level. |
| 26 | /// - (c_rounds=1, d_rounds=2) fastest option, but the output may be distinguishable from random data with related keys or non-uniform input - not suitable as a PRF. |
| 25 | 27 | /// |
| 26 | 28 | /// SipHash is not a traditional hash function. If the input includes untrusted content, a secret key is absolutely necessary. |
| 27 | 29 | /// And due to its small output size, collisions in SipHash64 can be found with an exhaustive search. |
| ... | ... | @@ -32,8 +34,11 @@ pub fn SipHash64(comptime c_rounds: usize, comptime d_rounds: usize) type { |
| 32 | 34 | /// SipHash function with 128-bit output. |
| 33 | 35 | /// |
| 34 | 36 | /// Recommended parameters are: |
| 37 | /// - (c_rounds=4, d_rounds=8) for conservative security; regular hash functions such as BLAKE2 or BLAKE3 are usually a better alternative. |
| 35 | 38 | /// - (c_rounds=2, d_rounds=4) standard parameters. |
| 36 | | /// - (c_rounds=1, d_rounds=2) reduced-round function. Faster, no known implications on its practical security level. |
| 39 | /// - (c_rounds=1, d_rounds=4) reduced-round function. Recommended to hash very short, similar strings, when a 128-bit PRF output is still required. |
| 40 | /// - (c_rounds=1, d_rounds=3) reduced-round function. Faster, no known implications on its practical security level. |
| 41 | /// - (c_rounds=1, d_rounds=2) fastest option, but the output may be distinguishable from random data with related keys or non-uniform input - not suitable as a PRF. |
| 37 | 42 | /// |
| 38 | 43 | /// SipHash is not a traditional hash function. If the input includes untrusted content, a secret key is absolutely necessary. |
| 39 | 44 | pub fn SipHash128(comptime c_rounds: usize, comptime d_rounds: usize) type { |