To quote Wikipedia:
>BLAKE2 removes addition of constants to message words from BLAKE round function, changes two rotation constants, simplifies padding, adds parameter block that is XOR'ed with initialization vectors, and reduces the number of rounds from 16 to 12 for BLAKE2b (successor of BLAKE-512), and from 14 to 10 for BLAKE2s (successor of BLAKE-256).
https://en.wikipedia.org/wiki/BLAKE_(hash_function)#BLAKE2
Reducing the rounds by 4 might raise eyebrows wrt security, but Aumasson's 'Too Much Crypto' discusses BLAKE vs BLAKE2 among other things: https://eprint.iacr.org/2019/1492.pdf
Why kernel devs didn't go with BLAKE3, I can't say.
Maybe people just liked it better that way?
It also seems to be almost as fast according to the BLAKE3 specs PDF (page 11).
https://github.com/BLAKE3-team/BLAKE3-specs/blob/master/blak...
but it just BLAKE2, BLAKE3 got a nope
SHA1's a long time gone, that crypto's a slowpoke
Why did BLAKE3 and SHA1 get the works?
That's nobody's business, even Turks!
It would only result in small incremental perf improvement due to reduced number of rounds (10 to 7).
Majority of Blake3's perf benefit manifests from merkle-tree structure and SIMD processing of multiple input streams at the same time.
To add to this: BLAKE2 is derived from BLAKE only, whereas BLAKE3 is derived from Bao AND BLAKE2.
> Why kernel devs didn't go with BLAKE3, I can't say.
I think tptacek has it right: this thing is used very infrequently (period 300 seconds) and blake2 was already in the kernel, so they just reused it. It’s adequately fast, even if blake3 would be marginally faster.
To sum up: BLAKE3 has no advantages over BLAKE2 when it comes to the Linux kernel[1], plus BLAKE2 is already in the kernel (with tests and everything), while BLAKE3 is not (at all). That, and BLAKE3 is still fairly new.
[1] It is faster than BLAKE2 due to parallelism, which is not suitable for the Linux kernel; you want to restrict computation to a single thread instead of making all the cores busy. FWIW, the C reference implementation is not multi-threaded either.