Does it add any additional security to multi-layer multiple hash algorithms and/or multiple runs of the same algo?
For example, sha1(md5(sha1(foo)))
Does it add any additional security to multi-layer multiple hash algorithms and/or multiple runs of the same algo?
For example, sha1(md5(sha1(foo)))
With some padding to make them the same size.
https://www.iacr.org/archive/crypto2004/31520306/multicollis...
> If F and G are good iterated hash functions with no attack better than the generic birthday paradox attack, we claim that the hash function F||G obtained by concatenating F and G is not really more secure that F or G by itself.
In your example, if sha1(foo)==sha1(bar), then foo, bar have a collision regardless of what you do afterwards.
Maybe there’s some fancier layering scheme that adds security?
When done correctly, it increases the security. It's like encrypting a file with AES and then encrypting it with Twofish and then Serpent.
The security is actually the strongest link; not the weakest.
That's why bitcoin addresses use SHA256(RIPEMD160(X)) for output into a 160 bit hash.
Concatenating the outputs of the hash functions fixes that particular issue. But concatenating makes preimage attacks easier.
decreases security because the output of MD5 is 128 bits, compared with 160 bits for SHA-1. The arbitrarily long input foo is reduced to an input of 128 bits at the final step, and you only need to find that input for a collision (independently of any MD5-specific weakness you may also have added to the mix).
HMAC is, in part, a way to do that: