Are there any examples, prominent or obscure?
(Who the hell would buy something with "SHA-1, but different"?)
Are there any examples, prominent or obscure?
(Who the hell would buy something with "SHA-1, but different"?)
As for why? Intentional incompatibility with the standard hash usually, often as security-by-obscurity or to lock users into using their products.
I've personally worked with NIH SSL systems based on the idea of XOR'ing the messages with the 3rd byte of a header field called 'CryptoKey' or something like that. There are all sorts of homebrew crypto systems out there in the wild, if you're lucky it's based on an actual algorithm, but mostly it's worst than an enigma machine.
In the case of the system I was working with the 3rd byte of the message was always a : so I ditched the whole look at the header thing, and just XOR'd the 3rd byte with : to derived the 'key'.