Questions about BLAKE (hash function)
Short answers, pulled from the story.
What is the BLAKE hash function and how does it work?
BLAKE is a cryptographic hash function based on Daniel J. Bernstein's ChaCha stream cipher, with message words added at each round and rotation directions reversed. It combines an 8-word hash value with 16 message words repeatedly, producing digests of 224, 256, 384, or 512 bits depending on the variant. It was submitted to the NIST hash function competition by Jean-Philippe Aumasson, Luca Henzen, Willi Meier, and Raphael C.-W. Phan.
Who created BLAKE2 and when was it announced?
BLAKE2 was created by Jean-Philippe Aumasson, Samuel Neves, Zooko Wilcox-O'Hearn, and Christian Winnerlein. It was announced on the 21st of December 2012, with a reference implementation released under CC0, the OpenSSL License, and the Apache License 2.0.
Why did BLAKE lose the SHA-3 competition?
BLAKE reached the final round of five candidates in the NIST hash function competition but lost to Keccak in 2012, which was selected as the SHA-3 algorithm. The source does not specify the precise technical reasons Keccak was chosen over BLAKE.
What systems and software use BLAKE2?
BLAKE2 is used by Argon2 (the Password Hashing Competition winner), WireGuard, WhatsApp's Noise Protocol Framework, Zcash, the NANO cryptocurrency, FreeBSD's package manager, GNU Core Utilities, the btrfs file system, and the Linux kernel (version 5.17 replaced SHA-1 with BLAKE2s in the random number generator entropy pool).
How does BLAKE3 differ from BLAKE2?
BLAKE3 is a single algorithm rather than a family of variants, and it is consistently a few times faster than BLAKE2. It reduces the number of rounds from 10 to 7, uses a binary tree (Merkle tree) structure for practically unlimited parallelism, and supports verified streaming and incremental updates. It was announced on the 9th of January 2020, at the Real World Crypto conference.
What caused the rotation direction difference between BLAKE and ChaCha?
Jean-Philippe Aumasson explained in his Crypto Dictionary that the reversed rotation directions in BLAKE compared to ChaCha originated from a typo in the original BLAKE specifications, not from an intentional optimization. The error was preserved and standardized throughout the algorithm's development.