Repository navigation
[doc] hmac cannot be used with shake algorithms #72570
Copy link
Copy link
Closed
Labels
docsDocumentation in the Doc dirDocumentation in the Doc dir
Description
Activity
HMAC digest methods call inner.digest() with no arguments, but new-in-3.6 shake algorithms require a length argument.
possible solutions:
- add optional length argument to HMAC.[hex]digest, and pass through to inner hash object
- set hmac.digest_size, and use that to pass through to inner hash object if inner hash object has digest_size == 0
- give shake hashers a default value for
lengthin digest methods (logically 32 for shake_256, 16 for shake_128, I think)
test:
import hmac, hashlib h = hmac.HMAC(b'secret', digestmod=hashlib.shake_256) h.hexdigest() # raises on self.inner.digest() requires length argument
- addedextension-modulesC modules in the Modules dirC modules in the Modules dirtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Oct 7, 2016 It's not a bug, but indented behavior. It does not make any sense to use SHAKE with the HMAC construct. In fact it does not make sense to combine Keccak sponge or Blake2 with HMAC at all. HMAC is only necessary for old, Merkle-Damgard hashing algorithms like MD5, SHA1 and SHA2, because they are subject to length extension attacks.
The correct solution is
4. improve documentation- added3.9 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixesdocsDocumentation in the Doc dirDocumentation in the Doc dirand removed3.7 (EOL)end of lifeend of life
on Jan 17, 2022 - changed the title
[-]hmac cannot be used with shake algorithms[/-][+][doc] hmac cannot be used with shake algorithms[/+]on Jan 17, 2022 - removedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errorextension-modulesC modules in the Modules dirC modules in the Modules dir
on Jul 15, 2025 1 remaining item
Now that I've improved the docs, I'll also need to make the interface consistent (because if we use the pure Python HMAC, we raise a TypeError instead of a ValueError) but this will be a separate issue.
Metadata
Metadata
Assignees
Labels
docsDocumentation in the Doc dirDocumentation in the Doc dir
Projects
- StatusShow more project fieldsTodo
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs