INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Log In

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips Forums!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.

Jobs

Possible to use SHA-3 for encrypting database data?

Possible to use SHA-3 for encrypting database data?

(OP)
We are working with a vendor that will be in custody of some of our business data (e.g., customer contact info, products purchased, payment info, and similar). To get a sense of how our data will be protected, I asked a few questions about data encryption and data backup. When I asked i asked if our data will be stored encrypted, they said 'yes' and they do so using SHA-3.

I am not an expert, but I feel I know enough to sense that this doesn't sound right. My understanding is the SHA is a hashng function and that SHA-3 hasn't been ratify yet.

Before I go back to my vendor to question them about this, I would those familiar with this to comment about what I researched and determined.  If I am missing something or I am wrong, please let me know.

Much appreciated. Thank you in advance.

RE: Possible to use SHA-3 for encrypting database data?

The way I've always understood it, a hash value is to prove that a set of data has not been modified or corrupted from its original value.  For example, you want to download a fun free game from the internet.  They give you a hash value for the EXE installer.  You find a site to download it.  You could compare the hash value that they give (from the real unadulterated file) with one for the file that you actually download.

If they are different, then the file is not what it should be - intentionally or accidentally changed.

So for backup, this would be a way of verifying that what they have in storage or going into their storage is YOUR data in good condition.

Encryption of your data before it leaves your premises is what you should be asking about.  Maybe you're talking to the wrong person or maybe this company doesn't know enough to be in charge of your data.

For example, Mozy uses 448-bit encryption on data before it leaves my computer so as to be "un-hackable" on its way to their servers.

Make sense??  Be wary of using these people if they can't give you good answers.  It's ONLY your data.

RE: Possible to use SHA-3 for encrypting database data?

(OP)
Thank goombawaho. Yes, it makes sense. I appreciate your input. It helps me validate my concern..

Red Flag This Post

Please let us know here why this post is inappropriate. Reasons such as off-topic, duplicates, flames, illegal, vulgar, or students posting their homework.

Red Flag Submitted

Thank you for helping keep Tek-Tips Forums free from inappropriate posts.
The Tek-Tips staff will check this out and take appropriate action.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Resources

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close