My argument concerning performance is that for long messages SipHash isn't actually significantly faster than (possibly round reduced) MD5, Skein, Blake2 etc.
The main selling point of SipHash is that it's faster than normal crypto hashes for short messages. Since ZFS almost always hashes long messages, the advantage of SipHash doesn't matter. _______________________________________________ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography