How to make hash functions go fast inside snarks. The state of the art of arithmetisation friendly hash functions (useful for all cryptographic protocols where cost is dominated by multiplications -- e.g. anything using R1CS, all secret sharing based multiparty computation protocols, etc).