Stop using SHA1: It’s now completely unsafe

in #news7 years ago

From CIO

Security researchers have achieved the first real-world collision attack against the SHA-1 hash function, producing two different PDF files with the same SHA-1 signature. This shows that the algorithm's use for security-sensitive functions should be discontinued as soon as possible.

SHA-1 (Secure Hash Algorithm 1) dates back to 1995 and has been known to be vulnerable to theoretical attacks since 2005. The U.S. National Institute of Standards and Technology has banned the use of SHA-1 by U.S. federal agencies since 2010, and digital certificate authorities have not been allowed to issue SHA-1-signed certificates since Jan. 1, 2016, although some exemptions have been made.

However, despite these efforts to phase out the use of SHA-1 in some areas, the algorithm is still fairly widely used to validate credit card transactions, electronic documents, email PGP/GPG signatures, open-source software repositories, backups and software updates.

A hash function such as SHA-1 is used to calculate an alphanumeric string that serves as the cryptographic representation of a file or a piece of data. This is called a digest and can serve as a digital signature. It is supposed to be unique and non-reversible.

If a weakness is found in a hash function that allows for two files to have the same digest, the function is considered cryptographically broken, because digital fingerprints generated with it can be forged and cannot be trusted. Attackers could, for example, create a rogue software update that would be accepted and executed by an update mechanism that validates updates by checking digital signatures.

...

Read more here: http://www.cio.com/article/3173788/security/stop-using-sha1-it-s-now-completely-unsafe.html
Make sure to follow this profile @contentjunkie to stay up to date on more great posts like this one.

Sort:  

Super Interesting, Need to learn more about Hashing!

Definitely known to have been vulnerable. Albeit with Five Eyes surveillance going around who knows what is safe anymore.

This post has been ranked within the top 50 most undervalued posts in the first half of Feb 24. We estimate that this post is undervalued by $3.87 as compared to a scenario in which every voter had an equal say.

See the full rankings and details in The Daily Tribune: Feb 24 - Part I. You can also read about some of our methodology, data analysis and technical details in our initial post.

If you are the author and would prefer not to receive these comments, simply reply "Stop" to this comment.

Coin Marketplace

STEEM 0.31
TRX 0.11
JST 0.033
BTC 64733.60
ETH 3170.85
USDT 1.00
SBD 4.16