|Cryptographers show collision in SHA-1 algorithm|
|By special contributor Alfman on 2017-03-01 08:30:04|
On February 23rd, a joint team from the CWI Amsterdam and Google announced that they had generated the first ever collision in the SHA-1 cryptographic hashing algorithm. SHA-1 has long been considered theoretically insecure by cryptanalysts due to weaknesses in the algorithm design, but this marks the first time researchers were actually able to demonstrate a real-world example of the insecurity. In addition to being a powerful Proof of Concept (POC), the computing power that went into generating the proof was notable.
So what's the big deal?
Unfortunately, the migration away from SHA-1 has not been universal. Some programs, such as the version control system Git, have SHA-1 hard-baked into its code. This makes it difficult for projects which rely on Git to ditch the algorithm altogether. The encrypted e-mail system PGP also relies on it in certain places.
- "Gmail app developers have been reading your emails" - 2018-07-03
- Wi-Fi Alliance introduces WPA3 security - 2018-06-26
- Verizon and AT&T will stop selling your phone's location - 2018-06-20
- Apple just took a shot at Facebook's web-tracking empire - 2018-06-05
- More related articles