Live data from Hacker News

Gradually sunsetting SHA-1

googleonlinesecurity.blogspot.com

1–10 of 100 posts

Re: Gradually sunsetting SHA-1

#3
Mozilla and IE should adopt similar policies, and not just for SHA1 deprecation, but for other weak security protocols, too. If website A uses much weaker security than website B, they shouldn't be treated equally by the browser.

Reward the ones who embrace stronger security, punish (within reason, and gradually) those who don't.

Re: Gradually sunsetting SHA-1

#4
The problem i have with their "neutral, lacking security" icon is that it does not indicate that anything is wrong when in fact there is. https:// should never have a neutral icon. it should be VALID or INVALID.

Re: Gradually sunsetting SHA-1

#5
I notice there's no mention of what should be used instead. I'm sure that it's obvious to a lot of people, but not to me. Are we supposed to use SHA-2? SHA-3? Or something else?

Also, does Google believe that we should stop using SHA-1 for other things too, or is this only an issue with really high-profile, high-reward targets like certificates?

Re: Gradually sunsetting SHA-1

#6
This leads to me to think about the longer term viability of bitcoin. Bitcoin uses a combination of RIPEMD and SHA256. Given the sha-2 family was released in 2001, when is SHA-2 going to go into depreciation cycle and what does that mean for the bitcoin network.

Given that there are plenty of op-codes left, the network can probably easily start switching into in the next generation of hashing algorithms.

This is the beautiful thing about open networks, it evolves organically. Whereas you can't say the same about bank protocols.

Re: Gradually sunsetting SHA-1

#7
post #5

I notice there's no mention of what should be used instead. I'm sure that it's obvious to a lot of people, but not to me. Are we supposed to use SHA-2? SHA-3? Or something else? Also, does Google believe that we should stop using SHA-1 for other things too, or is this only an issue with really high-profile, high-reward targets like certificates?

SHA-2 for new certificates.

SHA-1 has been deprecated for a while but is still in (very) widespread use, see: http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-13... http://news.netcraft.com/archives/2014/02/04/nist-continues-...

Re: Gradually sunsetting SHA-1

#10
post #4

The problem i have with their "neutral, lacking security" icon is that it does not indicate that anything is wrong when in fact there is. https:// should never have a neutral icon. it should be VALID or INVALID.

There's nothing wrong with a valid SHA-1 certificate.
Post reply on HN