Gradually sunsetting SHA-1
googleonlinesecurity.blogspot.com
Gradually sunsetting SHA-1
1–10 of 100 posts
Re: Gradually sunsetting SHA-1
#2Re: Gradually sunsetting SHA-1
#3Reward the ones who embrace stronger security, punish (within reason, and gradually) those who don't.
Re: Gradually sunsetting SHA-1
#4Re: Gradually sunsetting SHA-1
#5Also, does Google believe that we should stop using SHA-1 for other things too, or is this only an issue with really high-profile, high-reward targets like certificates?
Re: Gradually sunsetting SHA-1
#6Given that there are plenty of op-codes left, the network can probably easily start switching into in the next generation of hashing algorithms.
This is the beautiful thing about open networks, it evolves organically. Whereas you can't say the same about bank protocols.
Re: Gradually sunsetting SHA-1
#7I notice there's no mention of what should be used instead. I'm sure that it's obvious to a lot of people, but not to me. Are we supposed to use SHA-2? SHA-3? Or something else? Also, does Google believe that we should stop using SHA-1 for other things too, or is this only an issue with really high-profile, high-reward targets like certificates?
SHA-1 has been deprecated for a while but is still in (very) widespread use, see: http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-13... http://news.netcraft.com/archives/2014/02/04/nist-continues-...
Re: Gradually sunsetting SHA-1
#8[deleted]
Re: Gradually sunsetting SHA-1
#9Re: Gradually sunsetting SHA-1
#10The problem i have with their "neutral, lacking security" icon is that it does not indicate that anything is wrong when in fact there is. https:// should never have a neutral icon. it should be VALID or INVALID.