Live data from Hacker News

Gradually sunsetting SHA-1

googleonlinesecurity.blogspot.com

11–20 of 100 posts

Re: Gradually sunsetting SHA-1

#11

This leads to me to think about the longer term viability of bitcoin. Bitcoin uses a combination of RIPEMD and SHA256. Given the sha-2 family was released in 2001, when is SHA-2 going to go into depreciation cycle and what does that mean for the bitcoin network. Given that there are plenty of op-codes left, the network can probably easily start switching into in the next generation of hashing algorithms. This is the…

Anyone who has dealt with bank protocols will tell you that "organic" is certainly an apt, if perhaps too kind, word. It's not like it's all designed by committee.

The difference is you don't get to see the haggling and back and forth. Ten years from now, when a large bitcoin institution has a mission-critical legacy app that depends on some facet of the network, we're likely to see similar shenanigans.

I would venture, at least. Simplicity is probably the product of a) abstraction, or b) a small number of stakeholders.

Re: Gradually sunsetting SHA-1

#13
This deprecation policy appears to affect some (possibly all) Startcom SSL certificates, which are chained through "StartCom Class 1 Primary Intermediate Server CA", which is signed with SHA1 and expires on 2017-10-24.

Re: Gradually sunsetting SHA-1

#14
I feel a bit uneasy with having the "unsafe" when SHA1 is technically still safe - just not as safe as, say, sha256 (which is itself probably not as safe as sha512, etc.). It would be nice to have a better "marker" for it instead of having a very fast deprecation rate.

Re: Gradually sunsetting SHA-1

#15
This is about to become a massive issue for Godaddy SSL users[1] seeing that Godaddy has still not added their G2 CA server (which signs all SHA-2 certs at Godaddy) to the default truststore for Java and some other devices/languages/platforms!

[1] http://stackoverflow.com/questions/18746565/godaddy-ssl-cert...

Re: Gradually sunsetting SHA-1

#16

This leads to me to think about the longer term viability of bitcoin. Bitcoin uses a combination of RIPEMD and SHA256. Given the sha-2 family was released in 2001, when is SHA-2 going to go into depreciation cycle and what does that mean for the bitcoin network. Given that there are plenty of op-codes left, the network can probably easily start switching into in the next generation of hashing algorithms. This is the…

It's a common myth. Bitcoin can be easily upgraded to use any algorithm.

https://en.bitcoin.it/wiki/Myths#Quantum_computers_would_bre...

https://en.bitcoin.it/wiki/Myths#Bitcoins_are_worthless_beca...

Re: Gradually sunsetting SHA-1

#17
post #4

The problem i have with their "neutral, lacking security" icon is that it does not indicate that anything is wrong when in fact there is. https:// should never have a neutral icon. it should be VALID or INVALID.

Heh, maybe they could extend it to self-signed being neutral...

Re: Gradually sunsetting SHA-1

#18

This deprecation policy appears to affect some (possibly all) Startcom SSL certificates, which are chained through "StartCom Class 1 Primary Intermediate Server CA", which is signed with SHA1 and expires on 2017-10-24.

It specifically says the dates apply to the end entity. They're not trying to get people off SHA1 in a couple months, they're trying to get them off in a year or two.

Re: Gradually sunsetting SHA-1

#19

This deprecation policy appears to affect some (possibly all) Startcom SSL certificates, which are chained through "StartCom Class 1 Primary Intermediate Server CA", which is signed with SHA1 and expires on 2017-10-24.

Yes, this is going to further insecure the Internet by forcing people back to the for-pay CAs, unless Startcom manages to fix it basically instantly and forces everyone to get new certs, very very quickly.
Post reply on HN