Live data from Hacker News

Why Google is Hurrying the Web to Kill SHA-1

konklone.com

41–50 of 136 posts

Re: Why Google is Hurrying the Web to Kill SHA-1

#41
A while back I launched a SSL scanner [1] and got tons of feedback from people at Facebook, Google, Microsoft.

The most divisive item was how to represent SHA1 deprecation. The OPs article doesn't really touch on it, but the reason that Google and everyone else haven't moved on is that there still exist a sizeable number of clients that can only accept SHA1 (and will error on anything else).

I actually suspect that large sites like Facebook, etc will maintain multiple certs at the different levels and dynamically serve the best one up that the client can support. They're already doing things like only serving HSTS to browsers that identify as Chrome, etc.

1 - https://www.expeditedssl.com/simple-ssl-scanner/scan?target_...

Re: Why Google is Hurrying the Web to Kill SHA-1

#42
post #38
post #2

Two nits, both pedantic: An attack on SHA1 that makes certificate forgery viable within the next few years doesn't seem very likely, although over the long term it might be. The attack on SHA1 isn't like the attacks on RSA-1024; my sense is that the literature already knows how to break RSA-1024 given enough compute, but does not know how to do that with SHA1. Further, factoring RSA-1024 provides an attacker with a t…

To out-pedant you: even assuming that the differential collision attacks we know about are incorrect [1], we absolutely know how to break SHA-1 given enough compute, that is, roughly the same resources needed to break RSA-1024. The answer is generic collision finding with parallel rho [2]. [1] https://marc-stevens.nl/research/papers/EC13-S.pdf [2] http://people.scs.carleton.ca/~paulv/papers/JoC97.pdf

You haven't so much out-pedanted me as refuted me. :)

Re: Why Google is Hurrying the Web to Kill SHA-1

#43
post #8

Can someone post a summary of the part of the story hinted to by the headline? I couldn't find it.

It's one of the links early in the story. (It's pretty link heavy, so it can be hard to miss. 6th link in). Basically, by 2015, Google will update Chrome to show websites with HTTPS certificates using SHA-1 as "insecure." The level of insecurity shown will get more severe over time, as well as being based on when your certificate expires. Here is the full link for details: http://googleonlinesecurity.blogspot.com/201…

That's What. The headline hints at Why, but never delivers.

Re: Why Google is Hurrying the Web to Kill SHA-1

#44

A while back I launched a SSL scanner [1] and got tons of feedback from people at Facebook, Google, Microsoft. The most divisive item was how to represent SHA1 deprecation. The OPs article doesn't really touch on it, but the reason that Google and everyone else haven't moved on is that there still exist a sizeable number of clients that can only accept SHA1 (and will error on anything else). I actually suspect that l…

a) This is great. Also, a friend linked me to Expedited SSL yesterday and I link to it in the bottom of this post.

b) I think its SHA-1 scanner is mistaken - it flags my site as using SHA-1, but it's SHA-2 in every cert in its chain: https://www.expeditedssl.com/simple-ssl-scanner/scan?target_...

Re: Why Google is Hurrying the Web to Kill SHA-1

#45
post #26
post #2

Two nits, both pedantic: An attack on SHA1 that makes certificate forgery viable within the next few years doesn't seem very likely, although over the long term it might be. The attack on SHA1 isn't like the attacks on RSA-1024; my sense is that the literature already knows how to break RSA-1024 given enough compute, but does not know how to do that with SHA1. Further, factoring RSA-1024 provides an attacker with a t…

Why SHA-2 instead of RSA 4096 or SHA-256? Even the RSA is compromised but 4096-bit will take a lot more(maybe few more hours) resources to decrypt. ==edited== Thank you for the reply.

You use a hash function (e.g. SHA256) to make the hash of the page and a signature algorithm (like RSA 4096) to sign it.

Re: Why Google is Hurrying the Web to Kill SHA-1

#46
post #32

Earlier quoted context omitted.

@tptacek - I tried to include enough detail to make it clear that a SHA-1 forgery isn't as trivial as a brute force. That you'd have to "coax a Certificate Authority" into issuing you a targeted forgery, and that that's what the MD5 team did. The SHA-3 mention at the very bottom was in the spirit of "all things are broken eventually", not a specific comment on SHA-2 (though my understanding is that there are some con…

Another way to think about SHA2 and SHA3 is that it's entirely possible that SHA3 could fall before SHA2 does. They are unrelated algorithms. I'm also not comparing attacks on SHA1 to brute force (which is also not how MD5 fell). It would be helpful, when people posit attacks on SHA1, if they'd cite the literature they're referring to.

> Another way to think about SHA2 and SHA3 is that it's entirely possible that SHA3 could fall before SHA2 does. They are unrelated algorithms.

Very good point, though I would expect SHA2 to see far more research on weakening it. It's been around a lot longer, and its wider deployment makes it a much higher value target. (Is SHA-3 supported anywhere right now?)

Re: Why Google is Hurrying the Web to Kill SHA-1

#47
post #43

Earlier quoted context omitted.

It's one of the links early in the story. (It's pretty link heavy, so it can be hard to miss. 6th link in). Basically, by 2015, Google will update Chrome to show websites with HTTPS certificates using SHA-1 as "insecure." The level of insecurity shown will get more severe over time, as well as being based on when your certificate expires. Here is the full link for details: http://googleonlinesecurity.blogspot.com/201…

That's What . The headline hints at Why , but never delivers.

This entire article is about Why. Read the "An attack on SHA-1 feels plenty viable to me" section for the most info.

Re: Why Google is Hurrying the Web to Kill SHA-1

#48
post #42
post #38

Earlier quoted context omitted.

To out-pedant you: even assuming that the differential collision attacks we know about are incorrect [1], we absolutely know how to break SHA-1 given enough compute, that is, roughly the same resources needed to break RSA-1024. The answer is generic collision finding with parallel rho [2]. [1] https://marc-stevens.nl/research/papers/EC13-S.pdf [2] http://people.scs.carleton.ca/~paulv/papers/JoC97.pdf

You haven't so much out-pedanted me as refuted me. :)

I added links to both papers to the bottom, and removed the "we'll probably need to upgrade" to SHA-3 sentence fragment.

Re: Why Google is Hurrying the Web to Kill SHA-1

#49
post #43

Earlier quoted context omitted.

That's What . The headline hints at Why , but never delivers.

This entire article is about Why. Read the "An attack on SHA-1 feels plenty viable to me" section for the most info.

I see -- it's not announcing any news, or any new theories; it's just a roundup of last week's news.

Re: Why Google is Hurrying the Web to Kill SHA-1

#50
post #36

It's surprising how much energy Certificate Authorities invest into arguing about this. Instead, they should invest that energy into improving their SHA-2 support and helping their customers migrate.

They are businesses. Their customers are mostly businesses. SHA1 is, for most businesses that only want a padlock to reassure their customers, just peachy. A CA that hassles their customers and says "you need to do complicated extra work" is put at a disadvantage to other CA's that have a "customer is always right" kind of attitude. Combined with tools that default to SHA1, and customers that may depressingly actually have Windows XP SP2 terminals still in production use, and you get feet dragging.

I don't think this is inherently a problem with the CA model. Rather it's what you'd expect in a competitive market that is basically selling a binary commodity product (a padlock icon), given textbook economics.

Post reply on HN