Live data from Hacker News

Gradually sunsetting SHA-1

googleonlinesecurity.blogspot.com

41–50 of 100 posts

Re: Gradually sunsetting SHA-1

#41
post #15

This is about to become a massive issue for Godaddy SSL users[1] seeing that Godaddy has still not added their G2 CA server (which signs all SHA-2 certs at Godaddy) to the default truststore for Java and some other devices/languages/platforms! [1] http://stackoverflow.com/questions/18746565/godaddy-ssl-cert...

Excellent; this should be another reason for some people to no longer be a client of one of the worst companies in the tech sector today.

I'll leave CA recommendations to those who deal with them more than I, but if you use Godaddy as a registrar I would urge you to switch to Gandi.net (or namecheap.com if you cannot afford Gandi).

Re: Gradually sunsetting SHA-1

#42
post #33

Earlier quoted context omitted.

The world will be switching to SHA-256 - Microsoft already decided that last November [1]. This is just Chrome helping out. Obviously, XP is a problem. We're planning on prompting Chrome users on affected versions to update, both at startup and on the error page. SP3 does exist and one doesn't need to pass the Genuine Windows check to install it[2] so I think we have a good chance to getting users to update once site…

While I'm a huge fan of what you're doing in terms of crypto at Google, it's hard for me to see this decision as anything other than reckless. I think we'll be able to show a number of empirical examples of how, over the coming months, it will make the web a less secure place as sites that we're just now starting to convince to adopt crypto will stop. I do at least hope that you will make efforts to alert more of the…

Unfortunately we don't have the technical ability, nor do people have the mental capacity, to cope with multiple URL schemes for different "levels" of security. SHA-1 limits the security for everyone and all uses. And if sites are worried about compat, Google will be doing this transition along with everyone else. That's a good tailwind to ride.

If Microsoft's 2016/2017 deadline is reckless, what SHA-1 deprecation date would be right by your measure? Some have suggested ~2020 (5 years issuance from 2015). Would you really be happy depending on SHA-1 in 2020?

(Edit: on re-read, the 2020 suggestion sounds like a strawman - but that's actually what we were on the road towards and we may not have even managed that.)

Re: Gradually sunsetting SHA-1

#43

I think it's really crazy that certificates are now declared insecure based on their expiration date. We've deployed several certificates with a three year validity (i.e. valid after 1-Jan-2017), and since our CA could only provide SHA-1, that's what we're using. Now these certificates get marked as insecure. However, if we'd gone for a 2 year validity, we'd be fine until somewhere in 2016. How does this help securit…

You have to draw a line in the sand somewhere... And as mentioned elsewhere, you could keep using your SHA-1 certificate for older user agents while serving modern platforms a new, SHA-256 certificate in your name. Dropping SHA-1 in 2015 is better than doing so in 2016, after all. ;-)

Re: Gradually sunsetting SHA-1

#44

I'm concerned that the net effect of this will be to make the Internet less secure. In most cases, webmasters will be forced to make a Faustian choice: live with the scary warning in Chrome for modern users or give up support of browsers running on Windows XP (pre-SP3) and early versions of Android (pre-2.3), since they don't support certificates with a more secure hash than SHA1. We'll likely write a blog post soon…

> It's a startling amount.

It's a startling amount today. Just by virtue of making the announcement, Google knocks that number down quite a bit.

Honestly, in a world where your choices are "doesn't work" and "secure", and there is no in between "works but isn't secure", security becomes a LOT simpler.

Re: Gradually sunsetting SHA-1

#45

Anybody know what the easiest way to determine if your certificate is affected? I looked at my certificate and it says Signature Algorithm is "SHA-1 with RSA Encryption". Is this affected? When I viewed the certificate for google.com it also said "SHA-1 with RSA Encryption".

Yes. Both those certificates are affected. If I had to guess, Google will begin issuing a non-SHA1 cert to modern browser users and a SHA1 certificate to older browsers before the end of September. I wish I could give you easy advice on how to do that yourself.

Thanks for the reply, I thought I was understanding it correctly. Now that I think about it more, they will still be able to use SHA-1 and not be affected because they will surely just issue another certificate that only lasts 1 year which means it will expire before January 2016, so it will still show up as Green in Chrome. Sucks for me because we paid for a cert through July 2017 and now we'll probably have to pay more money to get a non-SHA1 cert.

Re: Gradually sunsetting SHA-1

#46
post #15

This is about to become a massive issue for Godaddy SSL users[1] seeing that Godaddy has still not added their G2 CA server (which signs all SHA-2 certs at Godaddy) to the default truststore for Java and some other devices/languages/platforms! [1] http://stackoverflow.com/questions/18746565/godaddy-ssl-cert...

If the G2 CA is signed by their other CAs which are in the trust root, you can just add it to the chain you're serving, right?

Re: Gradually sunsetting SHA-1

#47
post #42

Earlier quoted context omitted.

While I'm a huge fan of what you're doing in terms of crypto at Google, it's hard for me to see this decision as anything other than reckless. I think we'll be able to show a number of empirical examples of how, over the coming months, it will make the web a less secure place as sites that we're just now starting to convince to adopt crypto will stop. I do at least hope that you will make efforts to alert more of the…

Unfortunately we don't have the technical ability, nor do people have the mental capacity, to cope with multiple URL schemes for different "levels" of security. SHA-1 limits the security for everyone and all uses. And if sites are worried about compat, Google will be doing this transition along with everyone else. That's a good tailwind to ride. If Microsoft's 2016/2017 deadline is reckless, what SHA-1 deprecation da…

You say that Google will be doing this transition along with everyone else, but you won't be feeling the same pain. Google's current cert expires November 24th, 2014, so when you extend it then it will be for 1 year and your new cert will expire before January 1st, 2016 which is pretty convenient for you because that cert (even if it is SHA-1) will still show up as a green bar through Chrome 41 so it will have no impact for you. I also second eastdakota's response that this was pretty crappy to drop as a Friday afternoon announcement.

Re: Gradually sunsetting SHA-1

#48
post #42

Earlier quoted context omitted.

Unfortunately we don't have the technical ability, nor do people have the mental capacity, to cope with multiple URL schemes for different "levels" of security. SHA-1 limits the security for everyone and all uses. And if sites are worried about compat, Google will be doing this transition along with everyone else. That's a good tailwind to ride. If Microsoft's 2016/2017 deadline is reckless, what SHA-1 deprecation da…

You say that Google will be doing this transition along with everyone else, but you won't be feeling the same pain. Google's current cert expires November 24th, 2014, so when you extend it then it will be for 1 year and your new cert will expire before January 1st, 2016 which is pretty convenient for you because that cert (even if it is SHA-1) will still show up as a green bar through Chrome 41 so it will have no imp…

(Google's certificates only last three months and that's not because of this announcement.)

The transition that I'm talking about is the transition to SHA-256 overall. If you're in a position where your CA sold you a certificate that they shouldn't have then I feel sorry, but if you're blaming us for that then I think you're pointing in the wrong direction.

Re: Gradually sunsetting SHA-1

#49

Anybody know what the easiest way to determine if your certificate is affected? I looked at my certificate and it says Signature Algorithm is "SHA-1 with RSA Encryption". Is this affected? When I viewed the certificate for google.com it also said "SHA-1 with RSA Encryption".

Yes. Both those certificates are affected. If I had to guess, Google will begin issuing a non-SHA1 cert to modern browser users and a SHA1 certificate to older browsers before the end of September. I wish I could give you easy advice on how to do that yourself.

How? I would expect anything that might identify the browser would be sent after the encryption was set up?
Post reply on HN