Google Breaks SHA-1, And Not A Moment Too Soon

Collision attack illustrated

Google announced that it achieved the first practical collision attack against the SHA-1 function. SHA-1 support is now mostly dropped from browsers due to Google’s aggressive efforts to deprecate it over the past few years. However, the company has received significant criticism for trying to deprecate SHA-1 too early.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Sakkura
    Google have almost been too patient about retiring this broken old piece of 90s tech. The article describes SHA-2 as "next-gen," but it was released in 2001. It's ancient, it's unbelievable that anyone was wanting to hold on to something even more ancient in 2016.

    SHA-3 is the truly next-gen algorithm, and it was released in 2015. Companies should be actively working on adding support for that, so we don't run into the same issue in 5-10 years when SHA-2 might need to be retired.
    Reply
  • alextheblue
    There they go with the arbitrary 90 days again. Not 120 days, not 5 months. 90 days and boom, every website better have SHA-1 replaced with SHA-2. Google has spoken!
    Reply
  • derekullo
    1. Thou Shall not be Evil
    2. Thou Shall not use Sha-1
    3. Thou Shall not speak of Yahoo
    Reply