Sitting-Duc Posted October 10, 2015 Member ID: 561 Group: ++++ Senior Admin Followers: 85 Topic Count: 502 Topics Per Day: 0.09 Content Count: 5336 Content Per Day: 0.94 Reputation: 4612 Achievement Points: 41356 Solved Content: 0 Days Won: 29 Joined: 10/14/09 Status: Offline Last Seen: Monday at 05:58 PM Birthday: 04/06/1992 Device: Windows Posted October 10, 2015 Just for anyone like me and is interested in the security side of computing. SHA-1 has had a collision detected and should now be viewed as an insecure encryption method. The CA's and browser authorities are voting on the matter of how long to honor certificated issued with SHA-1 encryption and it will probably be only to the end of 2016 (https://cabforum.org/pipermail/public/2015-October/006048.html). This is similar to when MD5 collisions started to be detected and a similar process will now take place to remove the functions use from computing. The collision details can be found here: https://docs.google.com/viewer?url=https%3A%2F%2Fsites.google.com%2Fsite%2Fitstheshappening%2Fshappening_article.pdf%3Fattredirects%3D0 eidolonFIRE 1 Awards
loaderXI Posted October 11, 2015 Member ID: 252 Group: +++ COD2 Head Admin Followers: 72 Topic Count: 396 Topics Per Day: 0.07 Content Count: 6439 Content Per Day: 1.12 Reputation: 6582 Achievement Points: 54661 Solved Content: 0 Days Won: 32 Joined: 09/05/09 Status: Offline Last Seen: Tuesday at 01:36 AM Birthday: 03/22/1965 Device: Windows Posted October 11, 2015 What kind of Global impact will this have as far as the transition not being met by companies and major websites...If you could or had to give a percentage at a guess...What would you give ? and what major effects could be seen from this as far as securities Awards
Sammy Posted October 11, 2015 Member ID: 3036 Group: ***- Inactive Clan Members Followers: 32 Topic Count: 219 Topics Per Day: 0.04 Content Count: 9419 Content Per Day: 1.91 Reputation: 7515 Achievement Points: 62539 Solved Content: 0 Days Won: 21 Joined: 11/29/11 Status: Offline Last Seen: March 17 Birthday: 04/26/2008 Device: Windows Posted October 11, 2015 Looks like you have to be a pretty advanced mathematician to understand all of that. Awards
Sitting-Duc Posted October 11, 2015 Member ID: 561 Group: ++++ Senior Admin Followers: 85 Topic Count: 502 Topics Per Day: 0.09 Content Count: 5336 Content Per Day: 0.94 Reputation: 4612 Achievement Points: 41356 Solved Content: 0 Days Won: 29 Joined: 10/14/09 Status: Offline Last Seen: Monday at 05:58 PM Birthday: 04/06/1992 Device: Windows Author Posted October 11, 2015 @@loaderXI Easily over 80% of secure websites are using SHA1, probably closer to 90%. That means within the next year they all have to reissue their certificates using SHA2 or another supported encryption method. The released collision is not usable but confirms that today's technologies are now able to create collisions and therefore begin to exploit them. Conspiracy theorists will jump saying that governments are most likely already exploiting the encryption method like they did with MD5. For the average user it doesn't matter that much but it certainly shows how encryption is not infallible. eidolonFIRE 1 Awards
eidolonFIRE Posted October 11, 2015 Member ID: 2759 Group: **- Inactive Registered Users Followers: 17 Topic Count: 199 Topics Per Day: 0.04 Content Count: 3496 Content Per Day: 0.70 Reputation: 3021 Achievement Points: 26464 Solved Content: 0 Days Won: 3 Joined: 08/22/11 Status: Offline Last Seen: June 16, 2017 Birthday: 07/27/1990 Posted October 11, 2015 wow..... at least AES is still holding lol.
Sammy Posted October 11, 2015 Member ID: 3036 Group: ***- Inactive Clan Members Followers: 32 Topic Count: 219 Topics Per Day: 0.04 Content Count: 9419 Content Per Day: 1.91 Reputation: 7515 Achievement Points: 62539 Solved Content: 0 Days Won: 21 Joined: 11/29/11 Status: Offline Last Seen: March 17 Birthday: 04/26/2008 Device: Windows Posted October 11, 2015 Yup some governments are most definitely doing it. At least on a low level. Simply because if they didnt do it they they wouldnt be very good at their jobs. Awards
Recommended Posts