Imminent Collisions for SHA-1?

A discussion has broken out about when the defeat of SHA-1 hashing will happen. That’s “when”, not “if”, because it’s just a matter of time and the growth of computing resources or the decline in the price of computing resources that matter. The method of attack is already known. If a better attack develops the defeat could come in just a few years bringing unprecedented chaos to IT. Rather than having to buy computing resources, the bad guys can just rent a botnet and have a million PCs doing what they want at any time. That means the bad guys will win if we do nothing.

Should we hedge our bets and use a variety of hashes so that whichever one is defeated first can just be dropped with minimal problems? Should we require simultaneous checks with multiple hashes? That would seem to make finding a collision more difficult. The first crack of SHA-1 is extremely unlikely to simultaneously collide with MD-5.

“A collision attack is therefore well within the range of what an organized crime syndicate can practically budget by 2018, and a university research project by 2021.”

see Schneier on Security: When Will We See Collisions for SHA-1?.

- Robert Pogson

0 Responses to “Imminent Collisions for SHA-1?”


  1. No Comments

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>




Archives by Month

My Mission

My observations and opinions about IT are based on 40 years of use in science and technology and lately, in education. I like IT that is fast, cost-effective and reliable. I do not care whether my solution is the same as yours. I like to think for myself.

My first use of GNU/Linux in 2001 was so remarkably better than what I had been using, I feel it is important work to share GNU/Linux with the world. I have been blessed by working in schools where students and school systems have benefited by good, modular software easily installed in most systems.

I have shown GNU/Linux to thousands of students and hundreds of teachers over the years and will continue in some way doing that until I die in spite of the opposition.

Posts

October 2012
S M T W T F S
« Sep   Nov »
 123456
78910111213
14151617181920
21222324252627
28293031  

    Writing

    3429 articles
    30592 comments

      Comments

      platforms
      linux 17466
      windows 12765
      macos 206
      sun 3
      wp 2

      browsers
      firefox 23909 
      safari 11862 
      chrome 11714 
      ie 4637 
      iceweasel 4261 
      opera 1642 
      konqueror 198 
      netnewswire 14 
      epiphany 2 
      flock 0 
      bonecho 0 
      lynx 0 

Bad Behavior has blocked 6236 access attempts in the last 7 days.