create account

Stop using SHA1: It’s now completely unsafe by contentjunkie

View this thread on: hive.blogpeakd.comecency.com
· @contentjunkie ·
$0.90
Stop using SHA1: It’s now completely unsafe
<center>http://images.techhive.com/images/article/2016/12/digital_key.jpg-100699424-large.jpeg</center>

From CIO
<blockquote>
Security researchers have achieved the first real-world collision attack against the SHA-1 hash function, producing two different PDF files with the same SHA-1 signature. This shows that the algorithm's use for security-sensitive functions should be discontinued as soon as possible.

SHA-1 (Secure Hash Algorithm 1) dates back to 1995 and has been known to be vulnerable to theoretical attacks since 2005. The U.S. National Institute of Standards and Technology has banned the use of SHA-1 by U.S. federal agencies since 2010, and digital certificate authorities have not been allowed to issue SHA-1-signed certificates since Jan. 1, 2016, although some exemptions have been made.

However, despite these efforts to phase out the use of SHA-1 in some areas, the algorithm is still fairly widely used to validate credit card transactions, electronic documents, email PGP/GPG signatures, open-source software repositories, backups and software updates.

A hash function such as SHA-1 is used to calculate an alphanumeric string that serves as the cryptographic representation of a file or a piece of data. This is called a digest and can serve as a digital signature. It is supposed to be unique and non-reversible.

If a weakness is found in a hash function that allows for two files to have the same digest, the function is considered cryptographically broken, because digital fingerprints generated with it can be forged and cannot be trusted. Attackers could, for example, create a rogue software update that would be accepted and executed by an update mechanism that validates updates by checking digital signatures.

...
</blockquote>
Read more here: http://www.cio.com/article/3173788/security/stop-using-sha1-it-s-now-completely-unsafe.html

<hr>
Make sure to follow this profile @contentjunkie to stay up to date on more great posts like this one.

<a href="https://steemit.com/@contentjunkie"><img src="http://i.imgsafe.org/dd8bd8753d.gif"></a>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 95 others
properties (23)
authorcontentjunkie
permlinkstop-using-sha1-it-s-now-completely-unsafe
categorynews
json_metadata{"tags":["news","science","technology","security","privacy"],"users":["contentjunkie"],"image":["http://images.techhive.com/images/article/2016/12/digital_key.jpg-100699424-large.jpeg","http://i.imgsafe.org/dd8bd8753d.gif"],"links":["http://www.cio.com/article/3173788/security/stop-using-sha1-it-s-now-completely-unsafe.html","https://steemit.com/@contentjunkie"],"app":"steemit/0.1","format":"markdown"}
created2017-02-24 01:12:12
last_update2017-02-24 01:12:12
depth0
children4
last_payout2017-03-27 01:51:03
cashout_time1969-12-31 23:59:59
total_payout_value0.770 HBD
curator_payout_value0.129 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,080
author_reputation253,577,661,205,632
root_title"Stop using SHA1: It’s now completely unsafe"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,579,292
net_rshares10,133,900,080,578
author_curate_reward""
vote details (159)
@cheetah ·
Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
http://warehousediscounts.co.uk/posts/2017/02/stop-using-sha1-its-now-completely-unsafe/
👍  ,
properties (23)
authorcheetah
permlinkcheetah-re-stop-using-sha1-it-s-now-completely-unsafe
categorynews
json_metadata""
created2017-02-24 01:12:39
last_update2017-02-24 01:12:39
depth1
children0
last_payout2017-03-27 01:51:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length187
author_reputation942,693,160,055,713
root_title"Stop using SHA1: It’s now completely unsafe"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,579,297
net_rshares52,601,134,517
author_curate_reward""
vote details (2)
@rebelskum ·
Definitely known to have been vulnerable. Albeit with *Five Eyes* surveillance going around who knows what is safe anymore.
👍  
properties (23)
authorrebelskum
permlinkre-contentjunkie-stop-using-sha1-it-s-now-completely-unsafe-20170224t011435154z
categorynews
json_metadata{"tags":["news"],"app":"steemit/0.1"}
created2017-02-24 01:14:42
last_update2017-02-24 01:14:42
depth1
children0
last_payout2017-03-27 01:51:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length123
author_reputation30,062,385,129,594
root_title"Stop using SHA1: It’s now completely unsafe"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,579,314
net_rshares39,377,943,521
author_curate_reward""
vote details (1)
@screenname ·
Re: Stop using SHA1: It’s now completely unsafe
<p>This post has been ranked within the top 50 most undervalued posts in the first half of Feb 24. We estimate that this post is undervalued by $3.87 as compared to a scenario in which every voter had an equal say.</p> 
<p>See the full rankings and details in <a href="https://steemit.com/curation/@screenname/the-daily-tribune-most-undervalued-posts-of-feb-24---part-i">The Daily Tribune: Feb 24 - Part I</a>. You can also read about some of our methodology, data analysis and technical details in <a href="https://steemit.com/curation/@screenname/introducing-the-daily-tribune-most-undervalued-posts-of-nov-04---part-i">our initial post</a>.</p>
<p>If you are the author and would prefer not to receive these comments, simply reply "Stop" to this comment.</p>
properties (22)
authorscreenname
permlinkre-stop-using-sha1-it-s-now-completely-unsafe-20170224t130900
categorynews
json_metadata"{"replyto": "@contentjunkie/stop-using-sha1-it-s-now-completely-unsafe"}"
created2017-02-24 13:09:00
last_update2017-02-24 13:09:00
depth1
children0
last_payout2017-03-27 01:51:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length762
author_reputation46,276,338,038,330
root_title"Stop using SHA1: It’s now completely unsafe"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,582,702
net_rshares0
@steemitguide ·
Super Interesting, Need to learn more about Hashing!
👍  
properties (23)
authorsteemitguide
permlinkre-contentjunkie-stop-using-sha1-it-s-now-completely-unsafe-20170224t034249626z
categorynews
json_metadata{"tags":["news"],"app":"steemit/0.1"}
created2017-02-24 03:42:48
last_update2017-02-24 03:42:48
depth1
children0
last_payout2017-03-27 01:51:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length52
author_reputation35,147,549,313,619
root_title"Stop using SHA1: It’s now completely unsafe"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id2,580,172
net_rshares39,379,061,416
author_curate_reward""
vote details (1)