[Geek-Crypto] New Results Against SHA-1
Apr. 30th, 2009 06:16 pmhttp://eurocrypt2009rump.cr.yp.to/837a0a8086fa6ca714249409ddfae43d.pdf
There is not much hard information yet, but the two big quotes are "SHA-1 collisions now 2^52" and "Practical collisions are within resources of a well funded organisation."Hmm, what to do about all the applications where SHA-1 is hardwired? There's still plenty of MD-5 out there too.
no subject
Date: 2009-04-30 11:32 pm (UTC)no subject
Date: 2009-05-01 01:51 am (UTC)I think the plan these people have is, with a tip o’ the hat to Sluggy, “commence simultaneous panic, on my mark…”
no subject
Date: 2009-05-02 04:01 pm (UTC)The nice thing is that most of its uses can live with weak algorithms as long as key rotation is used. But as a counter to that, key rotation happens very seldom. IKE and routing protocols don't coexist very well.
no subject
Date: 2009-05-03 12:24 am (UTC)The thing which stuns me most about the IETF’s push towards SHA–1 is that they are once again learning almost exactly the wrong lesson from history.
Which algorithms are used is not relevant. Algorithms have a finite life span. The existence of a migration mechanism is enormously relevant, and most protocols don’t have it.
no subject
Date: 2009-05-03 12:23 pm (UTC)