Skip to main content

Research paper provides evidence of first known SHA-1 collision

SHA-1 is a cryptographic hash function that underpins various security applications and protocols to help keep the internet safe. Experts, however, have warned for years that it’s out of date. Now, evidence of the first known “collision” of two files with the same SHA-1 hash has demonstrated that the function is no longer safe to use.

A collision refers to an event where two separate files or messages produce the same cryptographic hash, which malicious entities can use to feign authentication  and facilitate an attack. While this has been observed before in relation to other hash algorithms, this is the first time that two SHA-1 hashes have collided, according to a report from Ars Technica.

Recommended Videos

SHA1 was officially deprecated by the National Institute of Standards and Technology in 2011, but the algorithm is still in use despite doubts about its security. In November 2016, Microsoft joined Google and Mozilla in making preparations to start blocking sites that use SHA-1 protection.

paper that was published Thursday demonstrates that SHA-1 is unsafe as of right now, and should be retired immediately. The paper is the result of two years of collaborative work undertaken by the Centrum Wiskunde & Informatica, a national research center in Amsterdam, and Google’s security, privacy, and anti-abuse research group.

It would take a great deal of computing power to carry out an attack that takes advantage of an SHA-1 collision — however, that kind of muscle is ready available, as long as the perpetrators have enough financial backing. The paper states that an attack could be performed using Amazon Web Services for as little as $110,000.

Google’s disclosure policy dictates that source code used to perform the collision detailed in the paper will be released in 90 days. As a result, the sites and services that still use SHA-1 hashing will need to discontinue their usage of the algorithm before that date, as those materials will make it much easier for an attack to be carried out.

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Google demos its smartglasses and makes us hanker for the future
A screenshot from Google's TED Talk on its smartglasses.

At a recent TED talk, Google’s exciting XR smartglasses were demonstrated to the public for the very first time. While we’ve seen the smartglasses before, it has always been in highly polished videos showcasing Project Astra, where we never get a true feel for the features and functionality in the real world. All that has now changed, and our first glimpse of the future is very exciting. However, future is very much the operative word. 

https://www.ted.com/talks/shahram_izadi_the_next_computer_your_glasses?utm_campaign=tedspread&utm_medium=referral&utm_source=tedcomshare

Read more
The HP Victus gaming PC with RTX 4060 is under $1,000 with this deal
The black version of the HP Victus 15L gaming PC.

Replacing your aging gaming desktop doesn't have to leave a huge dent in your wallet, as there are affordable options like the HP Victus 15L. The price for this configuration with the Nvidia GeForce RTX 4060 graphics card is even lower right now, following a $350 discount from HP. Instead of $1,200, you'll only have to pay $850, but only if you hurry because this offer may not last much longer. A lot of gamers are looking for a budget-friendly upgrade from gaming PC deals, so secure your purchase as soon as possible before stocks run out.

Why you should buy the HP Victus 15L gaming desktop

Read more
Kagi’s AI search assistant gives you access to all the big models in one place
Kagi search bar in light mode.

Kagi's "Assistant" feature, previously only available to Ultimate subscribers, is now rolling out to all tiers -- including the free trial tier. The feature gives you access to a range of different LLMs for both chatting and web-searching purposes.

If you don't know much about Kagi, it's a paid search engine that borrows its name from the Japanese word for "key." The concept is simple -- with Google, you pay for the service by allowing ads and data collection. With Kagi, you pay for the service with money to get a private and ad-free experience.

Read more