SHA-1: A Collision Of Research & Practicality
Mark Nunnikhoven
Principal @ Amazon | I make security and privacy easier to understand
This week brought a fascinating announcement from the team at Google and CWI: they presented a "practical" attack on the SHA-1 hashing algorithm.
There's been a ton of great coverage on the announcement but no one can seem to agree on what the day-to-day impact is. The SHA-1 algorithm has long been deprecated but still pops up in a regular usage (hello git, time to update).
Are these occurrences anything to worry about? Just because this announcement has a slick site & clever name (kudos, btw) and is getting press, is the sky actually falling?
Short answer? No.
Read my long answer over on the Trend Micro blog.