FacebookInstagramTwitterContact

 

Hibiscus Tea Improves Blood Flow, Reduces Risk Of Cardiovascular Disease           >>           Beer Brewed To Music And A Crystal Castle — How To Have An A-List Getaway In Byron Bay           >>           Sleep Is Good For Your Heart, Reduces Risk Of CVD, According To Study           >>           Black Nightshade Reduces Growth Of Cancerous Tumors           >>           You Won't Be Able To Unsee Ryan Gosling's La La Land Confession           >>           Kate Middleton And Prince William’s Designer Friend Says They’re “Going Through Hell”           >>           Eta Aquarid Meteor Shower Peak Could Spawn Over 100 'Shooting Stars' Per Hour This Weekend           >>           Nintendo blitzes GitHub with over 8,000 emulator-related DMCA takedowns           >>           X Is Using Grok To Publish AI-Generated News Summaries           >>           Microsoft’s latest Windows security updates might break your VPN           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Google Helps Put Aging SHA-1 Encryption Out To Pasture


Google

 


 February 25th, 2017  |  11:28 AM  |   1456 views

ENGADGETS.COM

 

The first "collision" makes website attacks 100,000 times faster.

 

The decades-old SHA-1 encryption used to protect websites is already dying, but a discovery from Google and security researcher CWI Amsterdam could be the killing blow. For the first time, they've found a way to generate a "collision" and create the same critical hash function multiple times. The discovery will make it 100,000 times easier for attackers to slip malicious files into websites or servers than by a brute force attack. That new should help end its use, increasing security around the internet.

 

Breaking SHA-1 has been a goal of security users for quite a while, so it's quite a feather in Google's cap to be first. (It's possible, though, that the NSA, Russians or others have had one that they've kept under wraps.) The team said that the collision "is one of the largest computations ever completed," so Google's cloud infrastructure was an indispensable part of that.

 

There's no great danger for users. Google Chrome, Microsoft's Edge, Firefox and all other major browsers flag HTTPS sites that use SHA-1 as insecure with a big red warning -- so very few use it for verifying digital content. The team won't release the attack (Dad-jokingly called "SHAttered") for 90 days, in order to give affected sites time to deal with it.

 

Also, even though Google has made it 100,000 times faster to crack an SHA-1 certificate, it would still require some serious computing horsepower to do so. Google says it requires 12 million GPUs a full year to brute force a certificate, while the SHA-1 "Shattered" attack takes just 110 GPUs. For now, however, you'd still need a supercomputer or server farm (or a bot farm) to crack one in a reasonable amount of time.

 

As a proof of concept, Google is hosting two PDFs with the different content but the same hash, and has supplied the public with a free detection app. It had a lot of motivation to be first with a collision. It led the movement to deprecate SHA-1 because it's advertising business relies heavily on secure sites and ad platforms -- making the discovery a giant "I told you so" of sorts.

 


 

Source:
courtesy of ENGADGET

by Steve Dent

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Myanmar Stops Men From Working Abroad As War Intensifies

 2024-05-04 00:38:42

Have The Wheels Come Off For Tesla?

 2024-05-04 07:51:07