Handshake Papers
Handshake Papers
@HandshakePapers

Is SHA-1 still acceptable for internal or non-critical certificates?

Is SHA-1 still acceptable for internal or non-critical certificates?

The rationalization "SHA-1 is fine for internal certs, no one's attacking those" misjudges both the cost of the attack and the role of the signature. SHA-1 is the hash over which a CA computes a certificate's signature. A collision — two different inputs hashing to the same digest — lets an attacker craft a benign certificate signed by a CA and a malicious one sharing that signature, transplanting the trust.

This stopped being theoretical in 2017 when Stevens et al. produced SHACK/SHAttered, the first practical SHA-1 collision, and in 2020 Leurent and Peyrin demonstrated a chosen-prefix collision for roughly $45,000 of compute — directly applicable to certificate forgery. "Internal" does not change the math; it only changes who you imagine the attacker to be, and chosen-prefix collisions are now within reach of well-resourced adversaries and falling in price.

Browsers stopped accepting publicly-trusted SHA-1 certificates in 2017. The mandated baseline is SHA-256 or stronger (the SHA-2 family). There is no security argument for SHA-1 signatures on any new certificate.

— Chosen-prefix SHA-1 collisions are practical and cheap
— Forged certificates are the direct threat
— SHA-256 is the floor everywhere

Further reading: Leurent & Peyrin, "SHA-1 is a Shambles" (2020).
Bottom line: SHA-1 certificate signatures are forgeable today. "Internal" is not an exemption; use SHA-256.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.