Google shatters SHA-1 prompting calls to pull it from use

Encryption system has already been deprecated by NIST, but some companies still use it

A major cryptographic standard has been broken in practice, leading for calls to hurry efforts to fully pull it from use.

Google revealed that it "shattered" SHA-1, an encryption system that was deprecated by the National Institute of Standards and Technology in 2011. While it's no longer in wide use, some applications still rely on it, the researchers noted.

Advertisement - Article continues below

The Google's security team produced a "collision" with SHA-1, which is when two pieces of data such as a document or a website's certificate are reduced to the same hash digest.  

"Hash functions compress large amounts of data into a small message digest," Google explained in a blog post. "As a cryptographic requirement for wide-spread use, finding two messages that lead to the same digest should be computationally infeasible. Over time however, this requirement can fail due to attacks on the mathematical underpinnings of hash functions or to increases in computational power."

As SHA-1 has known flaws, it's long been thought to be possible for an attacker to craft such a collision. "The attacker could then use this collision to deceive systems that rely on hashes into accepting a malicious file in place of its benign counterpart," Google added.

Such an attack has long been known to be theoretically possible, but it took two years of work between Google and the CWI Institute in Amsterdam to manage it in practice which required one of the "largest computations ever completed".

Advertisement - Article continues below
Advertisement - Article continues below

Google used its cloud system to run it, using 6,500 of CPU computation to complete the first attack phase and 110 years of GPU computation for the second.

"While those numbers seem very large, the SHA-1 shattered attack is still more than 100,000 times faster than a brute force attack which remains impractical," Google added.

Kevin Bocek, chief cyber-security strategist for Venafi, said the announcement confirms what we already knew that SHA-1 isn't secure. "This is no longer science fiction," said Bocek. "Unfortunately, despite the dangers, organisations are just not reacting."

While SHA-1's use has been discouraged for years, Venafi's research at the end of last year suggested 35% of organisations were still using certificates based on its encryption.

"The time to eradicate SHA-1 digital certificates is now and it needs to be eradicated everywhere from the public Internet to the deepest parts of private networks and datacenters," he added. "We are already past the SHA-1 deprecation deadline and the longer the problem goes unaddressed, the greater the potential damage that SHA-1 could cause."

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now


cyber security

Hackers torn over how to adapt their tactics to the coronavirus pandemic

3 Apr 2020
cyber security

Report: 16.5 million Britons fell victim to cyber crime in the past year

1 Apr 2020
Amazon Web Services (AWS)

AWS launches Amazon Detective for investigating security incidents

1 Apr 2020

UK government to launch coronavirus 'contact tracking' app

1 Apr 2020

Most Popular

cyber security

Elon Musk's SpaceX bans Zoom over security fears

2 Apr 2020
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020