Google shatters SHA-1 prompting calls to pull it from use

Encryption system has already been deprecated by NIST, but some companies still use it

A major cryptographic standard has been broken in practice, leading for calls to hurry efforts to fully pull it from use.

Google revealed that it "shattered" SHA-1, an encryption system that was deprecated by the National Institute of Standards and Technology in 2011. While it's no longer in wide use, some applications still rely on it, the researchers noted.

The Google's security team produced a "collision" with SHA-1, which is when two pieces of data such as a document or a website's certificate are reduced to the same hash digest.  

"Hash functions compress large amounts of data into a small message digest," Google explained in a blog post. "As a cryptographic requirement for wide-spread use, finding two messages that lead to the same digest should be computationally infeasible. Over time however, this requirement can fail due to attacks on the mathematical underpinnings of hash functions or to increases in computational power."

Advertisement - Article continues below
Advertisement - Article continues below

As SHA-1 has known flaws, it's long been thought to be possible for an attacker to craft such a collision. "The attacker could then use this collision to deceive systems that rely on hashes into accepting a malicious file in place of its benign counterpart," Google added.

Such an attack has long been known to be theoretically possible, but it took two years of work between Google and the CWI Institute in Amsterdam to manage it in practice which required one of the "largest computations ever completed".

Google used its cloud system to run it, using 6,500 of CPU computation to complete the first attack phase and 110 years of GPU computation for the second.

"While those numbers seem very large, the SHA-1 shattered attack is still more than 100,000 times faster than a brute force attack which remains impractical," Google added.

Kevin Bocek, chief cyber-security strategist for Venafi, said the announcement confirms what we already knew that SHA-1 isn't secure. "This is no longer science fiction," said Bocek. "Unfortunately, despite the dangers, organisations are just not reacting."

While SHA-1's use has been discouraged for years, Venafi's research at the end of last year suggested 35% of organisations were still using certificates based on its encryption.

Advertisement - Article continues below

"The time to eradicate SHA-1 digital certificates is now and it needs to be eradicated everywhere from the public Internet to the deepest parts of private networks and datacenters," he added. "We are already past the SHA-1 deprecation deadline and the longer the problem goes unaddressed, the greater the potential damage that SHA-1 could cause."

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now


internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020
General Data Protection Regulation (GDPR)

Data protection fines hit £100m during first 18 months of GDPR

20 Jan 2020