SHA1 sunset will block millions from encrypted net, Facebook warns

  • 11 December 2015
  • 1 reply
  • 159 views

Userlevel 7
Badge +54

Companies unveil controversial fallback plan for tens of millions of browsers.

by Dan Goodin (US) - Dec 11, 2015
 
                                                 http://cdn.arstechnica.net/wp-content/uploads/sites/3/2015/12/blocked-640x480.jpg
 
Tens of millions of Internet users will be cut off from encrypted webpages in the coming months unless sites are permitted to continue using SHA1, a cryptographic hashing function that's being retired because it's increasingly vulnerable to real-world forgery attacks, Facebook and Web security company CloudFlare have warned.
 
Facebook said as many as seven percent of the world's browsers are unable to support the SHA256 function that serves as the new minimum requirement starting at the beginning of 2016. That translates into tens of millions of end users, and a disproportionate number of them are from developing countries still struggling to get online or protect themselves against repressive governments. CloudFlare, meanwhile, estimated that more than 37 million people won't be able to access encrypted sites that rely on certificates signed with the new algorithm.
 
Full Article

1 reply

Userlevel 7
So what is the answer?? If these web sites are allowed to retain using SHA1, their web sites are vulnerable to attacks. So the browsers and developers need to step up to accommodate this change one way or the other.

Reply