Without a doubt, SHA1 (like SHA) should not be used for digests. For
other applications, it's fine. For example, the Secure Remote Password
Protocol (SRP) uses SHA produce a fixed length hash of <account,
password, salt> on the server to compute a verifier and on the client
for subsequent authentication. The hash, over, is never stored on the
server and if any case is never exposed to the network.
But for message digests, certificates, licenses, and digital signatures,
OMG!
On 1/9/2020 12:25 PM, marius adrian popa [email protected]
[Firebird-Architect] wrote:
https://arstechnica.com/information-technology/2020/01/pgp-keys-software-security-and-much-more-threatened-by-new-sha1-exploit/
__._,_.___
------------------------------------------------------------------------
Posted by: marius adrian popa <[email protected]>
------------------------------------------------------------------------
Reply via web post
<https://groups.yahoo.com/neo/groups/Firebird-Architect/conversations/messages/11644;_ylc=X3oDMTJwcjMyc2ZjBF9TAzk3MzU5NzE0BGdycElkAzQ2NDE0MgRncnBzcElkAzE3MDUwMDcxODMEbXNnSWQDMTE2NDQEc2VjA2Z0cgRzbGsDcnBseQRzdGltZQMxNTc4NTkwNzMx?act=reply&messageNum=11644>
• Reply to sender
<mailto:[email protected]?subject=Re%3A%20PGP%20keys%2C%20software%20security%2C%20and%20much%20more%20threatened%20by%20new%20SHA1%20exploit>
• Reply to group
<mailto:[email protected]?subject=Re%3A%20PGP%20keys%2C%20software%20security%2C%20and%20much%20more%20threatened%20by%20new%20SHA1%20exploit>
• Start a New Topic
<https://groups.yahoo.com/neo/groups/Firebird-Architect/conversations/newtopic;_ylc=X3oDMTJkMzBia3AzBF9TAzk3MzU5NzE0BGdycElkAzQ2NDE0MgRncnBzcElkAzE3MDUwMDcxODMEc2VjA2Z0cgRzbGsDbnRwYwRzdGltZQMxNTc4NTkwNzMx>
• Messages in this topic
<https://groups.yahoo.com/neo/groups/Firebird-Architect/conversations/topics/11644;_ylc=X3oDMTM1ZDZnanRpBF9TAzk3MzU5NzE0BGdycElkAzQ2NDE0MgRncnBzcElkAzE3MDUwMDcxODMEbXNnSWQDMTE2NDQEc2VjA2Z0cgRzbGsDdnRwYwRzdGltZQMxNTc4NTkwNzMxBHRwY0lkAzExNjQ0>
(1)
Visit Your Group
<https://groups.yahoo.com/neo/groups/Firebird-Architect/info;_ylc=X3oDMTJkdmU1OXRkBF9TAzk3MzU5NzE0BGdycElkAzQ2NDE0MgRncnBzcElkAzE3MDUwMDcxODMEc2VjA3Z0bARzbGsDdmdocARzdGltZQMxNTc4NTkwNzMx>
Yahoo! Groups
<https://groups.yahoo.com/neo;_ylc=X3oDMTJjMHJoaGlyBF9TAzk3NDc2NTkwBGdycElkAzQ2NDE0MgRncnBzcElkAzE3MDUwMDcxODMEc2VjA2Z0cgRzbGsDZ2ZwBHN0aW1lAzE1Nzg1OTA3MzE->
• Privacy
<https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe
<mailto:[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>
.
__,_._,___
--
Jim Starkey
Firebird-Devel mailing list, web interface at
https://lists.sourceforge.net/lists/listinfo/firebird-devel