Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Security Infrastructure

Facebook Ready to Retire SHA-1

One year after saying that certificates using the SHA-1 hash algorithm should be kept alive in older browsers, Facebook is finally ready to retire the insecure cryptographic hash function and move to strong

One year after saying that certificates using the SHA-1 hash algorithm should be kept alive in older browsers, Facebook is finally ready to retire the insecure cryptographic hash function and move to stronger standards.

Last year, after security researchers revealed that collision attacks against SHA-1 are more practical and cheaper than previously believed, major browser companies announced plans to kill support for it as soon as possible. Facebook, however, was one of the large Internet companies to suggest that SHA-1 shouldn’t be retired altogether, and Twitter backed this proposal soon after.

Now, Wojciech Wojtyniak, a Production Engineer at Facebook, says that the social platform is ready to end support for SHA-1 certificates at the end of this year. The “well-documented security weaknesses for these older certificates” are the main reason for this, Wojtyniak notes.

Last year, Facebook claimed that killing SHA-1 in all major browsers would leave many unable to access their favorite websites. Many people, especially those in the poorest regions of the world, still use devices that are not capable of supporting TLS certificates beyond SHA-1, and the company suggested that killing SHA-1 certificates would have a great impact on these users.

“Fortunately, after an examination of our SHA-1 usage, we have determined that it is no longer necessary for us to maintain our remaining SHA-1 certificates. In fact, we have not been serving SHA-1 traffic since early November and there has been no measurable impact,” Wojtyniak said.

With Chrome, Firefox, and Microsoft Edge (and Internet Explorer 11) already en-route to sunset SHA-1 in the coming months, other large Internet players are making similar moves as well. Akamai recently said that it would end support for the algorithm on Dec 27, 2016.

“As a result, we are going to revoke our SHA-1 certificates. We look forward to the industry’s movement toward greater use of stronger certificates like SHA-256,” Wojtyniak concluded.

This industry-wide move, however, is expected to impact many, considering that around 35% websites were still using SHA-1 as of about a month ago (based on the analysis of over 11 million publicly visible IPv4 websites). This means that, as soon as browsers, providers, and Certificate Authorities move to SHA-2, access to these websites will be disrupted.

Advertisement. Scroll to continue reading.
Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Security Infrastructure

Security vendor consolidation is picking up steam with good reason. Everyone wants to improve security efficiency and effectiveness while paying for less.

Management & Strategy

Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.

Cloud Security

The term ‘zero trust’ is now used so much and so widely that it has almost lost its meaning.

Security Infrastructure

Instead of deploying new point products, CISOs should consider sourcing technologies from vendors that develop products designed to work together as part of a...

Security Infrastructure

Comcast jumps into the enterprise cybersecurity business, betting that its internal security tools and inventions can find traction in an expanding marketplace.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...

Security Infrastructure

XDR's fully loaded value to threat detection, investigation and response will only be realized when it is viewed as an architecture