Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Google to Sunset SHA-1 Crypto Hash Algorithm

Google has announced plans to begin sunsetting the SHA-1 cryptographic hash algorithm in the upcoming version of its Chrome browser.

Google has announced plans to begin sunsetting the SHA-1 cryptographic hash algorithm in the upcoming version of its Chrome browser.

In Chrome 39, which is slated to come in November, HTTPS sites whose certificates use SHA-1 and are valid past January 1, 2017, will no longer appear to be fully trustworthy in Chrome’s user interface.

“The SHA-1 cryptographic hash algorithm has been known to be considerably weaker than it was designed to be since at least 2005 — 9 years ago,” blogged Google’s Chris Palmer and Ryan Sleevi. “Collision attacks against SHA-1 are too affordable for us to consider it safe for the public web PKI. We can only expect that attacks will get cheaper.”

The use SHA-1 has been deprecated since 2011, when the CA/Browser Forum published their Baseline Requirements for SSL, Palmer and Sleevi noted. The requirements recommended that all CAs [certificate authorities] move away from SHA-1 as soon as possible.

Advertisement. Scroll to continue reading.

“We have seen this type of weakness turn into a practical attack before, with the MD5 hash algorithm,” the two explained. “We need to ensure that by the time an attack against SHA-1 is demonstrated publicly, the web has already moved away from it. Unfortunately, this can be quite challenging. For example, when Chrome disabled MD5, a number of enterprises, schools, and small businesses were affected when their proxy software — from leading vendors — continued to use the insecure algorithms, and were left scrambling for updates. Users who used personal firewall software were also affected.”

“We plan to surface, in the HTTPS security indicator in Chrome, the fact that SHA-1 does not meet its design guarantee,” they wrote. “We are taking a measured approach, gradually ratcheting down the security indicator and gradually moving the timetable up.”

In Chrome 40, sites with end-entity certificates that expire between June 1, 2016, and Dec. 31, 2016, and include a SHA-1-based signature as part of the certificate chain will be treated as “secure, but with minor errors.” Sites with end-entity certificates that expire on or after Jan. 1, 2017, and include a SHA-1-based signature as part of the certificate chain will be considered “neutral, lacking security.”

The current visual display for “neutral, lacking security” is a blank page icon, and is used in other situations, such as HTTP, the two stated.

In Chrome 41, sites with end-entity certificates that expire between the start of 2016 and Dec. 31, 2016, that include a SHA-1-based signature as part of the certificate chain will be treated as “secure, but with minor errors.” Sites with end-entity certificates that expire on or after Jan. 1, 2017, and include a SHA-1-based signature as part of the certificate chain meanwhile will be treated as “affirmatively insecure.” Subresources from such domain will be treated as “active mixed content,” according to Google.

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

UK cybersecurity agency NCSC announced Richard Horne as its new CEO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.