Google Just Achieved First-Ever Successful SHA-1 Collision Attack
Get link
Facebook
X
Pinterest
Email
Other Apps
Google just managed to broke SHA-1 Encryption. Google managed to alter a PDF without changing its SHA-1 hash value. This type of collision might force people into believing that the modified document was the original one.
Google Just Achieved First-Ever Successful SHA-1 Collision Attack
It took two years of hard work and research for the researchers and Google to broke SHA-1 encryption. Let me tell you about SHA-1 encryption. SHA stands for Secure Hash Algorithm. It is a cryptographic hash function which was designed by the United States National Security Agency (NSA), and this algorithm was first published in 1995.
Well, SHA-1 encryption is used for HTTPS certificates which are right now used for protecting your browsing history and in Git repositories. SHA-1 encryption is used to prove that the data, whether it’s an email, passwords, PDF’s or any other credentials have not been interfered by the hacker of any kind.
Now, the most horrific thing is Google has just managed to turn all these facts wrong by creating a hash collision. Google managed to alter a PDF without changing its SHA-1 hash value. This type of collision might force people into believing that the modified document was the original one.
Google on its security blog wrote “Today, 10 years after of SHA-1 was first introduced, we are announcing the first practical technique for generating a collision. This represents the culmination of two years of research that sprung from a collaboration between the CWI Institute in Amsterdam and Google.”
The entire effort was just to show tech community that SHA-1 encryption is now no more secure. Although Google always had depreciated SHA-1 for many years, especially when it comes to signing TLS certificates. Even, Google Chrome has been slowly phasing out the use of SHA-1 since 2014.
Google security blog wrote “We hope our practical attack on SHA-1 will cement that the protocol should no longer be considered secure” and recommended the industry to move to the safer alternative like SHA-256.
Image Source: Google
Well, now you all might be thinking how Google demonstrated the first ever SHA-1 Hash collision? Google had created two different PDF files that feature the same SHA1 hash and then used its cloud infrastructure to a computer the collision. Let me tell you Google had computed the collision which is one of the largest computations ever completed.
According to Google Security Blog, here are some numbers that give a sense of how large scale this computation was:
Nine quintillion (9,223,372,036,854,775,808) SHA1 computations in total
6,500 years of CPU computation to complete the attack first phase
110 years of GPU computation to complete the second phase
Image Source: Google
Google had even mentioned that they would be disclosing the code after 90 days “Following Google’s vulnerability disclosure policy, we will wait 90 days before releasing code that allows anyone to create a pair of PDFs that hash to the same SHA-1 sum given two distinct images with some pre-conditions. In order to prevent this attack from active use, we’ve added protections for Gmail and GSuite users that detects our PDF collision technique.”
Google has created a website to showcase the full attack. You can read the research paper. So, what do you think about this? Share your views in the comment box below.
Netflix is an American company that was founded in 1997 by Reed Hastings and Marc Randolph. In an earlier time when only provide DVD rental services across the USA. It is now one of the largest community to provide online streaming of movies and TV shows. On Netflix, you can watch your favorite movies and TV shows on demand. Just connect to the Internet on smartphones like iPhone, Android, tablets, smart TVs, computers, game consoles, etc. Since 2007 Netflix has expanded its services worldwide is now available in more than 190 countries such as Canada, Australia , United states, Japan and India. According to reports, the number of users increases Netflix twice after they began online streaming services. Now more than 69 million users are using Netflix premium accounts.We all know netflix premium account cookies tricks are not working these days. Netflix gives free one month trial for new users. But you’ll need to provide your credit card information. You can cancel your account at...
Free Netflix Account 2017 January Are you looking for free netflix premium account 2016 . Netflix is a community that provides various streaming media over the Internet. Netflix is one of the best streaming websites using Netflix, you can watch the newest online movies and TV shows. Netflix is an American company that was founded in 1997 by Reed Hastings and Marc Randolph . In an earlier time when only provide DVD rental services across the USA. It is now one of the largest community to provide online streaming of movies and TV shows. On Netflix, you can watch your favorite movies and TV shows on demand. Just connect to the Internet on smartphones like iPhone, Android, tablets, smart TVs, computers, game consoles, etc . Since 2007 Netflix has expanded its services worldwide is now available in more than 190 countries such as Canada, Australia , United states, Japan and India. Acc...
Terrarium TV Terrarium is an Android app which allows you to watch, stream and download FREE and HD TV Shows and movies on your Android devices. It provides almost any TV shows and movies. Absolutely free. You can download them on your Android device or watch online. Features FULL HD (1080p) and HD (720p) sources Absolutely FREE Download and watch offline Multi-language subtitles are available Fast sources (for Full HD and HD, mostly Google Drive) Great amount of TV shows and movies Bookmark Last watching Genre selection Chromecast support MOD Fashion : AD Free / No Update Pop-Up Screenshot Requirements Android 4.0.1 or upper version MXPlayer (Currently the most powerful video player on Android) Download Terrarium TV v1.4.10 (Premium) / Mirror
Comments
Post a Comment