1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Google "Shattered" SHA-1 Encryption- Its officially dead

Discussion in 'BlackHat Lounge' started by Skyebug77, Feb 23, 2017.

  1. Skyebug77

    Skyebug77 Jr. VIP Jr. VIP

    Joined:
    Mar 22, 2012
    Messages:
    2,105
    Likes Received:
    1,501
    Occupation:
    Marketing
    Location:
    Portland,Or
  2. nikchaing

    nikchaing Jr. VIP Jr. VIP UnGagged Attendee

    Joined:
    Apr 24, 2013
    Messages:
    1,114
    Likes Received:
    2,191
    Location:
    Florida
    lol the clock is ticking for a bunch of companies
     
    • Thanks Thanks x 1
  3. moonshine7000

    moonshine7000 Senior Member

    Joined:
    Mar 4, 2013
    Messages:
    1,105
    Likes Received:
    457
    Occupation:
    A+ IT technician,Clickbank and Amazon Marketer
    The end the world looks near.
     
  4. AustinNash5

    AustinNash5 Jr. VIP Jr. VIP

    Joined:
    Jun 9, 2016
    Messages:
    526
    Likes Received:
    117
    Gender:
    Male
    Couldn't have said it better
     
  5. tb303

    tb303 Senior Member

    Joined:
    Dec 18, 2011
    Messages:
    801
    Likes Received:
    480
    About time. sha1 should have been dead years ago. It says in that article it take $110k of AWS to run the attack (currently) so its not gone the way of md5 just yet.
     
    Last edited: Feb 23, 2017
  6. Capo Dei Capi

    Capo Dei Capi BANNED BANNED

    Joined:
    Oct 23, 2014
    Messages:
    754
    Likes Received:
    9,454
    From what I was looking at places I can't talk about here, I think the GTX 1080 may cut down the time for single GPU years to 34 from 110. So it may already be at a level where criminal groups can crack it affordably.


    Using Amazon may be a bad measure of how outdated SHA-1 could be, they should be estimating what the cost would be to acquire a massive cluster for SHA-1 attacks if the group was buying a mixed of used and new parts to keep prices as low as possible.
     
    • Thanks Thanks x 3
    Last edited: Feb 23, 2017
  7. Ste Fishkin

    Ste Fishkin BANNED BANNED Jr. VIP

    Joined:
    May 14, 2011
    Messages:
    2,058
    Likes Received:
    10,212
    Google have a team working on the assumption that quantum computing will be possible within the next 5 years.

    Once this happens, passwords and all forms of encryption are gone.

    What took years will take seconds[​IMG]
     
    • Thanks Thanks x 4
  8. bartosimpsonio

    bartosimpsonio Jr. VIP Jr. VIP Premium Member

    Joined:
    Mar 21, 2013
    Messages:
    12,660
    Likes Received:
    11,325
    Occupation:
    CHEAP
    Location:
    DATASETS
    Home Page:
    Should I freak out?