Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Tauber îl vrea pe Șor premier și nu neagă că ar candida la Președinție

January 27, 2023

Urmărirea penală în privința lui Andronachi și a unui complice, la final

January 26, 2023

SEAL Team Six kills key ISIS facilitator Bilal al-Sudani, 10 operatives in counterterrorism mission in Somalia

January 26, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Friday, January 27
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Tauber îl vrea pe Șor premier și nu neagă că ar candida la Președinție
  • Urmărirea penală în privința lui Andronachi și a unui complice, la final
  • SEAL Team Six kills key ISIS facilitator Bilal al-Sudani, 10 operatives in counterterrorism mission in Somalia
  • Victor Nichituș: Guvernul stă cu mâna întinsă către structurile europene
  • Jeremy Hunt warns economic ‘discipline’ needed to get inflation under control
  • Va candida la funcția de bașcan al Găgăuziei? Răspunsul lui Stoianoglo
  • Tăbîrță, despre integrarea UE: Moldova nu a avut evoluții democratice
  • Munteanu l-a criticat pe Nosatîi pentru poziția privind chestiunea NATO
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » NIST Retires SHA-1 Cryptographic Algorithm

NIST Retires SHA-1 Cryptographic Algorithm

December 17, 20223 Mins Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

The SHA-1 algorithm, one of the first widely used methods of protecting electronic information, has reached the end of its useful life, according to security experts at the National Institute of Standards and Technology (NIST). The agency is now recommending that IT professionals replace SHA-1, in the limited situations where it is still used, with newer algorithms that are more secure.

SHA-1, whose initials stand for “secure hash algorithm,” has been in use since 1995 as part of the Federal Information Processing Standard (FIPS) 180-1. It is a slightly modified version of SHA, the first hash function the federal government standardized for widespread use in 1993. As today’s increasingly powerful computers are able to attack the algorithm, NIST is announcing that SHA-1 should be phased out by Dec. 31, 2030, in favor of the more secure SHA-2 and SHA-3 groups of algorithms.

“We recommend that anyone relying on SHA-1 for security migrate to SHA-2 or SHA-3 as soon as possible,” said NIST computer scientist Chris Celi.

SHA-1 has served as a building block for many security applications, such as validating websites — so that when you load a webpage, you can trust that its purported source is genuine. It secures information by performing a complex math operation on the characters of a message, producing a short string of characters called a hash. It is impossible to reconstruct the original message from the hash alone, but knowing the hash provides an easy way for a recipient to check whether the original message has been compromised, as even a slight change to the message alters the resulting hash dramatically.

Today’s more powerful computers can create fraudulent messages that result in the same hash as the original, potentially compromising the authentic message. These “collision” attacks have been used to undermine SHA-1 in recent years. NIST has announced previously that federal agencies should stop using SHA-1 in situations where collision attacks are a critical threat, such as for the creation of digital signatures.

As attacks on SHA-1 in other applications have become increasingly severe, NIST will stop using SHA-1 in its last remaining specified protocols by Dec. 31, 2030. By that date, NIST plans to:

  • Publish FIPS 180-5 (a revision of FIPS 180) to remove the SHA-1 specification.
  • Revise SP 800-131A and other affected NIST publications to reflect the planned withdrawal of SHA-1.
  • Create and publish a transition strategy for validating cryptographic modules and algorithms.

The last item refers to NIST’s Cryptographic Module Validation Program (CMVP), which assesses whether modules — the building blocks that form a functional encryption system — work effectively. All cryptographic modules used in federal encryption must be validated every five years, so SHA-1’s status change will affect companies that develop modules.

“Modules that still use SHA-1 after 2030 will not be permitted for purchase by the federal government,” Celi said. “Companies have eight years to submit updated modules that no longer use SHA-1. Because there is often a backlog of submissions before a deadline, we recommend that developers submit their updated modules well in advance, so that CMVP has time to respond.”

Questions about the transition can be sent to [email protected] More information is available at the NIST Computer Security Resource Center transition page.

Read more at NIST

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

U.K. Warns of Targeted Phishing Attacks from Russia and Iran

January 26, 2023 Cybersecurity

FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony’s Horizon Bridge Currency Theft

January 25, 2023 Cybersecurity

CISA Releases Report for K-12 Schools to Help Address Evolving Cybersecurity Threats

January 24, 2023 Cybersecurity

Vulnerabilities in TP-Link routers, WR710N-V1-151022 and Archer C5 V2

January 24, 2023 Cybersecurity

Arrests Across Europe and U.S. in Bitzlato Crackdown

January 24, 2023 Cybersecurity

GAO Highlights Urgent Federal Cybersecurity Issues

January 23, 2023 Cybersecurity
Don't Miss
Moldova

Urmărirea penală în privința lui Andronachi și a unui complice, la final

By woe whJanuary 26, 20230

Procuratura Anticorupție anunță că în data de 25 ianuarie 2023 a finalizat urmărirea penală disjunsă…

SEAL Team Six kills key ISIS facilitator Bilal al-Sudani, 10 operatives in counterterrorism mission in Somalia

January 26, 2023

Victor Nichituș: Guvernul stă cu mâna întinsă către structurile europene

January 26, 2023

Jeremy Hunt warns economic ‘discipline’ needed to get inflation under control

January 26, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Tăbîrță, despre integrarea UE: Moldova nu a avut evoluții democratice

January 26, 2023

Munteanu l-a criticat pe Nosatîi pentru poziția privind chestiunea NATO

January 26, 2023

Boris Johnson reveals how big is advance was for forthcoming memoir

January 26, 2023

Rod Stewart joins Sky News phone-in on NHS crisis to call for Tories to quit

January 26, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.