Re: phasing out SHA1 for digest creation

Rainer Perske <[email protected]>
Newsgroups gmane.comp.encryption.gpg.devel
Organization Universität Münster
Message-ID <permail-20241205171344103ecc050007da30-perske@message-id.uni-muenster.de>

Bruce Walzer schrieb am 2024-12-05:
> What is the actual issue here?

Extremely simplified:

Attacker makes many good documents and many bad documents until he finds a collision.
See https://shattered.io
Attacker takes the good document and the bad document with the same hash.
Attacker asks victim to sign the good document.
Victim does so.
Attacker combines the signature with the bad document.
So the attacker can "prove" that the victim has signed the bad document.

Conclusion:
Do never use SHA-1 for new signatures.
Emit a warning for existing SHA-1 signatures.

Kind regards
-- 
Rainer Perske
Systemdienste + Leiter der Zertifizierungsstelle (UCAM)
-- 
Universität Münster
CIT - Center for Information Technology
Rainer Perske, Systemdienste
Röntgenstraße 7-13, Raum 006
48149 Münster
Tel.: +49 251 83-31582
E-Mail: [email protected]
Website: www.uni-muenster.de/IT

Universitätszertifizierungsstelle Münster (UCAM):
Tel.: +49 251 83-31590
E-Mail: [email protected]
WWW: www.uni-muenster.de/CA

YouTube: youtube.com/@uni_muenster
Instagram: instagram.com/uni_muenster
LinkedIn: linkedin.com/school/university-of-muenster
Facebook: facebook.com/unimuenster

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
smime.p7s (application/pkcs7-signature, 6.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.