{"id":17619,"date":"2020-05-30T14:12:00","date_gmt":"2020-05-30T14:12:00","guid":{"rendered":"https:\/\/icrowdnewswire.com\/?p=2575286"},"modified":"2020-05-30T14:12:00","modified_gmt":"2020-05-30T14:12:00","slug":"a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak","status":"publish","type":"post","link":"https:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/","title":{"rendered":"A popular encryption algorithm is being killed because it is too weak"},"content":{"rendered":"<p><strong>OpenSSH and Libssh have abandoned SHA-1 over growing security concerns<\/strong><\/p>\n<p>The developers of two open source code libraries for Secure Shell, which is the protocol used by millions of computers to create encrypted connections, have decided to no longer support the Secure Hash Algorithm 1 (<a class=\"hawk-link-parsed\" href=\"https:\/\/www.techradar.com\/news\/wishbone-hack-data-of-40-million-users-up-for-sale\" data-component-tracked=\"1\" data-dimension73=\"7766318873046567000\">SHA-1<\/a>) due to growing security concerns.<\/p>\n<p>As reported by&nbsp;<a class=\"hawk-link-parsed\" href=\"https:\/\/arstechnica.com\/information-technology\/2020\/05\/dangerous-sha-1-crypto-function-is-about-to-die-in-ssh\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-original-href=\"https:\/\/arstechnica.com\/information-technology\/2020\/05\/dangerous-sha-1-crypto-function-is-about-to-die-in-ssh\/\" data-component-tracked=\"1\"><em>Ars Technica<\/em><\/a>, developers using the OpenSSH and Libssh libraries will no longer be able to use SHA-1 to digitally sign encryption keys going forward. In its&nbsp;<a class=\"hawk-link-parsed\" href=\"https:\/\/www.openssh.com\/releasenotes.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-original-href=\"https:\/\/www.openssh.com\/releasenotes.html\" data-component-tracked=\"1\">release notes<\/a>, OpenSSH explained why it will no longer support SHA-1, saying:<\/p>\n<aside class=\"hawk-widget\" data-render-type=\"fte\" data-skip=\"dealsy\" data-widget-type=\"seasonal\" data-widget-id=\"3547542561318982000\" data-result=\"missing\"><\/aside>\n<p>&ldquo;It is now possible to perform chosen-prefix attacks against the SHA-1 algorithm for less than USD$50K. For this reason, we will be disabling the &#8220;ssh-rsa&#8221; public key signature algorithm by default in a near-future release. This algorithm is unfortunately still used widely despite the existence of better alternatives, being the only remaining public key signature algorithm specified by the original SSH RFCs.&rdquo;<\/p>\n<p>SHA-1 is a cryptographic hash function that was first developed in 1995. It is used for producing hash &ldquo;digests&rdquo; which are each 40 hexadecimal characters long and these digests are meant to be distinct for every message, file and function that uses them.<\/p>\n<h2 id=\"hash-collisions\">Hash collisions<\/h2>\n<p>A collision is a cryptographic term used to describe when two or more inputs generate the same outputted digest and researchers began warning that SHA-1 was becoming increasingly vulnerable to collisions almost a decade ago.&nbsp;<\/p>\n<p>In 2017, SHA-1 fell victim to a collision attack that cost $110,000 to produce which lead to a number of browsers, browser-trusted certificate authorities and software update systems to abandon the algorithm though some services and software continued using it despite the risk.<\/p>\n<p>However, in January of this year, researchers showed that an even more powerful collision attack could be launched for just $45,000. This chosen-prefix attack showed that it is possible to modify an existing input and still end up with the same SHA-1 hash and an attacker could use this method to alter documents or software to bypass SHA-1-based integrity checks.<\/p>\n<p>While OpenSSH and Libssh will no longer support SHA-1, the encryption algorithm is still supported in recent versions of&nbsp;<a class=\"hawk-link-parsed\" href=\"https:\/\/www.techradar.com\/news\/software\/security-software\/post-heartbleed-is-it-time-to-consider-an-alternative-to-openssl-1246986\" data-component-tracked=\"1\" data-dimension73=\"7998353875926018000\">OpenSSL<\/a>.<\/p>\n<p class=\"tags\">\n<div><strong>See Campaign: <\/strong><a href=\"http:\/\/http:\/\/www.techradar.com\/news\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\" target=\"_blank\">http:\/\/http:\/\/www.techradar.com\/news\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak<\/a><br \/><b>Contact Information:<\/b><br \/>Anthony Spadafora<\/p>\n<p><b>Tags:<\/b><br \/><a href=\"\"><\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/wire\/\" rel=\"category tag\">Wire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/global-regions\/united-states\/\" rel=\"category tag\">United States<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/language\/english\/\" rel=\"category tag\">English<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" alt=\"image\" width=\"400\" height=\"300\" class=\"cwdfimg\" \/><\/div>\n<div>\n<h3>Contact Information:<\/h3>\n<p>Anthony Spadafora<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>OpenSSH and Libssh have abandoned SHA-1 over growing security concerns The developers of two open source code libraries for Secure Shell, which is the protocol used by millions of computers to create encrypted connections, have decided to no longer support the Secure Hash Algorithm 1 (SHA-1) due to growing security concerns. As reported by&nbsp;Ars Technica, &hellip; <a href=\"https:\/\/icrowdnewswire.com\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\">Continue reading <span>A popular encryption algorithm is being killed because it is too weak<\/span><\/a> <a href=\"https:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\" class=\"more-link\">Continue Reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":106,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,22,54],"tags":[],"class_list":["post-17619","post","type-post","status-publish","format-standard","hentry","category-english","category-united-states","category-wire"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A popular encryption algorithm is being killed because it is too weak - Business<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A popular encryption algorithm is being killed because it is too weak - Business\" \/>\n<meta property=\"og:description\" content=\"OpenSSH and Libssh have abandoned SHA-1 over growing security concerns The developers of two open source code libraries for Secure Shell, which is the protocol used by millions of computers to create encrypted connections, have decided to no longer support the Secure Hash Algorithm 1 (SHA-1) due to growing security concerns. As reported by&nbsp;Ars Technica, &hellip; Continue reading A popular encryption algorithm is being killed because it is too weak Continue Reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\" \/>\n<meta property=\"og:site_name\" content=\"Business\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-30T14:12:00+00:00\" \/>\n<meta name=\"author\" content=\"Waqas Awan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Waqas Awan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\",\"url\":\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\",\"name\":\"A popular encryption algorithm is being killed because it is too weak - Business\",\"isPartOf\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#website\"},\"datePublished\":\"2020-05-30T14:12:00+00:00\",\"author\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/46e7a3c31ebaa3d111acaa0daf39976f\"},\"breadcrumb\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ipsnews.net\/business\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A popular encryption algorithm is being killed because it is too weak\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ipsnews.net\/business\/#website\",\"url\":\"https:\/\/ipsnews.net\/business\/\",\"name\":\"Business\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ipsnews.net\/business\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/46e7a3c31ebaa3d111acaa0daf39976f\",\"name\":\"Waqas Awan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3453ff882f8bf8f7e605d09dc0750c5759cb895a2d09c18a38d07b424e7f6a29?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3453ff882f8bf8f7e605d09dc0750c5759cb895a2d09c18a38d07b424e7f6a29?s=96&d=mm&r=g\",\"caption\":\"Waqas Awan\"},\"sameAs\":[\"https:\/\/icrowdnewswire.com\/fc\"],\"url\":\"https:\/\/ipsnews.net\/business\/author\/waqas-awan\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A popular encryption algorithm is being killed because it is too weak - Business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/","og_locale":"en_US","og_type":"article","og_title":"A popular encryption algorithm is being killed because it is too weak - Business","og_description":"OpenSSH and Libssh have abandoned SHA-1 over growing security concerns The developers of two open source code libraries for Secure Shell, which is the protocol used by millions of computers to create encrypted connections, have decided to no longer support the Secure Hash Algorithm 1 (SHA-1) due to growing security concerns. As reported by&nbsp;Ars Technica, &hellip; Continue reading A popular encryption algorithm is being killed because it is too weak Continue Reading &rarr;","og_url":"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/","og_site_name":"Business","article_published_time":"2020-05-30T14:12:00+00:00","author":"Waqas Awan","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Waqas Awan","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/","url":"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/","name":"A popular encryption algorithm is being killed because it is too weak - Business","isPartOf":{"@id":"https:\/\/ipsnews.net\/business\/#website"},"datePublished":"2020-05-30T14:12:00+00:00","author":{"@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/46e7a3c31ebaa3d111acaa0daf39976f"},"breadcrumb":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/30\/a-popular-encryption-algorithm-is-being-killed-because-it-is-too-weak\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ipsnews.net\/business\/"},{"@type":"ListItem","position":2,"name":"A popular encryption algorithm is being killed because it is too weak"}]},{"@type":"WebSite","@id":"https:\/\/ipsnews.net\/business\/#website","url":"https:\/\/ipsnews.net\/business\/","name":"Business","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ipsnews.net\/business\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/46e7a3c31ebaa3d111acaa0daf39976f","name":"Waqas Awan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3453ff882f8bf8f7e605d09dc0750c5759cb895a2d09c18a38d07b424e7f6a29?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3453ff882f8bf8f7e605d09dc0750c5759cb895a2d09c18a38d07b424e7f6a29?s=96&d=mm&r=g","caption":"Waqas Awan"},"sameAs":["https:\/\/icrowdnewswire.com\/fc"],"url":"https:\/\/ipsnews.net\/business\/author\/waqas-awan\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/17619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/users\/106"}],"replies":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/comments?post=17619"}],"version-history":[{"count":1,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/17619\/revisions"}],"predecessor-version":[{"id":17620,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/17619\/revisions\/17620"}],"wp:attachment":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/media?parent=17619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/categories?post=17619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/tags?post=17619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}