Personal tools
You are here: Home wikidblog SHA1 Broken
« August 2008 »
Mo Tu We Th Fr Sa Su
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Recent comments
Re:Security and Oil admin Apr 25, 2008
Re:Security and Oil Paul feet Apr 24, 2008
Re:100% open source admin Apr 22, 2008
Re:100% open source Adam Apr 22, 2008
Re:Capital Gains Tax Rates and Entrepreneurs Lance Oct 23, 2007
 

SHA1 Broken

According to a number of places, but primarily Bruce Schneier, SHA-1 has been broken by a team of researchers in China. It's not time to panic if you're using it, but it is time to start thinking about a replacement.

Schneier notes that hashing isn't very well understood. Encryption, he notes, is much better understood and therefore more secure. Unlike RSA's SecurID and other token-based two-factor authentication systems, WiKID uses asymmetric cryptography in our WiKID Strong Authentication System.

It seems as though researchers are improving their ability to break hashing systems. Scott Contini and Yiqun Lisa Yin published a paper on Fast Software-Based Attacks on SecurID.

While their research isn't a smoking gun, they make a solid case for not recycling your tokens, which is frequently done.

The URL to Trackback this entry is:
http://www.wikidsystems.com/WiKIDBlog/9/tbping
Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.