Why Everyone Is Abandoning SHA-1 Encryption

The Secure Hash Algorithm (SHA) has been perhaps the most instrumental tool in the fight against hackers during the beginning of the 21st century. Its ability to encrypt data without an immense amount of effort while demanding an inordinate amount of hardware to break it has kept our accounts and data safe for the better part of a few decades. This is why it may come as a surprise that all the major browser developers appear to be unanimous in the idea that SHA-1 should be abandoned completely in favor of its bigger brother, SHA-2. Why is everyone suddenly determined to phase it out by 2017, and why couldn’t both of them coexist?

Hashing Explained

In order to understand SHA, we have to look into the process and purpose behind hashing as a practice. A hash is a string that represents a particular asset but doesn’t substitute it. In simpler terms, unlike most cryptographic algorithms, you can hash a sentence but you cannot “un-hash” it. The only way this is useful is if the destination server doesn’t necessarily need to know the content of the data. Instead, it only needs to compare the hash of your input with the hash inside its database and authenticate you when both of them match. This is why hashes are so useful when storing account passwords; the server doesn’t need to know your actual password to authenticate you into a site.

Why Is SHA-1 Being Abandoned Then?

sha1-hash

If hashes are so difficult to reconstruct into actual data, then why is it that everyone is in such a hurry to phase it out of existence? All of it has to do with hardware.

You see, a hash can be “hacked” if someone can stumble upon input that produces the hash that coincides with the value that a server has in storage. If your account password has the hash b27263b7466a56b1467822108f5487422d054bbb, a hacker only needs to find another piece of text (it doesn’t necessarily have to be your password) that could create that exact combination when it is hashed. It used to be extremely expensive to acquire the kind of hardware that could do this within a reasonable amount of time. In the year 2015, however, this could all be done with the help of a cluster of GPUs. As hardware becomes more powerful and cheaper, it will be so inexpensive to solve SHA-1 that even small-time hackers and enthusiasts could feasibly do this.

Meet SHA-2

sha1-switch

To do away with the problems that have plagued SHA-1, SHA-2 has been created as a family of cryptographic algorithms with the purpose of making life extraordinarily difficult for well-to-do hackers. Since browsers and hosts will stop using SHA-1 certificates, the cost of hacking an account through the above-mentioned method would be astronomical. SHA-2 uses a maximum of 512 bits in its output, giving it the space it needs to ensure that any attempt to decipher and reproduce the string would take an unreasonable amount of time. Of course, this algorithm will also be broken at some point in the future and will eventually be replaced by another one that can continue the fight.

For the foreseeable future, however, SHA-2 will remain the champion of the Internet.

How many more years do you think SHA-2 will remain in the ring? Are browser developers right in their decision to phase out its predecessor? Tell us your thoughts in a comment!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe