Three Chinese scholars made an impact on the SHA-1 hash algorithm--the core of today's mainstream security products.Those top experts said the users still could trust the system and application based on them,but the next generation of the algorithms should be changed.
Wide use of SHA-1
SHA-1 is widely used in CA,it is the key technplogy of SSL. SSL is widely used in delivering secure information through internet,such as the number of credit cards.In addition,some chip manufacturer including Atmel、Infineon、National Semiconductor and STMicroelectronics use SHA-1 as the basis of TPMs to provide rliable hardware root for PC and other equipments.
Famous company's comments on the event
A production manager of Microsoft said:“This means that we should amend our products,but it is hard to say when we should do it. We needn't go on it now even if it is related to the next generation of OS”
While the CSO of Sun Microsystems Whitfield Diffie said that they had enough time to solve this problem.It is reported that Sun didn't use SHA-1 in their chips,but they probably provided hardsoftware which supports this algorithm.
NIST suggested recently that the researchers should shift to SHA-256 and SHA-512 before 2010.The security majordomo of Seagate Technology Mark Willet pointed out that NIST may probably need to bring forward the schedule.Paul Kocher said optimisticly that as long as we upgrade SHA-1,the serious threater would not occur. |