SHA1 and Richard Feynman
Read OriginalThe article draws a parallel between Richard Feynman's critique of NASA's misunderstanding of engineering 'safety factors' after the Challenger disaster and the misunderstanding of cryptographic breaks like SHA1. It argues that a practical collision attack means the algorithm is fundamentally broken for cryptographic purposes, emphasizing that security is hard and 'compromise-free' choices should be used when available. It uses TLS handshake signatures as a concrete example of lingering weak hash usage.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser