Alex Gaynor 2/26/2017

SHA1 and Richard Feynman

Read Original

The article draws a parallel between Richard Feynman's critique of NASA's misunderstanding of engineering 'safety factors' after the Challenger disaster and the misunderstanding of cryptographic breaks like SHA1. It argues that a practical collision attack means the algorithm is fundamentally broken for cryptographic purposes, emphasizing that security is hard and 'compromise-free' choices should be used when available. It uses TLS handshake signatures as a concrete example of lingering weak hash usage.

SHA1 and Richard Feynman

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week