Breaking News

DJI Introduces Osmo Mobile 8 with Intelligent Subject Tracking Samsung Launches New P9 Express microSD Express Cards Cloud Streaming officially arrives on PlayStation Portal CORSAIR Launches Second-Generation RMx SHIFT PSUs with Updated Cables and 12V-2×6 GPU Support Zenmuse L3 Launches as DJI's First Long-Range, High-Accuracy Aerial LiDAR System

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Facebook Warns Over Expiring SHA-1 Algorithm

Facebook Warns Over Expiring SHA-1 Algorithm

Enterprise & IT Dec 11,2015 0

Web browsing will get much riskier when a key security algorithm known as SHA stops supported by web browsing programs during 2016, warns Facebook. Its replacement - SHA-2 - will not be compatible with older web browsers.

Facebook's data shows that 3-7% of browsers currently in use are not able to use the newer SHA-256 standard, meaning that tens of millions of people will not be able to securely use the Internet after December 31st. A disproportionate number of those people reside in developing countries, and the likely outcome in those counties will be a serious backslide in the deployment of HTTPS by governments, companies and NGOs that wish to reach their target populations.

"We don't think it's right to cut tens of millions of people off from the benefits of the encrypted internet," wrote Alex Stamos, Facebook's chief security officer in a blogpost.

Security firm Cloudflare has also issued warnings about the retirement of SHA-1 and drawn up a list of the nations where older browsers that cannot work with the new version are most prominent.

"Unfortunately, this list largely overlaps with lists of the poorest, most repressive, and most war-torn countries in the world," said Matthew Prince, co-founder of Cloudflare in a blogpost.

"In other words, after 31 December most of the encrypted web will be cut off from the most vulnerable populations of internet users who need encryption the most," he said.

Both Facebook and Cloudflare have called for changes to the way that web browsers handle SHA-1 once it is retired. The proposal would mean SHA-1 would still be used for those using a browser that cannot use the updated algorithm.

Facebook supports CloudFlare's proposal for a different approach. Namely, the CA/Browser Forum should create a new type of Legacy Verified certificate that should only be issued to organizations that have demonstrated they are offering SHA-256 certificates to modern browsers. Such verification can be automated or manual, and appropriate measures can be put in place to reduce the risk of a collision attack. Those protections could include requiring LV applicants to have already passed OV or EV verification, as well as technical best practices such as serial number randomization.



Tags: facebook
Previous Post
Microsoft Updates Band
Next Post
Microsoft Warns Xbox Live Certificate Keys Exposed

Related Posts

  • EU Privacy Watchdog Accused of Delaying Probe Procedures Against Facebook

  • Zuckerberg Says Remote Work is Here to Stay

  • Facebook to Launch New Shopping Feature Across Apps

  • EU Tech Chief Demands More From Facebook Regarding Business Practices

  • Facebook Buys GIPHY as Part of Instagram Team

  • Facebook Works With Telecoms on 2Africa Subsea Cable for Future Internet Connectivity

  • Facebook Reports Increased Number of Removals of Hate speech, Terrorism

  • Facebook Users Accept $550 Million Privacy Deal Over Facebook's “Tag Suggestions”

Latest News

DJI Introduces Osmo Mobile 8 with Intelligent Subject Tracking
Drones

DJI Introduces Osmo Mobile 8 with Intelligent Subject Tracking

Samsung Launches New P9 Express microSD Express Cards
Cameras

Samsung Launches New P9 Express microSD Express Cards

Cloud Streaming officially arrives on PlayStation Portal
Gaming

Cloud Streaming officially arrives on PlayStation Portal

CORSAIR Launches Second-Generation RMx SHIFT PSUs with Updated Cables and 12V-2×6 GPU Support
PC components

CORSAIR Launches Second-Generation RMx SHIFT PSUs with Updated Cables and 12V-2×6 GPU Support

Zenmuse L3 Launches as DJI's First Long-Range, High-Accuracy Aerial LiDAR System
Drones

Zenmuse L3 Launches as DJI's First Long-Range, High-Accuracy Aerial LiDAR System

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed