You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SHA-1 is unsuitable for signatures over data. The first
collision was published in 2017, and attacks have advanced since
to the point that chosen-prefix attacks are feasible now.
Signatures using SHA-1 in signed messages and detached signatures
must be rejected.
The case is less clear for self-signatures in OpenPGP
certificates, because we discovered that use in certificates is
still wide-spread. Please follow the discussion on openpgp@:
SHA-1 is unsuitable for signatures over data. The first
collision was published in 2017, and attacks have advanced since
to the point that chosen-prefix attacks are feasible now.
Signatures using SHA-1 in signed messages and detached signatures
must be rejected.
Relevant test: https://tests.sequoia-pgp.org/#Signature_over_the_shattered_collision
The case is less clear for self-signatures in OpenPGP
certificates, because we discovered that use in certificates is
still wide-spread. Please follow the discussion on openpgp@:
https://mailarchive.ietf.org/arch/msg/openpgp/Rp-inhYKT8A9H5E34iLTrc9I0gc/
Reproducer
Use this certificate:
To verify this signature:
Over these two files:
The signature authenticates both files even though they are
different.
The text was updated successfully, but these errors were encountered: