Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Deprecation of old stuff is going incredibly slowly even in rich countries (to the intense frustration of a lot of security teams). Check out the incredible true story, told over years on cabfpub, of the attempt to get rid of SHA-1 in TLS authentication. Notably, the attacks that led to experts' recommendation to move away from SHA-1 immediately were published back in 2005. Meanwhile, Microsoft's "effective date of the SHA-1 deprecation" is tomorrow (!), February 14, 2017.

https://social.technet.microsoft.com/wiki/contents/articles/...

(Let's have a party!)

Figuring out how people are going to get upgraded when problems of some sort are discovered (including software vulnerabilities, not just cryptographic protocol issues) is a major security challenge of our day, maybe the biggest information security problem overall in the world.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: