http://www.zdnet.com/article/as-sha1-winds-down-sha2-leap-will-leave-millions-stranded/?tag=nl.e540&s_cid=e540&ttag=e540&ftag=TRE5369823


As sites move to SHA2 encryption, millions face HTTPS lock-out

"We're about to leave a whole chunk of the internet in the past," as
millions of people remain dependent on old, insecure, but widely-used
encryption.



By Zack Whittaker <http://www.zdnet.com/meet-the-team/us/zack-whittaker/>
for Zero Day <http://www.zdnet.com/blog/security/> | October 23, 2015 --
17:26 GMT (10:26 PDT) |

SHA1 certificates will no longer be issued from 2016. (Image: ZDNet/CBS
Interactive)

In 2016, tens of millions of people around the world will face trouble
accessing some of the most common encrypted websites like Facebook, Google
and Gmail, Twitter, and Microsoft sites.

Why? Because their browser or device will be unable to read the new, more
secure certificates.

SHA1, the cryptographic hashing algorithm that's been at the heart of the
web's security for a decade, will be retired in a little over a year. Some
say it could be cracked
<http://arstechnica.com/security/2015/10/sha1-crypto-algorithm-securing-internet-could-break-by-years-end/>
by the end of the year, essentially making it useless and weakening security
<http://www.zdnet.com/article/just-how-many-websites-are-vulnerable-because-of-sha-1/>
for millions of users.

Certificate authorities said they will respond by no longer issuing SHA1
certificates at midnight, January 1 2016, opting instead for SHA2
certificates. SHA2 is a significantly stronger algorithm that will last for
many years to come. But there's a problem. A small but sizable portion of
the internet's users don't have browsers or devices that are compatible
with SHA2.

"We're about to leave a whole chunk of the internet in the past," said
CloudFlare chief executive Matthew Prince, during a conversation in our New
York newsroom earlier this month.
'One million websites' running risky crypto

Encryption isn't important just for protecting your online banking, email
accounts, and social networks. That green lit-up bar or padlock in your
browser also verifies the integrity of a site, offering a strong level of
assurance that the page has not been modified in any way.

More sites nowadays are adopting encryption because it costs little to
nothing to implement.

In an age of daily data breaches, hacks, and mass surveillance, adopting
strong SHA2 encryption is more important than ever. But browser makers and
website owners alike thought they had more time.

Prominent security researchers thought SHA1 would last until about 2018
<http://arstechnica.com/security/2012/10/sha1-crypto-algorithm-could-fall-by-2018/>,
but now they think SHA1 encryption may be broken by the end of 2015
<http://arstechnica.com/security/2015/10/sha1-crypto-algorithm-securing-internet-could-break-by-years-end/>
.

[image: Description:
http://zdnet4.cbsistatic.com/hub/i/2015/10/23/69604480-ebdd-45ad-99c1-970b81ebd088/sha256-2-jpg.jpg]

The good news is that most website are already using the stronger SHA2
certificates. About 24 percent
<https://www.trustworthyinternet.org/ssl-pulse/> of SSL-encrypted websites
still use SHA1 -- or, about 1 million websites
<http://www.zdnet.com/article/just-how-many-websites-are-vulnerable-because-of-sha-1/>
.

That figure is declining every month, so much so that by the end of the
year it could fall as low as 10 percent of all websites, meaning the vast
majority of encrypted websites will be safe from SHA1 collision attacks.

For most people, there's nothing to worry about. The majority are already
using the latest Chrome or Firefox browser, the latest operating system, or
the newest smartphone with the latest software, which are compatible with
the old SHA1-hashed websites and the newer SHA2-hashed websites.

But many, particularly those in developing nations, who are running older
software, devices, and even "dumbphones," the candy-bar cellphones that
have basic mobile internet, will face a brick wall, because their devices
aren't up-to-date enough to even know what SHA2 is.
Mozilla's 'one million downloads' mistake

There's no way to tell exactly how many will be affected until it happens,
in part because there are no concrete figures on how many people are
running old or unsupported browsers or devices.

Ivan Ristic, head of of SSL Labs at Qualys, said in an email that users of
Windows XP SP2 and earlier, and Android 2.2 and earlier, do not support
SHA2 certificates.
*HTTPS*

[image: Description: Sites that don't offer HTTPS encryption are running
out of excuses]
<http://www.zdnet.com/article/most-sites-are-not-secure-and-why-we-are-all-doomed/>

Sites that don't offer HTTPS encryption are running out of excuses
<http://www.zdnet.com/article/most-sites-are-not-secure-and-why-we-are-all-doomed/>

The barriers that once stood in the way of a fully secure web don't exist
anymore.

There are no stable or steady figures to reference. From what's available,
usage of unsupported systems remains low worldwide, but still has
double-digit percentages in China
<http://gs.statcounter.com/#desktop-os-CN-monthly-201409-201509>, Africa
<http://gs.statcounter.com/#desktop-os-af-monthly-201409-201509>, India
<http://gs.statcounter.com/#desktop-os-IN-monthly-201409-201509>, and other
developing nations like Vietnam, accounting for tens of millions of users.
Even if Microsoft's usage share sites <https://dev.modern.ie/ie6countdown/>
is to be believed, that 1 percent of the world still uses an unsupported
browser, there could be as many as 70 million that face being locked out of
SHA2 encrypted sites.

"Given that many sites are 75 percent through to SHA2 migration, it's
likely that those users with old browsers will start to experience problems
with increased frequency throughout 2016," said Ristic.

Mozilla found out the hard way last year. Last year, the browser maker
updated its website with a new SHA2-hashed SSL certificate. But those who
were running a browser or operating system that didn't support SHA2
couldn't get onto the website.

The upgrade "killed one million downloads," said Mozilla's Chris More in a
bug listing <https://bugzilla.mozilla.org/show_bug.cgi?id=1064387#c6> at
the time. "A lot of the world is still running old browsers and come to our
website to get Firefox," he said.

And it won't be the last time it happens.
'Untrusted connection'

With SHA1 no longer available from 2016, website owners and app makers have
a whole year to upgrade to SHA2.

A year later, starting in 2017, Chrome
<https://googleonlinesecurity.blogspot.com/2014/09/gradually-sunsetting-sha-1.html>
and Firefox
<https://blog.mozilla.org/security/2015/10/20/continuing-to-phase-out-sha-1-certificates/>
browsers that encounter an old SHA1 certificate will throw a security
warning, telling the user that the connection is untrusted. In some cases,
like Firefox, users may get warnings during 2016.

Mozilla said it may push the date back to July 2016 if attacks on SHA1 are
successful
<https://blog.mozilla.org/security/2015/10/20/continuing-to-phase-out-sha-1-certificates/>.


Website encryption is becoming more ubiquitous as security becomes more of
a focal issue. But it's not always as simple as upgrading to a new browser.
In many cases it involves upgrading hardware, like phones and computers,
which many can't afford or can't get because of trade restrictions.

"We're trying to get everyone to upgrade to the latest security and that's
good, but in order to do that we have to support the past," said Prince.

With potentially only a few days or weeks
<http://arstechnica.com/security/2015/10/sha1-crypto-algorithm-securing-internet-could-break-by-years-end/>
before SHA1 is cracked, and sites and services can be impersonated, there
has not been a bigger need to upgrade to better cryptography in years.

Prince said the industry wanted the "best and greatest security, but in the
process we broke everything," he said.

"It's the best of intentions backfiring," he said. "And it scares the s**t
out of me."




__._,_.___
------------------------------
Posted by: "Beowulf" <[email protected]>
------------------------------


Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmbXUyaGZ0BF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0NDU2MjMwMTQ->


[image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlNmtvM2VzBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQ0NTYyMzAxNA-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to