Skip to main content

Google will stamp down on SHA-1 security certificates in 2016

android lollipop problems at google hq
Image used with permission by copyright holder
Over the course of 2015, Google has been actively tightening up its standards in relation to security certificates — the cryptographic codes used to establish which connections can and cannot be trusted. Heading into next year, the company has announced further restrictions on the certificates supported by its Chrome browser.

Any website using a SHA-1-signed certificate issued after January 1, 2016, will be blocked as of an unspecified date in the early part of next year, according to a report from Tom’s Hardware. While the algorithm has been set for depreciation for some time, there’s been more impetus to do so in recent months.

Recommended Videos

A team comprising of Marc Stevens, Pierre Karpman, and Thomas Peyrin published research earlier this year that suggests a criminal entity could carry out an SHA-1 collision attack for around $100,000. With that kind of accessibility, Google and other organizations are thought to have sped up plans to discontinue support.

The Baseline Requirements for SSL have been updated to stipulate an end to any distribution of SHA-1 certificates in 2016, so it seems clear that the writing is on the wall for the algorithm. However, there seems to be little downside to Google being proactive in cleaning up any perceived threats to the quality of Internet access.

In recent months, Google has targeted security software firm Symantec, after doubt was cast over the way that the company was issuing its certificates. Earlier this month, Symantec made a request to Google that one of its legacy certificate be untrusted or removed.

At present, Firefox and Microsoft Edge are also expected to begin blocking SHA-1 certificates before the end of 2017. However, given that Google has chosen to accelerate the process, it wouldn’t be all that surprising to see others follow suit.

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Update Google Chrome now to protect yourself from an urgent security bug
Google Chrome app on s8 screen.

Google posted a security update for its Chrome browser that fixes what's known as a zero-day bug. The problem affects Chrome on Windows, Mac, and Android. The flaw can lead to arbitrary code execution, a serious security vulnerability, so it's best to download and install the latest version immediately. Zero-day bugs mean that this is a known weakness and, in this case, Google said that the flaw is already being exploited by hackers.

Google did not post a detailed explanation of how the exploit works, but will do so when the majority of people have updated, making the danger of further attacks less severe. The most severe bug is identified as CVE-2022-2294 and the update also patches CVE-2022-2295 and CVE-2022-2296.

Read more
The M1 has a major security loophole that Apple can’t patch
Apple M1 processor on a mainboard.

Researchers at MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) have discovered a new security vulnerability that targets Apple's popular M1 processor. The attack, dubbed PACMAN, is capable of bypassing the last line of defense against software bugs on the M1 and potentially other ARM-based processors.

PACMAN attacks pointer authentication, which is the final stop for most software vulnerabilities. Pointer authentication confirms that a program hasn't been changed in any malicious way, serving as a "safety net ... in the worst case scenario," as MIT PhD student Joseph Ravichandran put it. MIT's researchers developed PACMAN as a way to guess the pointer authentication signature, bypassing this critical security mechanism. Researchers say PACMAN exploits a hardware mechanism, so a software patch won't be able to fix it.

Read more
Microsoft Edge vs. Google Chrome: Performance, design, security, and more
Microsoft Edge browser on a computer screen.

Google Chrome remains the king of the web browsers, with around 60% share of the browser market as of December 2021. Microsoft's Edge browser, which uses the Chromium open-source engine, is in a lower spot around 12%, which is impressive with the browser having only been introduced in the last couple of years. Microsoft pushed the new Edge to all Windows 10 desktops, replacing the old Windows 10 version and giving Edge a built-in -- well -- edge. Edge is also the default browser for Windows 11.

Which browser should you use? The two share a lot of similarities, but some key differences make one the clear winner.
Design

Read more