Facebook to remove support for SHA-1 certificate signatures Oct. 1, will require SHA-2
Adam Gross / Facebook Developers :
Context & Ripple Effects
Facebook's June 2015 announcement set an October 1 deadline for killing SHA-1 certificate signatures, and the related coverage shows how that played out: by late 2015 Facebook itself was warning that the SHA1 sunset would block millions from the encrypted web, and ZDNet reported the SHA-2 transition would leave tens of millions of older-browser and legacy-device users unable to reach HTTPS sites at all.
The move matters because it made one of the largest traffic sources on the web a compliance gatekeeper: any site operator or CA chain still leaning on SHA-1 had to migrate or lose Facebook-driven visitors, and the episode became an early data point in the platform-forced crypto modernization wave that Facebook extended years later through API lockdowns and hardware security keys.
First-order effects
- Users on older browsers and devices lose HTTPS access to Facebook after October 1 unless they upgrade — the direct population affected, per Facebook's own warning and the ZDNet reporting.
- Site operators and certificate issuers still serving SHA-1 signatures must reissue certificates under SHA-2 or risk broken handshakes for traffic arriving from Facebook.
Second-order effects
- Certificate authorities face a surge of forced reissuance ahead of the deadline, accelerating SHA-1's deprecation industry-wide rather than waiting for browser vendors to act alone.
- Other high-traffic platforms come under pressure to match Facebook's cutoff, since holding SHA-1 support longer makes them the weak link attackers target.
Third-order effects
- If the pattern holds, large platforms become the effective enforcers of cryptographic standards — willing to lock out legacy devices to force encryption upgrades, trading universal access for security, as Facebook later did again by restricting APIs and pushing security keys.
The trend: Major consumer platforms are unilaterally forcing cryptographic modernization, accepting that each security mandate locks a slice of legacy-device users out of the encrypted web.