Google unveils “practical” SHA-1 collision using nine quintillion computations, releases two different PDFs with identical hashes, urges sunsetting of protocol
Cryptographic hash functions like SHA-1 are a cryptographer's swiss army knife. You'll find that hashes play a role …
Context & Ripple Effects
Two days after Google announced the first-ever SHA-1 collision, it followed up with what it calls a practical version: nine quintillion computations produced two genuinely different PDFs carrying the identical SHA-1 fingerprint, turning a theoretical weakness into a reproducible forgery. The company pairs the demo with an explicit call to sunset the protocol.
The timing matters because the industry had already been arguing about the exit costs: back in 2015, Facebook warned that a SHA-1 sunset would block millions of users from the encrypted web. Google's collision hands the pro-deprecation camp its decisive evidence.
First-order effects
- Any certificate authority, code-signing pipeline, or document-integrity system still relying on SHA-1 is now exposed to forged artifacts that pass hash verification — the two-PDF proof shows exactly how a tampered file can masquerade as the original.
- Operators caught between the two sides of Facebook's earlier warning — legacy-client compatibility versus security — lose the status quo option; keeping SHA-1 is no longer defensible as 'no practical attack exists.'
Second-order effects
- Browser and certificate vendors gain cover to harden deprecation deadlines, because the absence of a working collision was the main brake on forcing laggard sites off SHA-1; expect accelerated cutoffs rather than gradual phase-outs.
- Archival and integrity-checking products built on SHA-1 face emergency re-hashing of stored fingerprints, a migration bill that falls hardest on systems serving the legacy clients Facebook flagged.
Third-order effects
- Google's playbook — publicly demonstrate the break, then drive the migration clock — becomes a repeatable template, resurfacing years later when it set a 2029 deadline for its post-quantum cryptography migration; the company is positioning itself as the industry's de facto scheduler of algorithm transitions.
- If the pattern holds, hash agility — building systems so the digest function can be swapped without re-architecture — shifts from cryptographer best practice to a baseline procurement requirement for anything that stores long-lived fingerprints.
The trend: Cryptographic standards are increasingly retired on the schedule of platform owners armed with public break demonstrations, not on the slower cadence of formal standards bodies.