/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google unveils “practical” SHA-1 collision using nine quintillion computations, releases two different PDFs with identical hashes, urges sunsetting of protocol

Here's Why That's Big For Web Security Steve Dent / Engadget : Google helps put aging SHA-1 encryption out to pasture Gordon Hunt / Silicon Republic : Is nowhere left secure? SHA-1 collision confirmed in study MSRC : SHA-1 Collisions Research Jaikumar Vijayan / eWeek : Researchers Crack the Secure Hash Algorithm-1 Cryptographic Function Gary Sims / Android Authority : Google shatters SHA-1, but don't worry: the Internet is still working Inquirer : Google makes a mockery of SHA-1 with ‘first’ collision attack Tess Townsend / Recode : Google researchers have cracked a key internet security tool PYMNTS.com : Google Cracks Old Cryptographic Algorithm As A Wake-Up Call To Companies Gabriela Vatu / Softpedia News : Mozilla Says Goodbye to SHA-1 as Deprecation Plan Reaches the End Gareth Halfacree / bit-tech.net : Google, CWI announce SHAttered attack against SHA-1 Chris Loterina / Tech Times : Google Cracks Old Crypto Algorithm, SHA-1 Now Unsafe: Why You Should Panic Paul Ducklin / Naked Security : Bang! SHA-1 collides at 38762cf7­f55934b3­4d179ae6­ a4c80cad­ccbb7f0a CircleID : Security Researchers Announce First SHA-1 Collision, Confirming Fears About Its Vulnerabilities Duncan Riley / SiliconANGLE : Google has cracked the widely used SHA-1 encryption standard

Google Online Security Blog

Context & Ripple Effects

This is the payoff to a deprecation fight that started years earlier: in 2015, [[a:837858|Facebook warned that a SHA-1 sunset would block millions of users from encrypted connections]], because legacy clients could not negotiate newer hash functions. Google and CWI have now settled the argument empirically — the initial SHAttered announcement demonstrated two different PDFs sharing one SHA-1 hash after roughly nine quintillion computations, turning a theoretical weakness into a reproducible attack.

The demonstration matters because SHA-1 equality is what many systems use as proof two files are identical — code signing, deduplication, integrity checks — so a forged collision breaks the assumption those systems run on.

First-order effects

  • Any site or vendor still issuing SHA-1 signatures faces document-forgery risk immediately, since attackers can now craft colliding files rather than wait for random chance.
  • Browser vendors and certificate authorities under pressure to drop SHA-1 lose their last counterargument — the 'no practical collision exists' defense is gone.

Second-order effects

  • Operators of systems built on hash-equality assumptions (content-addressed storage, update verification) must fund migrations they deferred while the collision stayed theoretical, echoing the compatibility costs Facebook flagged when the sunset was first proposed.
  • Security teams shift budget toward hash agility — designing systems so the algorithm can be swapped without re-engineering — as a direct lesson from how long SHA-1's retirement took.

Third-order effects

  • Google's own later behavior shows where this leads: the company went on to set a 2029 deadline for its post-quantum cryptography migration, treating algorithm replacement as scheduled infrastructure work rather than crisis response.
  • If that pattern holds, cryptographic standards acquire explicit end-of-life dates set by large platform operators, with researchers' demonstrations serving as the forcing function instead of exploited breaches.

The trend: Cryptographic algorithms are shifting from break-then-replace emergencies to planned, deadline-driven retirements, with platform operators like Google setting the schedule.