Google unveils “practical” SHA-1 collision using nine quintillion computations, releases two different PDFs with identical hashes, urges sunsetting of protocol
Here's Why That's Big For Web Security Steve Dent / Engadget : Google helps put aging SHA-1 encryption out to pasture Gordon Hunt / Silicon Republic : Is nowhere left secure? SHA-1 collision confirmed in study MSRC : SHA-1 Collisions Research Jaikumar Vijayan / eWeek : Researchers Crack the Secure Hash Algorithm-1 Cryptographic Function Gary Sims / Android Authority : Google shatters SHA-1, but don't worry: the Internet is still working Inquirer : Google makes a mockery of SHA-1 with ‘first’ collision attack Tess Townsend / Recode : Google researchers have cracked a key internet security tool PYMNTS.com : Google Cracks Old Cryptographic Algorithm As A Wake-Up Call To Companies Gabriela Vatu / Softpedia News : Mozilla Says Goodbye to SHA-1 as Deprecation Plan Reaches the End Gareth Halfacree / bit-tech.net : Google, CWI announce SHAttered attack against SHA-1 Chris Loterina / Tech Times : Google Cracks Old Crypto Algorithm, SHA-1 Now Unsafe: Why You Should Panic Paul Ducklin / Naked Security : Bang! SHA-1 collides at 38762cf7f55934b34d179ae6 a4c80cadccbb7f0a CircleID : Security Researchers Announce First SHA-1 Collision, Confirming Fears About Its Vulnerabilities Duncan Riley / SiliconANGLE : Google has cracked the widely used SHA-1 encryption standard
Context & Ripple Effects
This is the payoff to a deprecation fight that started years earlier: in 2015, [[a:837858|Facebook warned that a SHA-1 sunset would block millions of users from encrypted connections]], because legacy clients could not negotiate newer hash functions. Google and CWI have now settled the argument empirically — the initial SHAttered announcement demonstrated two different PDFs sharing one SHA-1 hash after roughly nine quintillion computations, turning a theoretical weakness into a reproducible attack.
The demonstration matters because SHA-1 equality is what many systems use as proof two files are identical — code signing, deduplication, integrity checks — so a forged collision breaks the assumption those systems run on.
First-order effects
- Any site or vendor still issuing SHA-1 signatures faces document-forgery risk immediately, since attackers can now craft colliding files rather than wait for random chance.
- Browser vendors and certificate authorities under pressure to drop SHA-1 lose their last counterargument — the 'no practical collision exists' defense is gone.
Second-order effects
- Operators of systems built on hash-equality assumptions (content-addressed storage, update verification) must fund migrations they deferred while the collision stayed theoretical, echoing the compatibility costs Facebook flagged when the sunset was first proposed.
- Security teams shift budget toward hash agility — designing systems so the algorithm can be swapped without re-engineering — as a direct lesson from how long SHA-1's retirement took.
Third-order effects
- Google's own later behavior shows where this leads: the company went on to set a 2029 deadline for its post-quantum cryptography migration, treating algorithm replacement as scheduled infrastructure work rather than crisis response.
- If that pattern holds, cryptographic standards acquire explicit end-of-life dates set by large platform operators, with researchers' demonstrations serving as the forcing function instead of exploited breaches.
The trend: Cryptographic algorithms are shifting from break-then-replace emergencies to planned, deadline-driven retirements, with platform operators like Google setting the schedule.