Decius wrote: ] ] SHA-1 has been broken. Not a reduced-round version. Not a ] ] simplified version. The real thing. Well, "Broken" is relative.  I'd instead use the term "somewhat weaker than expected".  From what I'm reading, the old chances of collision were 2^80, and now with the "break" they've been reduced to only 2^69.  Still pretty hefty. Lots of good discussion on this at Slashdot: http://it.slashdot.org/comments.pl?sid=139602 RE: Schneier on Security: SHA-1 Broken  |