Tag Archive for: Considers

Microsoft considers blocking SHA-1 certificates after cost of collisions slashed

Microsoft may phase out support for TLS certificates that use the SHA-1 hashing algorithm as early as June 2016. The decision comes in the wake of recent calculations that suggest generating collisions is quicker and cheaper than previously anticipated.

SHA-1 is a hash algorithm, used to derive a 160-bit value from an arbitrary input. Its intent is for collisions—different inputs that hash to the same 160-bit value—to be hard to generate. As compute power has steadily grown over the years, it becomes quicker and cheaper to generate collisions. It was previously projected by Bruce Schneier, based on the observed growth of compute power, that creating SHA-1 collisions would be within reach of criminals by 2018 at a cost of about $ 173,000. On this basis, Microsoft intended to cease supporting the use of new SSL/TLS certificates using SHA-1 on January 1, 2016 and all SHA-1 SSL/TLS certificates on January 1, 2017.

The new cost and performance estimates, however, suggest that the cost is both drastically lower—$ 75,000 to $ 120,000—and that the compute resources are immediately available through cloud services such as Amazon EC2. This has given browser vendors little option but to reconsider the previous 2017 timetable for retiring support of SHA-1.

Read 2 remaining paragraphs | Comments

Ars Technica » Technology Lab

Study considers Computer Security Incident Response – Scoop.co.nz (press release)


Stuff.co.nz

Study considers Computer Security Incident Response
Scoop.co.nz (press release)
A CSIRT is a team focused on supporting the community deal with computer security issues. Formed initially to deal with malware such as computer worms and other viruses, CSIRTS these days work to stay one step ahead of those who would use Internet …
Computer security response team options investigatedVoxy
New unit needed for cybersecurityStuff.co.nz

all 5 news articles »

“computer security” – read more

US considers firmer action against Chinese cyber-espionage – Telegraph.co.uk


Telegraph.co.uk

US considers firmer action against Chinese cyber-espionage
Telegraph.co.uk
One of the former officials said the NIE, an assessment prepared by the National Intelligence Council, also will cite more directly a role by the Chinese government in such espionage. The former official said the NIE will underscore the administration
U.S. Considers Stronger Action Over Chinese Cyber-Espionage After Major ThinkProgress
US mulls firmer action to combat Chinese cyber-espionage following NYT, WSJ Newstrack India
The People's Republic of HackingForeign Policy (blog)
Macleans.ca
all 381 news articles »

Espionage China – read more

Huawei Considers IPO, Counters Accusations of Cyber Espionage – UCStrategies


Quartz

Huawei Considers IPO, Counters Accusations of Cyber Espionage
UCStrategies
However, making steps toward a listing was confounded because of the Chinese company's complex share model. Plus, there were apprehensions about a listing not being able to take the edge off the espionage-related suspicions of U.S. lawmakers.
Chinese telecom giant Huawei tries on transparency for size to combat black Quartz
Huawei: IPO possible, sales may top Ericsson'sFierceBroadbandWireless
Huawei sees firmer revenue growth, 2012 profit up 33 percentReuters UK

all 80 news articles »

Espionage China – read more