Finally a SHA-1 collision. TL;DR: same-prefix collision, don't panic *yet*, but Git better start thinking of SHA-256 and don't trust PDFs.
SHA-2 vs SHA-3 boils down to "old and battle tested but sibling of broken SHA-1" and "new and unknown".
-
-
Think of SHA-3 as a backup if SHA-2 is broken... but nothing says SHA-3 won't be broken first.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Keccak/SHA-3 has actually been well-studied, see, e.g., http://eprint.iacr.org/2017/128 and refs therein
-
Of course, but SHA-2 has been studied for longer due to its age.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.