New issue
Advanced search Search tips

Issue 618486 link

Starred by 4 users

Issue metadata

Status: Untriaged
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug

Blocked on:
issue 564281
issue 613443
issue 613460
issue 618487



Sign in to add a comment

Audit: Ensure SHA-1 is not used for sensitive or security-relevant actions within Chrome

Project Member Reported by rsleevi@chromium.org, Jun 8 2016

Issue description

As we move to distrust SHA-1 certificates, we should be carefully examining any other uses of SHA-1 within the codebase that may have security-relevance, and updating as appropriate.

Possible actions:
- If a cryptographic hash is not required, switch to another appropriate hash that is better for performance (e.g. city/murmur or even std::hash)
- If a cryptographic hash is desired for security, switch to SHA-256

 
Blockedon: 618487
Blockedon: 564281 613460 613443

Sign in to add a comment