New issue
Advanced search Search tips

Issue 644625 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Sep 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 3
Type: Feature



Sign in to add a comment

Policy for extensions payload data hashes should be upgraded from SHA-1 to SHA-256

Project Member Reported by mnissler@chromium.org, Sep 7 2016

Issue description

Policy for extensions data payloads are currently integrity-checked using a SHA-1 digest passed in the ExternalPolicyData.secure_hash field: https://cs.chromium.org/chromium/src/components/policy/proto/chrome_extension_policy.proto?rcl=0&l=21

We should upgrade to SHA-256 given that SHA-1 is showing some signs of weakness and getting phased out elsewhere.
 
Mergedinto: 329824
Status: Duplicate (was: Untriaged)
Turns out we already have a bug, marking as duplicate.

Sign in to add a comment