Skip to content

Move from SHA1 to SHA256 #953

Description

@kewde

Recently the team at Google have found the first SHA1 collision,
the ECDSA signatures use SHA1 and most of the code for a switch to SHA256 is in the comments already.

https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html

  • allow signing with SHA256 for people who want to experiment
  • make all signatures SHA256
  • disable support for SHA1 verification

Activity

self-assigned this
on Feb 24, 2017

PeterSurda commented on Feb 24, 2017

@PeterSurda
Member
added this to the v0.6.5 milestone on Feb 24, 2017
added a commit that references this issue on Mar 2, 2017

g1itch commented on Mar 11, 2017

@g1itch
Collaborator

Wouldn't this potentially make it possible to use the bitcoin ASICs to spam bitmessage?

kewde commented on Mar 11, 2017

@kewde
Author

@g1itch I doubt it.
The ASICs operate under a very specific format that I doubt is applicable to BitMessage.

PeterSurda commented on Mar 11, 2017

@PeterSurda
Member

@g1itch Bitmessage uses double SHA512 for PoW, so no. The SHA1 -> SHA256 migration is only for sender authentication.

kewde commented on Sep 13, 2017

@kewde
Author

Has there been any progress on this issue?

martinvahi commented on Sep 14, 2017

@martinvahi

Wouldn't this potentially make it possible to use the bitcoin ASICs to spam bitmessage?

The ASICs operate under a very specific format that I doubt is applicable to BitMessage.

If the ASIC's are implemented by using FPGAs, which might be the case to allow the same hardware, server park, to be reconfigured and reused for mining other cryptocoins after the Bitcoin "mine" has become "depleted enough", then the switch from one hash algorithm to another is not that big of an impediment for the server park owners.

PeterSurda commented on Sep 14, 2017

@PeterSurda
Member

@kewde You can specify that you want to send SHA256-hashed messages by specifying

digestalg = sha256

in the bitmessagemain section of keys.dat. The other steps outlined will progress as new releases are made.

PeterSurda commented on Nov 16, 2019

@PeterSurda
Member

This probably should be expedited, it's been waiting for too long. I've been running with digestalg = sha256 for a long time and haven't had issues.

pinned this issue on Jun 29, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions