Google Says SHA-1 Encryption Not Secure, Will Drop Support in Chrome

Advertisement
By Manish Singh | Updated: 21 December 2015 19:39 IST

Google will soon drop support for the SHA-1 cryptographic hash algorithm in Chrome. The Mountain View-based company has said that it would start to ditch the outdated encryption technology from January 1, 2016, and completely pull support by January 1, 2017.

The company wrote in a blog post that it doesn't consider SHA-1 secure any more, and starting January 1, 2016, Chrome 48 will display a certificate error to any certificate that is signed with an SHA-1 based signature, or is issued on or after January 1, 2016. The company will completely stop supporting SHA-1 certificates by January 1, 2017.

Advertisement

"Google Chrome does not treat SHA-1 certificates as secure any more, and will completely stop supporting them over the next year," the company wrote in a blog post. "Chrome will discontinue support in two steps: first, blocking new SHA-1 certificates; and second, blocking all SHA-1 certificates."

Google isn't the only browser provider that is taking a strong stand against SHA-1. Microsoft and Mozilla have announced that they would drop support for the outdated encryption technology from their respective Web browsers on January 1, 2017.

Advertisement

Web browsers as well as websites protect the data exchange and communications by encrypting traffic using a hash function. This traffic carries a unique fingerprint which gets digitally signed ensuring that the data hasn't been altered when it passed through various servers. The SHA-1 encryption technology has been around since 1995 and is widely used. As per an estimate from last year, around 90 percent of websites used SHA-1 encryption. Over the years, SHA-1 has become one of the weakest links from the security standpoint, and has been the reason for several security attacks.

In 2011, Baseline Requirements for SSL identified weaknesses in SHA-1 and recommended certificate authorities to transition away from SHA-1 based signatures by early January, 2016. Google hopes that all CAs will stop issuing SHA-1 certificates in 2016.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Chrome, Google, Google Chrome, SHA 1, Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Pro Arrives With a 6,500mAh Battery at This Price in India
  2. Elden Ring Movie Film Adaptation Release Date, Full Cast Revealed
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.