3 ms·
PGP V4 key fingerprints still use SHA-1 exclusively. There hasn't been an update to this part of the RFC as far as I know [1]. Collisions where both preimages a
by maxtaco 10y ago
PGP V4 key fingerprints still use SHA-1 exclusively. There hasn't been an update to this part of the RFC as far as I know [1]. Collisions where both preimages are of the attacker's choosing matter less in this context, but who knows what clever attacks people can come up with.
[1] https://tools.ietf.org/html/rfc4880#page-71 https://tools.ietf.org/html/rfc4880#page-71