What if SHA-1 has been breached?
This article is about what to do if SHA-1 has been compromised. The editor thinks it is very practical, so share it with you as a reference and follow the editor to have a look.
Google has implemented a collision attack on SHA-1 to create two files with different contents but the same hash value. In addition, some security companies also believe that SHA-1 may have some flaws.
But at present, the cost of SHA-1 collision attack is very high, which requires a lot of computing power. If the computing power of the service is used for the attack, it may cost hundreds of thousands of dollars.
Anyway, it's time to use a more complete SHA-256 as the encryption technology. To prevent rainbow table attacks, you can use salt technology, which is encrypted based on the original password and some other characters. Using SHA-256 (global salt+ independent salt+ password) for encryption is a more effective way. The independent salt is placed in the user information table of the database, and each user's independent salt is different and is a random number. The global salt is placed in the program to ensure that even if the database is stolen by a hacker, as long as the program is secure, the password cannot be cracked.
Thank you for reading! This is the end of the article on "what to do if SHA-1 has been breached". I hope the above content can be of some help to you, so that you can learn more knowledge. if you think the article is good, you can share it for more people to see!