Post
Topic
Board Meta
Merits 10 from 3 users
Re: The profile page should be changed. No one uses ICQ, AIM, MSN or YIM.
by
Coding Enthusiast
on 27/02/2019, 11:31:02 UTC
⭐ Merited by Vod (5) ,suchmoon (4) ,OgNasty (1)
I’ve long thought there should be a spot for PGP fingerprint.

PGP fingerprints are SHA-1, which is insecure. The OpenPGP standard really needs a complete new revision...

Is it really insecure in this context?
To my knowledge the only problem with SHA-1 so far is collision. Considering SHA-1 is 160-bit and there is a known structural weakness, it has a time complexity of 263 which is very fast. But in this context the security depends on ability to find a second preimage (since the message aka the pubkey and the hash of it is already known), and there has been no weaknesses found to help perform this any faster so this has a time complexity of 2160 which makes it expensive enough to be secure.