SHA2: In 2016, tens of millions of people around the world will experience serious connection problems on some of the most widely used and encrypted websites such as Facebook, Google, Gmail, Twitter, and various Microsoft sites.
Why? Because their browser or device won't be able to read the new, more secure certificates.
The SHA1 encryption algorithm, which has been at the center of web security for a decade, will be completely retired, as reports claim it could be “broken” by the end of the year, effectively rendering it useless and weakening the security of millions of users.
[pullquote]“We are ready to leave a whole part of the internet in the past”[/pullquote]
Certificate Authorities, on the other hand, stated that they would respond immediately by stopping issuing SHA1 certificates as of midnight on January 1, 2016, opting instead for SHA2 certificates.
The SHA2 algorithm is much stronger and will last for many years to come. But there is a problem.
A fairly large portion of Internet users do not have browsers or devices that are compatible with the SHA2 algorithm.
“We’re ready to leave a whole chunk of the internet behind,” Cloudflare CEO Matthew Prince said during an interview in New York earlier this month.
Encryption is important not only for protecting online banking transactions, email accounts, and social networks. The green bar in the URL or the padlock in your browser verifies the integrity of a website and offers a strong level of assurance that the page has not been modified in any way.
So most websites today adopt encryption because it costs little to nothing to implement it.
In the age of hacking, mass data leaks, and mass surveillance, adopting a strong algorithm like SHA2 is a very important and necessary move. But browser makers and website owners in general thought they had more time.
Prominent security researchers have said that SHA1 will last until 2018, but their current reports state that the SHA1 algorithm could be broken by the end of 2015.
The good news is that most websites are already using strong SHA2 certificates. However, about 24% of websites that use SSL encryption still use the SHA1 algorithm. That's about 1 million websites.
This number is decreasing every month, so by the end of the year the percentage could have reached 10 percent of all websites, meaning that the vast majority of encrypted websites will be safe from SHA1 compromise attacks.
For most people, this won't be a problem. The majority are already using the latest version of Chrome or Firefox on the latest operating system, or the latest smartphone with the latest software, which are compatible with both the old SHA1 algorithm and the newer SHA2.
But what about those using older devices?
There is still no concrete data on how many people are running old or unsupported browsers or devices.
Ivan Ristic, head of SSL Labs at Qualys, told ZDNet that Windows XP SP2 users, and users with Android phones 2.2 and earlier, will not be supported by SHA2 certificates.
"Due to the switch to SHA2, it is likely that users with older browsers will begin to experience issues with increased frequency throughout 2016,"
Ristic said.
The Mozilla Foundation found this out the hard way last year.
Last year, the browser maker updated its website encryption with a new SSL certificate that uses the SHA2 algorithm. So those running a browser or operating system that doesn't support SHA2 wouldn't be able to access the new website and of course couldn't download the browser.
The upgrade “killed a million downloads,” said Mozilla’s Chris More.
So from the beginning of 2016, when the issuance of new certificates with the SHA1 algorithm stops, website owners and application developers will have a full year to upgrade to SHA2.
