@SteveBellovin@infosec.exchange
Post #3477184
2026-06-29 20:34 UTC
@matthewdgreen.bsky.social Up to a point, you're right. There's exactly no need now to switch algorithms. However… Certificates are often used for both, and for some digital signature uses you want the validity to be good for 20+ years. More seriously, if you've never needed a second algorithm, your protocol may not support it when you do need to convert; see, e.g., https://www.cs.columbia.edu/~smb/papers/new-hash.pdf, by myself and @ekr@infosec.exchange, when it was suddenly time to move on from MD5 and SHA-1.
Replies (0)
No replies.