Elektrine lite

← Feed

@SteveBellovin@infosec.exchange

Post #3477184

2026-06-29 20:34 UTC

@matthewdgreen.bsky.social Up to a point, you're right. There's exactly no need now to switch algorithms. However… Certificates are often used for both, and for some digital signature uses you want the validity to be good for 20+ years. More seriously, if you've never needed a second algorithm, your protocol may not support it when you do need to convert; see, e.g., https://www.cs.columbia.edu/~smb/papers/new-hash.pdf, by myself and @ekr@infosec.exchange, when it was suddenly time to move on from MD5 and SHA-1.

Replies (0)

No replies.