Algorithms
SHA-1
A 160-bit hash broken by SHAttered in 2017. Still inside Git and old systems and it has HMAC
Hash / Legacy
SHA-1
Broken since SHAttered, still inside Git.
- Digest
- 160-bit · 20 bytes
- HMAC
- takes a key
- Security
- BROKEN: practical collision attack (SHAttered)
- Family
- 2 in legacy
2 options, 0 required
Sample
- hex
- 2aae6c35c94fcfb415dbe95f408b9ce91ee846ed
- base64
- Kq5sNclPz7QV2+lfQIuc6R7oRu0=
Options
Access
- Create
create("sha1") - CLI
hashes sha1 'hello world' - Tryplayground with the sample above
- Kinmd5
Broken in practice since SHAttered in 2017, two different PDFs with one SHA-1. Git still names objects with it (with a collision detector bolted on), and plenty of old protocols still speak it.
create("sha1").hash("abc").digest; // "a9993e364706816aba3e25717850c26c9cd0d89d"
create("sha1").hash("").digest; // "da39a3ee5e6b4b0d3255bfef95601890afd80709"
For compatibility, fine. For anything new, SHA-256. HMAC-SHA1 still holds up as a MAC, which is why TOTP apps still use it.