[progress Communities] [progress Openedge Abl] Forum Post: Re: Message-digest Workaround

  • Thread starter Thread starter Jean-Christophe Cardot
  • Start date Start date
Status
Not open for further replies.
J

Jean-Christophe Cardot

Guest
Hi Prior to 11.0 you had MD5-DIGEST and SHA1-DIGEST. MD5 has been broken long ago and last week some Google researchers also broke SHA1, so if your security must be very good I'd rather go with OpenSSL (by the way you can also use the DLL or .so from within Progress) and SHA-256 at least. As for the pragmatic me, I'd stick to SHA1 and wait for my migrating to 11.0, then change this to the built-in MESSAGE-DIGEST with SHA-256... Would be easier, cheaper, and when you see the processing power used by Google in order to find a collision in SHA1, it won't be before a few years at least before SHA1 is really broken. By then you'll have migrated to 11 (or more ;) and to SHA-256 (or more :p) Regards JC

Continue reading...
 
Status
Not open for further replies.
Back
Top