Version 2 of SWHID, ISO/IEC 18670:2025?
kpcyrd
kpcyrd at archlinux.org
Mon Jan 19 14:21:09 UTC 2026
Hello!
Today I learned that SWHID (also known as ISO/IEC 18670:2025) was
published 1.0 in 2022 and ISO standardized in 2025, but uses the
insecure[1][2] SHA-1 as core cryptographic primitive[3].
Does somebody know if there's any efforts to upgrade this to sha256,
sha3-256, blake2b, blake3 or similar algorithms suitable for secure
content-addressing?
thanks,
kpcyrd
[1]: https://shattered.io/ (Feb 23, 2017)
[2]:
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-131a.pdf
(SHA-1 deprecation notice from January 2011, pretty much exactly 15
years ago)
[3]: https://www.swhid.org/specification/v1.2/5.Core_identifiers/
More information about the rb-general
mailing list