Live
Breaking
6m ago Cybersecurity Autenticação de Dois Fatores em Node.js: 12 Passos [2026] 20m ago Cryptography Crittografia End-to-End in Node.js: 12 Step [2026] 26m ago Cybersecurity Gratis SSL/TLS-certifikat: 12 trin med Certbot [2026] 32m ago Cybersecurity Certificat SSL gratuit avec Certbot : 11 étapes [2026] 41m ago Cybersecurity Authentification JWT en Node.js : 12 étapes [2026] 43m ago Cryptography SSH-Key erstellen: Ed25519 in 8 Schritten [2026] 44m ago Cybersecurity SSH-Key erstellen: ed25519 in 12 Schritten [2026] 56m ago Cryptography AES-256 Encryption in Node.js: 12 Steps [2026] 4h ago Cybersecurity 2FA-vertailu: 5 tapaa ja 99,9 % suoja [2026] 4h ago Privacy Signal vs WhatsApp vs Telegram: 3B vs 1B [2026] 8h ago Cybersecurity Agentic AI Security: $4.7M Breaches, 92% Alarmed [2026] 12h ago Cybersecurity Jaguar Land Rover Cyber Attack: £1.9B Hit [2026] 20h ago Privacy WireGuard vs OpenVPN: 892 vs 222 Mbps [2026] 20h ago Privacy NordVPN vs ProtonVPN vs Mullvad: 8800 vs 650 [2026] 6m ago Cybersecurity Autenticação de Dois Fatores em Node.js: 12 Passos [2026] 20m ago Cryptography Crittografia End-to-End in Node.js: 12 Step [2026] 26m ago Cybersecurity Gratis SSL/TLS-certifikat: 12 trin med Certbot [2026] 32m ago Cybersecurity Certificat SSL gratuit avec Certbot : 11 étapes [2026] 41m ago Cybersecurity Authentification JWT en Node.js : 12 étapes [2026] 43m ago Cryptography SSH-Key erstellen: Ed25519 in 8 Schritten [2026] 44m ago Cybersecurity SSH-Key erstellen: ed25519 in 12 Schritten [2026] 56m ago Cryptography AES-256 Encryption in Node.js: 12 Steps [2026] 4h ago Cybersecurity 2FA-vertailu: 5 tapaa ja 99,9 % suoja [2026] 4h ago Privacy Signal vs WhatsApp vs Telegram: 3B vs 1B [2026] 8h ago Cybersecurity Agentic AI Security: $4.7M Breaches, 92% Alarmed [2026] 12h ago Cybersecurity Jaguar Land Rover Cyber Attack: £1.9B Hit [2026] 20h ago Privacy WireGuard vs OpenVPN: 892 vs 222 Mbps [2026] 20h ago Privacy NordVPN vs ProtonVPN vs Mullvad: 8800 vs 650 [2026]
NewsroomLive
Today16 new
Archive28 stories
Last filed6m ago
Languages10
UTC17:05:34
Top Story Cybersecurity

Autenticação de Dois Fatores em Node.js: 12 Passos [2026]

A autenticação de dois fatores deixou de ser um extra opcional. Em 2026, qualquer aplicação web que guarde dados sensíveis precisa de uma segunda barreira para lá da palavra-passe. A Microsoft repete há anos que mais…

6m ago  ·  Jun 11, 2026 Read the brief

The Desks

// editorial departments

Latest

// fresh from the editors
Cryptography 43m ago

SSH-Key erstellen: Ed25519 in 8 Schritten [2026]

Ein gestohlenes Passwort ist 2026 die häufigste Eintrittstür in fremde Server. SSH-Keys schließen diese Tür: Statt einer Zeichenkette, die man erraten, abfangen…

Jun 11, 2026 Read →
Cybersecurity 44m ago

SSH-Key erstellen: ed25519 in 12 Schritten [2026]

Ein SSH-Key ersetzt das Passwort beim Anmelden auf einem Server durch ein kryptografisches Schlüsselpaar. Wer 2026 noch mit Passwörtern arbeitet, lädt Brute-Force-Angriffe…

Jun 11, 2026 Read →
Cybersecurity 4h ago

2FA-vertailu: 5 tapaa ja 99,9 % suoja [2026]

Kaksivaiheinen tunnistautuminen (2FA) on vuonna 2026 tilin tärkein yksittäinen suojaus, mutta kaikki menetelmät eivät ole läheskään yhtä turvallisia. Microsoftin mukaan monivaiheinen tunnistautuminen…

Jun 11, 2026 Read →

More from the desks

// keep digging
// about

About Shattered.io

This domain has been home to the SHAttered SHA-1 collision project since 2017, and is now a hub for cryptography, security and privacy reporting. The full origin story of the project, the two proof PDFs and the research credits live below.

The SHAttered project — origin, proof files and research credits

On 23 February 2017, researchers at CWI Amsterdam and Google showed the world the first real collision for the SHA-1 hash function. The project was called SHAttered, and this domain has been its home ever since. The two files that prove the break are still here to download.

What a collision actually is

A cryptographic hash takes any file and returns a short fixed-length fingerprint. The promise is simple: change a single bit of the file and the fingerprint changes too, and no two different files should ever share one. A collision breaks that promise. It is a pair of distinct inputs that produce the exact same hash. For a function used to sign software, certificates and documents, a collision is not a curiosity. It is a crack in the foundation.

What SHAttered produced

The team did not just argue that SHA-1 was weak on paper. They built the evidence. Two PDF files, visibly different and carrying different content, share one identical SHA-1 value: 38762cf7f55934b34d179ae6a4c80cadccbb7f0a. Run either file through SHA-1 and the answer matches. Run them through SHA-256 and the answer differs, which is how anyone can confirm they are genuinely two separate files.

What the attack cost

The break was expensive, and that was part of the point. Producing the collision took roughly nine quintillion SHA-1 computations, the work of about 6,500 CPU-years and 110 GPU-years run in parallel. That scale kept the attack out of reach for a casual attacker in 2017, yet it ran thousands of times faster than trying every possibility by brute force. The direction of travel was clear: the cost would only fall.

Why SHA-1 had to retire

Once a working collision exists, trust in a hash erodes quickly. Within months the result pushed browsers, certificate authorities and version-control systems to drop SHA-1 for anything security-sensitive. Git added collision detection. TLS certificates signed with SHA-1 were phased out. The lesson reached far past one algorithm: a function can look safe for years and still fall the moment the maths and the hardware line up.

The research and the people behind it

SHAttered was the work of Marc Stevens and Pierre Karpman at CWI Amsterdam, together with Elie Bursztein, Ange Albertini and Yarik Markov at Google. It built on years of earlier cryptanalysis of the SHA-1 design. The full technical paper that documents the method is preserved here.

Beyond the collision

The same questions that drove SHAttered run through everything we cover here: how hashing works, where it is used, and how systems prove they have not cheated. These guides pick up where the research leaves off.

What you'll find on shattered.io today

Beyond the original SHA-1 collision proof, the site now publishes ongoing coverage across cryptography, cybersecurity, privacy, cryptocurrency and provably-fair systems. Every article is editorial, lightly-opinionated and built on primary sources where possible.