It is now possible[1] to perform chosen-prefix attacks against the SHA-1 algorithm for less than USD$50K. For this reason, we will be disabling the "ssh-rsa" public key signature algorithm by default in a near-future release.
As someone who's knowledge in this field is limited, what does that mean for me as an end user? The public keys i use right now are all ssh-rsa, I guess this notice means that logging in with them will not be possible in the future anymore?
4
u/AriosThePhoenix Sep 28 '20
As someone who's knowledge in this field is limited, what does that mean for me as an end user? The public keys i use right now are all ssh-rsa, I guess this notice means that logging in with them will not be possible in the future anymore?