HN Hall of Fame Weekly email

Lifetimes of cryptographic hash functions

valerieaurora.org Research & data Technical reports Security & privacy Candidate
Screenshot of valerieaurora.org captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 8 calendar years, with breakout response in 2 of them.

submissions
10
submitters
10
observed span
2011–2025
peak thread · 52 comments
153 pts
latest 20+ return · 2017-02-25
132 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

I think SHA-2 should be "minor weakness discovered" (if not outright "unbroken"), not "weakened". At the onset of the SHA-3 competition, everyone was nervous about SHA-2: it appeared as though a good attack was inevitable, what with the cryptanalytic attacks on SHA-1. But as the competition went on, things got calmer. The attacks against SHA-2 that were so expected simply weren't coming[1]. And so now the status quo is that SHA-2 seems pretty darn safe, and the real focus of…

ReidZB·153-point thread·

The SHA-256 "weakness" is a bit disingenuous. As far as I'm aware in the 10 years since that paper was published the "weakness" hasn't been extended _at all_. The main reason for the SHA3 competition was because we were all concerned at the time that SHA2 would be broken and there'd be nothing to replace it with. However as it happens, SHA2 has remained rock solid, so the outcome of SHA3 was to pick something (Keccak) maximally different from SHA2…

kobeya·132-point thread·

This has been discussed before, about 9 months ago: https://news.ycombinator.com/item?id=6123720 And this page was largely written in 2007, although it's been updated a few times since. I'll also note that Val's "Compare by hash considered harmful" is not a conclusion which is widely shared. One can also worry about two people randomly (assuming quality random number generators) choosing the same RSA public key. Or we can worry about all of the oxygen molecules in the room simultaneously randomly deciding to…

tytso·54-point thread·

Zooko Wilcox privately showed some data at the Decentralized Web Summit suggesting that if you extend these results with newer data, the apparent pattern changes: up until around SHA-1, hash algorithms would eventually break, but since SHA-256, we "figured out how to build them right" and now they can be expected to last "forever." I don't know if his conclusion is right, and unfortunately he hasn't published it, but it at least seems plausible to me. A cryptographic hash function…

btrask·10-point thread·

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
2

100+ points or 50+ comments

Total points
381

reference only — not used in Hall rules or ranking

Total comments
119

reference only — not used in Hall rules or ranking

Every submission

DateTitle as submittedByPointsComments
2011-06-01Lifetimes of cryptographic hash functionsphiggy150
2012-11-18Lifetimes of cryptographic hash functions (updated)ibotty20
2013-07-29Lifetimes of cryptographic hash functionsFirst breakout · Best threadtswicegood15352
2014-04-30Lifetimes of cryptographic hash functionsluu5415
2017-02-24Lifetimes of cryptographic hash functionsJoshTriplett103
2017-02-25Lifetimes of cryptographic hash functionsLatest 20+ point returnwwwhizz13247
2020-10-14Lifetimes of Cryptographic Hash Functionsnoanabeshima71
2021-08-03Lifetimes of Cryptographic Hash Functionsantondd20
2025-04-16Lifetimes of Cryptographic Hash Functionskretaceous51
2025-09-24Lifetimes of Cryptographic Hash Functionsbmn__10