On Thu, 30 Apr 2009, David Shaw wrote:

> There is not much hard information yet, but the two big quotes are 
> "SHA-1 collisions now 2^52" and "Practical collisions are within 
> resources of a well funded organisation."

so... when is the open-pgp spec moving beyond SHA1 hashes to identify 
public keys? what's next? will it have to be a bigger hash?


