Hash function with practical collisions. Must not be used for signatures.
At a glance
| Quantum risk | Weakened by quantum |
|---|---|
| Used for | Hash function |
| Post-quantum algorithm | No |
Positions and deadlines by authority
| Authority | Position | Effective | Scope | Details |
|---|---|---|---|---|
| NIST | Deprecated | in force | all variants | SP 800-131A Rev. 3 (draft): deprecated through 2030. |
| NIST | Disallowed | from January 1, 2031 | all variants | Disallowed for applying cryptographic protection after 2030-12-31. |
Recommended replacements
Sources
- SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.