FWIW, the memo from the horse's mouth[4]:
> To protect your security, Windows operating system updates are dual-signed using both the SHA-1 and SHA-2 hash algorithms to authenticate that updates come directly from Microsoft and were not tampered with during delivery. Due to weaknesses in the SHA-1 algorithm and to align to industry standards Microsoft will only sign Windows updates using the more secure SHA-2 algorithm exclusively.
I'd imagine orchestrating this push is a real cluster. Would be interesting hear perspective from the inside.
[1] https://csrc.nist.gov/projects/hash-functions/nist-policy-on...
[2] https://doi.org/10.6028/NIST.SP.800-131A
[3] https://doi.org/10.6028/NIST.SP.800-131Ar1
[4] https://support.microsoft.com/en-us/help/4472027/2019-sha-2-...