At the bottom the article mentions that the NSA said there was something wrong with SHA-0. Do we now know what that was?
Apparently the NSA warned against SHA-0 in 1995.
So do we now know what they perceived the weakness to be? Or are we still guessing?