A presentation was given at this year's Chaos Communication Congress in which it was described how researchers were apparently able to produce authentic signed SSL certificates thanks to a handful of CAs who rely on MD5. If true, is it time to disable MD5 by default?
_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to