lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 30 Dec 2008 13:16:37 -0700 (MST) From: jlay@...ve-tothe-box.net To: full-disclosure@...ts.grok.org.uk Subject: Re: Creating a rogue CA certificate > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > SSL/PKI is only as strong as the weakest CA... > > For those of you who haven't been following this, here you go: > > http://www.win.tue.nl/hashclash/rogue-ca/ > http://www.phreedom.org/research/rogue-ca/md5-collisions-1.0.ppt > > Enjoy and Happy New Years! > > elazar > -----BEGIN PGP SIGNATURE----- > Charset: UTF8 > Version: Hush 3.0 > Note: This signature can be verified at https://www.hushtools.com/verify > > wpwEAQECAAYFAklaVFQACgkQi04xwClgpZh4TQP+ODe2/jTHhOrLbKtoSJhZInX+lJXt > LMkU/xlYK1Au/f1E5KhXt43uMWYSeC/M0njQRPLyrDfihFlLsmAxGK/97kRQfxEttbcN > R0q1BL+WmbiGNglujzSWHqMSkn20r12itVfGP77nEbGYbjidV1BXxFNR2QQwLHZhGLWe > gVO/5Zg= > =+Pm+ > -----END PGP SIGNATURE----- > > -- > Click for free info on getting an MBA, $200K/ year potential. > http://tagline.hushmail.com/fc/PnY6qxsZwUN6299xt0fJO8HvJUKovV4hcZ7MH3I6KbhlC0IDsYiG8/ > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ > > >>From Microsoft: http://www.microsoft.com/technet/security/advisory/961509.mspx "Microsoft is not aware of specific attacks against MD5, so previously issued certificates that were signed using MD5 are not affected and do not need to be revoked. This issue only affects certificates being signed using MD5 after the publication of the attack method." I take it the above is incorrect? James _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists