[nycbug-talk] [ccc related] MD5 considered harmful today

Miles Nordin carton at Ivy.NET
Tue Dec 30 21:19:27 EST 2008

>>>>> "cs" == Charles Sprickman <spork at bway.net> writes:

    cs> https://www.win.tue.nl/hashclash/rogue-ca/

``Until Firefox 3 and IE 7, certificate revocation was disabled by
  default. Even in the latest versions, the browsers rely on the
  certificate to include a URL pointing to a revocation server.''

pwaaaahahaha!  rapidssl ist gePWNen!
