Technology news and Jobs arrow Information Technology News arrow The Latest MD5 Attack - The Sky Continues to Fall
The Latest MD5 Attack - The Sky Continues to Fall E-mail
by David Heath   
Wednesday, 31 December 2008
Anyone with a voice on this topic has been saying for some time that MD5 is broken and that CAs should move to SHA-1.  As I said on the previous page, all but 6 of the root CAs have taken this advice; those six are aware of the issue.

The problem is that SHA-1 is also rather suspect.

Obviously, SHA-1 isn’t as broken as MD5, but experts in the field have recommended for some time that it should not be used beyond 2010.  To this end NIST has sponsored a competition to select a new algorithm which will become SHA-3.  The competition closed on October 31 2008 and a total of 64 entries were received of which 51 were assessed as meeting the initial criteria.  A final decision is expected in 2012.

Right now, there is nothing agreed to move forward in the short term.  Although Bruce Schneier, quoted elsewhere noted that this entire point is rather moot as users (and browsers) rarely check the validity of certificates in any situation.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter