No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
MyNetFone has received certification from NBN Co to provide both retail and wholesale broadband...
Facebook has launched an Antivirus Marketplace, initially offering products from Microsoft, McAfee, Trend Micro,...

More From

MD5 - The Internet has a Major Problem

Your IT - Home IT

Oiaohm further observes that the problem will also manifest in Windows driver signing.

Chillingly, de Weger responds “This depends on how the CAs that issue those certificates behave. We haven't investigated this.” 

Let me add, “Yet.”  Let me also add that this topic will need some serious further investigation as it has major ramifications for the anti-virus, anti-spam and related industries.

Next, Lawrence D'Oliveiro suggests: “The only solution is to dump these CAs' root certificates from the popular browsers. I would expect this sort of thing to happen in upcoming updates. In the meantime, you can reconfigure your browser installations yourself, and remove the suspect certificates from your trusted list.

I added some clarification to the question submitted to de Weger: “Is this likely?  It seems entirely reasonable that browsers could be 'updated' to reject anything to do with the six remaining CAs that cling to MD5.  But, would this also require rejecting anything defined both up-stream and down-stream from the CAs?  If so, the dependency tree could get very interesting.”

De Weger’s response makes it very clear that this problem won’t go away anytime soon.  “Yes, and that is exactly why it's unlikely that existing MD5 certificates will be revoked.”

Huh?  How’s that again? 

De Weger is telling us that even if the six remaining CAs abandon use of MD5 today, the problem won’t go away as an endless supply of existing certificates can’t easily be revoked without major upheavals on the web.

The “now what” hangs heavy in the air.