|
|
|
|
|
by timeal
3405 days ago
|
|
This attack is applicable to SSL certs. Not most CAs as they have deployed counter-measures (such as using a long, random serial number) after the publication of the colliding MD5 rogue CA (https://www.win.tue.nl/hashclash/rogue-ca/) but I'm sure there are tons of companies with IT department and internal CAs who don't follow best practices and could be attacked with SHA1 collisions. |
|
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1267332#c5