|
|
|
|
|
by y0ghur7_xxx
2523 days ago
|
|
> Certificates which are perfectly good for communication and do not pose any significant security risk. Is it so? I remember that in 2008 someone was able to create a rouge CA certificate because of the predictability of serial numbers[1]. It was a different time: we still used md5, but are you sure the limited entropy used to generate serial numbers does not pose any security risk? [1]https://www.win.tue.nl/hashclash/rogue-ca/ |
|
This is a Brown M&M ‡. It doesn't actually matter in terms of security, 63-bits, 65-bits, it's never going to make a real difference. But we wrote 64-bits in those rules, if we can't trust you to obey that rule, who says you got the really important parts right?
‡ https://www.snopes.com/fact-check/brown-out/