Skip to Content.
Sympa Menu

cacert - Re: [CA cert] [Fwd: [PGPNET] SSL Broken?]

Subject: A better approach to security

List archive

Chronological Thread  
  • From: "John W. Moore III" <jmoore3rd AT bellsouth.net>
  • To: A better approach to security <cacert AT lists.cacert.org>
  • Subject: Re: [CA cert] [Fwd: [PGPNET] SSL Broken?]
  • Date: Sun, 04 Jan 2009 19:05:05 -0500

Christoph A. wrote:
> Jan Pieter Cornet wrote:
>> It's rather hard for end-users to detect
>> these certificates (if not impossible)
>
> SSL Blacklist now detects and warns about certificate chains that use
> the MD5 algorithm for RSA signatures.
>
> http://www.codefromthe70s.org/sslblacklist.aspx

True, but what exactly does 'knowing' accomplish? The only 2 Login
Sites I've encountered so far that the SSLBlacklist Extension for
Firefox has detected were for Twitter & SourceForge. :-\

JOHN 8-)
Timestamp: Sunday 04 Jan 2009, 19:02 --500 (Eastern Standard Time)

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.24.

Top of Page