JREF Homepage Swift Blog Events Calendar $1 Million Paranormal Challenge The Amaz!ng Meeting Useful Links Support Us
James Randi Educational Foundation JREF Forum
Forum Index Register Members List Events Mark Forums Read Help

Go Back   JREF Forum » General Topics » Computers and the Internet
Click Here To Donate

Notices


Welcome to the JREF Forum, where we discuss skepticism, critical thinking, the paranormal and science in a friendly but lively way. You are currently viewing the forum as a guest, which means you are missing out on discussing matters that are of interest to you. Please consider registering so you can gain full use of the forum features and interact with other Members. Registration is simple, fast and free! Click here to register today.

Tags encryption , MD5 , security , SSL

Reply
Old 6th January 2009, 11:21 PM   #1
shadron
Philosopher
 
shadron's Avatar
 
Join Date: Sep 2005
Location: Colorado
Posts: 5,719
SSL MD5 security encryption

SSL, the web protocol which allows for secure communication of financial data and the like over the web, is vulnerable to an exploit of the MD5 hashing algorithm. I think this is going to spread some paranoia out in etherland.

It's a pretty technical article for IT geeks, but you might learn something about cryptography if you read it: http://blogs.techrepublic.com.com/ne...76&tag=nl.e101

It might also scare you some if you supervise an https domain with a shopping cart on it.
shadron is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 7th January 2009, 06:07 AM   #2
ddt
Mafia Penguin
 
ddt's Avatar
 
Join Date: Dec 2007
Location: Netherlands
Posts: 10,406
Originally Posted by shadron View Post
SSL, the web protocol which allows for secure communication of financial data and the like over the web, is vulnerable to an exploit of the MD5 hashing algorithm. I think this is going to spread some paranoia out in etherland.
And from your link, here is the article of the authors of the collision: MD5 considered harmful today. They claim that they can generate a usable MD5 collision in the matter of hours. Oops...

Originally Posted by shadron View Post
It might also scare you some if you supervise an https domain with a shopping cart on it.
Many webshops don't even care for https... And then there's the issue of phishers who register a domain name that resembles the real name of your bank/shop/etc. and happily use https the way it's intended.
__________________
Proud member of the Solipsistic Autosycophant's Group
ddt is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Old 17th January 2009, 09:19 PM   #3
vexed
Critical Thinker
 
vexed's Avatar
 
Join Date: Jun 2007
Location: Earth
Posts: 314
Leo Laporte and Steve Gibson discuss this on 'Security Now', very interesting.

http://twit.tv/sn Episode #179 (the most current at the time of this post)
__________________
"Thinking critically is a chore. It does not come naturally or easily. And if the fruits of such efforts are not carefully displayed to young minds, then they will not harvest them. Every school child must be implanted with the wonder of the atom, not the thrall of magic." - Perry DeAngelis
vexed is offline   Quote this post in a PM   Nominate this post for this month's language award Copy a direct link to this post Reply With Quote Back to Top
Reply

JREF Forum » General Topics » Computers and the Internet

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 11:05 PM.
Powered by vBulletin. Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
© 2001-2012, James Randi Educational Foundation. All Rights Reserved.

Disclaimer: Messages posted in the Forum are solely the opinion of their authors.