Security team successfully cracks SSL using 200 PS3's and MD5

Gadi Evron ge at
Sat Jan 3 02:53:06 UTC 2009

On Fri, 2 Jan 2009, Dragos Ruiu wrote:
>; classtype: policy-violation; 
> sid:1000001;)

You can't really use any snort rule to detect SHA-1 certs created by a 
fake authority created using the MD5 issue.

Yes, this is a serious matter, but it hardly has any operational impact to 
speak of for users and none for NSPs.


More information about the NANOG mailing list