Home Resources Expert Opinions Information assurance quote: Sotirov et al, No excuse for using broken crypto
quote: Sotirov et al, No excuse for using broken crypto

First and foremost, there is no proper excuse for continued use of a broken cryptographic primitive (MD5) when sufficiently strong alternatives are readily available, for example SHA-2. 

Secondly, there is no substitute for security awareness. Openness about security problems, vulnerabilities and technical possibilities is invaluable to make the Internet a safer place.

Advice from experts should be taken seriously and early in the process.

In this case, MD5 should have been phased out soon after 2004.

Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Wegerr, "MD5 considered harmful today - Creating a rogue CA certificate", December 2008

 

Related Items