-
"First and foremost, there is no proper excuse for continued use of a broken cryptographic primitive (MD5) when sufficiently strong alternatives are readily available, for example SHA-2. Secondly, there is no substitute for security awareness." ... "Advice from experts should be taken seriously and early in the process. In this case, MD5 should have been phased out soon after 2004."Read more...
Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Wegerr, "MD5 considered harmful today - Creating a rogue CA certificate", December 2008 -
Read more...
“It's not good enough to have a system where everyone (using the system) must be trusted, it must also be made robust against insiders!”
Robert Morris, former Chief Scientist of the US National Security Agency (NSA), National Computer Security Center, "Crypto '95 invited talks by R. Morris and A. Shamir", 1995
-
Read more...
“Given today’s common hardware and software architectural paradigms, operating systems security is a major primitive for secure systems – you will not succeed without it. This area is so important that it needs all the emphasis it can get. It is the current ‘black hole’ of security.”
Brian Snow, Former Technical Director of the US National Security Agency (NSA), "We need assurance!", 1999-2008
| bibliography: US President's 60 day Cyberspace Policy Review |
|
||||||||||||||||||||||||
| Last Updated on Friday, 04 June 2010 15:49 |
