[110347] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Security team successfully cracks SSL using 200 PS3's and MD5

daemon@ATHENA.MIT.EDU (Mikael Abrahamsson)
Sat Jan 3 12:44:41 2009

Date: Sat, 3 Jan 2009 18:44:29 +0100 (CET)
From: Mikael Abrahamsson <swmike@swm.pp.se>
To: "nanog@nanog.org" <nanog@nanog.org>
In-Reply-To: <Pine.LNX.4.64.0901031851230.17922@efes.iucc.ac.il>
Errors-To: nanog-bounces@nanog.org

On Sat, 3 Jan 2009, Hank Nussbacher wrote:

> You mean like for BGP neighbors?  Wanna suggest an alternative? :-)

Well, most likely MD5 is better than the alterantive today which is to run 
no authentication/encryption at all.

But we should push whoever is developing these standards to go for SHA-1 
or equivalent instead of MD5 in the longer term.

-- 
Mikael Abrahamsson    email: swmike@swm.pp.se


home help back first fref pref prev next nref lref last post