<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: KARL, YOU ARE WRONG. in </title>
<link>http://www.dslreports.com/forum/r21669579</link>
<description></description>
<language>en</language>
<pubDate>Sat, 28 Nov 2009 16:23:58 EDT</pubDate>
<lastBuildDate>Sat, 28 Nov 2009 16:23:58 EDT</lastBuildDate>

<item>
<title>Re: KARL, YOU ARE WRONG.</title>
<link>http://www.dslreports.com/forum/remark,21672245</link>
<description><![CDATA[<A HREF="/useremail/u/168864"><b>sporkme</b></A> : <div class="bquote"><small>said by  k1ll3rdr4g0n <A HREF="/useremail/u/1175917"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>[<br>If MD6 is available, why not use THAT in certificates instead of MD5? <br> </div>Hell, why not just turn it all the way up to MD11???]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21672245</guid>
<pubDate>Fri, 02 Jan 2009 20:29:57 EDT</pubDate>
</item>

<item>
<title>Re: KARL, YOU ARE WRONG.</title>
<link>http://www.dslreports.com/forum/remark,21670778</link>
<description><![CDATA[<A HREF="/useremail/u/1175917"><b>k1ll3rdr4g0n</b></A> : <div class="bquote"><small>said by  MxxCon <A HREF="/useremail/u/118623"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>how can you post a story without even reading it?!<br><b>THEY NEVER SAID THEY "have found a method of hacking any website".</b><br><br>what they did say was that they <b>"found a way to forge certain digital certificates"</b><br><br>THAT'S A HUGE DIFFERENCE.<br><br>your own link to our forum says &raquo;<A HREF="/forum/r21655254-SSL-security-flaw-with-MD5-certificates-announces-today">SSL security flaw with MD5 certificates announces today</A> that's nothing even close to "hacking any website"<br><br><blockquote><strong>KARL, STOP SPREADING FUD!</strong></blockquote><br> </div>I have to agree with you. Though they claim its just a "proof-of-concept" aka POC or Piece o' cr4p. I love how people always go "omgz its a new exploitz, lets all freak out" - and never actually demonstrates that it works. I mean what the hell people, so if I sat there and said that I found a "POC" exploit for Linux servers would you all jump out of your chair and go "I'm switching to Windows Server". I hope not (assuming I could explain exactly how it worked).<br><br>And actually this is partly the browsers fault, and the HTTPS scheme as a whole. I mean I just find the whole idea of *paying* for security a little unsecure. CA's don't maintain SSL, so why should we shell out $$$ to them? But, whatever, back to the point at hand. So lets point out the browser: its stupid. It wont tell you *what* CA verified (unless you manually look) the cert, just that its good; wait...so a cert from ABC company is as valid of a cert from verisign? Uhhh...I see something wrong with that myself but regardless. <br><br>I actually did see that a long time ago that 2 (chinese?) people claimed to have "broken" the MD5 algorithm (they claimed they were able to determine collisions or something like that...). They never posted any evidence, just that they broke it. Here it is, what a couple years later, I haven't seen a story on how MD5 is really broken, have you? What makes that even more of a laugh is that MD5 isn't an encryption, its just a hash algorithm. What makes THIS story a laugh too is that MD6 was talked about a long time and <A HREF="http://groups.csail.mit.edu/cis/md6/">seems</a> to be available for your greedy downloading hands.<br>My question I propose to you:<br>If MD6 is available, why not use THAT in certificates instead of MD5? <b>After all, don't we trust in CA's to keep our sites and data secure and encrypted?</b> I know I sure don't for my own sites/services (you might be like "wtf?", but I am coming with a solution to that).<br><br>In my conclusion, its merely just a response to increase of technology. Its like saying you can find the prime numbers to a 20 digit (I don't know, some obscene number) composite number in a matter of seconds on a quad core, with 64bit os with 4GBs of RAM. Yeah, its defiantly going to make that large number look like nothing on modern technology, but when the number was put out there - the technology at the time couldn't handle it. So - there's nothing to see here, move along.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21670778</guid>
<pubDate>Fri, 02 Jan 2009 15:34:50 EDT</pubDate>
</item>

<item>
<title>Re: KARL, YOU ARE WRONG.</title>
<link>http://www.dslreports.com/forum/remark,21669579</link>
<description><![CDATA[<A HREF="/useremail/u/118623"><b>MxxCon</b></A> : they never CLAIMED to have found a method of hacking any website either.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21669579</guid>
<pubDate>Fri, 02 Jan 2009 11:28:24 EDT</pubDate>
</item>

<item>
<title>Re: KARL, YOU ARE WRONG.</title>
<link>http://www.dslreports.com/forum/remark,21669525</link>
<description><![CDATA[<A HREF="/useremail/u/891765"><b>Cheese</b></A> : <div class="bquote"><small>said by  MxxCon <A HREF="/useremail/u/118623"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>how can you post a story without even reading it?!<br><b>THEY NEVER SAID THEY "have found a method of hacking any website".</b><br><br>what they did say was that they <b>"found a way to forge certain digital certificates"</b><br><br>THAT'S A HUGE DIFFERENCE.<br><br>your own link to our forum says &raquo;<A HREF="/forum/r21655254-SSL-security-flaw-with-MD5-certificates-announces-today">SSL security flaw with MD5 certificates announces today</A> that's nothing even close to "hacking any website"<br><br><blockquote><strong>KARL, STOP SPREADING FUD!</strong></blockquote><br> </div>And the article says CLAIM, not they they DID, can YOU read?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21669525</guid>
<pubDate>Fri, 02 Jan 2009 11:17:55 EDT</pubDate>
</item>

<item>
<title>KARL, YOU ARE WRONG.</title>
<link>http://www.dslreports.com/forum/remark,21669455</link>
<description><![CDATA[<A HREF="/useremail/u/118623"><b>MxxCon</b></A> : how can you post a story without even reading it?!<br><b>THEY NEVER SAID THEY "have found a method of hacking any website".</b><br><br>what they did say was that they <b>"found a way to forge certain digital certificates"</b><br><br>THAT'S A HUGE DIFFERENCE.<br><br>your own link to our forum says &raquo;<A HREF="/forum/r21655254-SSL-security-flaw-with-MD5-certificates-announces-today">SSL security flaw with MD5 certificates announces today</A> that's nothing even close to "hacking any website"<br><br><blockquote><strong>KARL, STOP SPREADING FUD!</strong></blockquote><br><small>--<br>Check out my awesome city of MxxTopia &raquo;<A HREF="http://mxxtopia.myminicity.com/ind" >mxxtopia.myminicity.com/ind</A>  or &raquo;<A HREF="http://mxxtopia.myminicity.com" >mxxtopia.myminicity.com</A> (the more people visit, the bigger it is)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21669455</guid>
<pubDate>Fri, 02 Jan 2009 10:59:20 EDT</pubDate>
</item>

</channel>
</rss>
