-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/487/rsa-signature-forgery-explained-with-nate-lawson-part-ii/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
a) switched to OAEP ?
b) implemented OAEP correctly ?
c) refused to trust anyone who uses a low exponent ?
At least, if we trust the random oracle model, we have something relatively strong in our hands (OAEP). I am consistently surprised that the migration away from other, clearly weaker message padding schemes isn't happening more quickly.
Cheers,
Halvar
They add a screwball symmetric algorithm like SEED, yet they can't be bothered to add suites that use SHA-256, SHA-512, Whirlpool, or Tiger, even when there was speculation that SHA-1 would be next to fall when MD5 attacks were announced a couple years ago?