<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Mon, 25 Sep 2006 15:41:48 -0000</lastBuildDate><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320548</link><description>Matt:&lt;br&gt;&lt;br&gt;I'm unaware of any changes in the root certs.  We won't know for another 3-6 months, my guess.  It takes a while for them to make a CRL, get it into IE and Firefox, etc.&lt;br&gt;&lt;br&gt;The tone we used was more one of wishful thinking than future certainty.  :)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nate</dc:creator><pubDate>Mon, 25 Sep 2006 15:41:48 -0000</pubDate></item><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320547</link><description>nice. :-)&lt;br&gt;&lt;br&gt;I am by no means a security specialist, but I love your blog and find it VERY interesting. Keep up the excelent work.&lt;br&gt;&lt;br&gt;-Emmanuel</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Emmanuel Leroux Sanders</dc:creator><pubDate>Tue, 19 Sep 2006 12:37:51 -0000</pubDate></item><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320546</link><description>Great summary Thomas, thanks for taking the time to fill in the blanks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William</dc:creator><pubDate>Tue, 19 Sep 2006 10:55:51 -0000</pubDate></item><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320545</link><description>&lt;blockquote&gt;However, we have started eliminating the few e=3 root certificates. That was a good idea.&lt;/blockquote&gt;&lt;br&gt;&lt;br&gt;Are the commercial CAs which deployed e=3 root certs (Entrust, &amp;lt;strike&amp;gt;Digital Signature Trust Co.&amp;lt;/strike&amp;gt; IdenTrust, others?) known to be doing anything about this snafu?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Mon, 18 Sep 2006 15:57:25 -0000</pubDate></item></channel></rss>