<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Matasano Chargen - Latest Comments in RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://matasanochargen.disqus.com/</link><description></description><atom:link href="https://matasanochargen.disqus.com/rsa_signature_forgery_explained_with_nate_lawson_part_iv/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 25 Sep 2006 15:41:48 -0000</lastBuildDate><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320548</link><description>&lt;p&gt;Matt:&lt;/p&gt;&lt;p&gt;I'm unaware of any changes in the root certs.  We won't know for another 3-6 months, my guess.  It takes a while for them to make a CRL, get it into IE and Firefox, etc.&lt;/p&gt;&lt;p&gt;The tone we used was more one of wishful thinking than future certainty.  :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nate</dc:creator><pubDate>Mon, 25 Sep 2006 15:41:48 -0000</pubDate></item><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320547</link><description>&lt;p&gt;nice. :-)&lt;/p&gt;&lt;p&gt;I am by no means a security specialist, but I love your blog and find it VERY interesting. Keep up the excelent work.&lt;/p&gt;&lt;p&gt;-Emmanuel&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Emmanuel Leroux Sanders</dc:creator><pubDate>Tue, 19 Sep 2006 12:37:51 -0000</pubDate></item><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320546</link><description>&lt;p&gt;Great summary Thomas, thanks for taking the time to fill in the blanks.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William</dc:creator><pubDate>Tue, 19 Sep 2006 10:55:51 -0000</pubDate></item><item><title>Re: RSA Signature Forgery Explained (with Nate Lawson) - Part IV</title><link>http://www.matasano.com/log/501/rsa-signature-forgery-explained-with-nate-lawson-part-iv/#comment-2320545</link><description>&lt;blockquote&gt;However, we have started eliminating the few e=3 root certificates. That was a good idea.&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Are the commercial CAs which deployed e=3 root certs (Entrust, &lt;strike&gt;Digital Signature Trust Co.&lt;/strike&gt; IdenTrust, others?) known to be doing anything about this snafu?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Mon, 18 Sep 2006 15:57:25 -0000</pubDate></item></channel></rss>