Re: Notes on openssh configuration

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



Hello Gordon,

On Fri, 2017-01-27 at 10:26 -0800, Gordon Messmer wrote:
> Cryptographers still consider MD5 secure for HMAC use. Wikipedia's 
> references (currently 6, 7, and 8) in this article are useful:
> 
> https://en.wikipedia.org/wiki/Hash-based_message_authentication_code

https://en.wikipedia.org/wiki/MD5 seems to disagree:

"The security of the MD5 has been severely compromised, with its
weaknesses having been exploited in the field, most infamously by the
Flame malware in 2012. The CMU Software Engineering Institute considers
MD5 essentially "cryptographically broken and unsuitable for further
use"."

SHA-1 is not as severely broken as MD5, so the argument that Schneier
made in 2009 that SHA-1 is still suitable as a HMAC cannot necessarily
be extended to MD5.

Regards,
Leonard.

-- 
mount -t life -o ro /dev/dna /genetic/research


_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
https://lists.centos.org/mailman/listinfo/centos



[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux