News

Oracle says that starting with April 18, 2017, Java (JRE) will treat all JAR files signed with the MD5 algorithm as unsigned, meaning they'll be considered insecure and blocked from running.
The research is significant because there are at least six CAs currently using the weak MD5 cryptographic algorithm in digital signatures and certificates.
Flame attackers' ability to forge a valid certificate for Windows Update should be a warning to companies to stop using the MD5 algorithm to issue security certificates.
The MD5 algorithm has a new vulnerability: Google! Here’s a piece of news that will worry anyone interested in security (which should be pretty much everyone who reads Network World): A ...
At the 25th Chaos Communication Congress (CCC) today, researchers will reveal how they utilized a collision attack against the MD5 algorithm to create a rogue certificate authority. This is pretty ...
Fatally weak MD5 function torpedoes crypto protections in HTTPS and IPSEC MD5 and its only slightly stronger SHA1 cousin put world on collision course.
The algorithm in question, called MD5, is one of the standard choices that programmers use when creating digital signatures. But some research has suggested attacks on MD5 (though those attacks ...
Viber flipped the switch for end-to-end encryption on Wednesday, but experts worried it may have used the cryptographically insecure MD5 algorithm. In response, Viber said that it did not use MD5 ...
Microsoft has given customers six months to find MD5 installations and prepare for a February 2014 patch that will block the broken algorithm.
Crypto attack that hijacked Windows Update goes mainstream in Amazon Cloud Collision attack against widely used MD5 algorithm took 10 hours, cost just 65 cents.