Re: [cryptography] Microsoft Sub-CA used in malware signing

2012-06-10 Thread Weger, B.M.M. de
Hi Florian, * Marsh Ray: Marc Stevens and B.M.M. de Weger (of http://www.win.tue.nl/hashclash/rogue-ca/) have been looking at the collision in the evil CN=MS cert. I'm sure they'll have a full report at some point. Until then, they have said this: [We] have confirmed that flame

Re: [cryptography] Microsoft Sub-CA used in malware signing

2012-06-10 Thread Marsh Ray
On 06/10/2012 03:03 PM, Florian Weimer wrote: Does this mean they've seen the original certificate in addition to the evil twin? Until then, there is another explanation besides an advance in cryptanalysis. Just saying. 8-) I guess I look at it like this: Start with the simplest