https://www.kb.cert.org/vuls/id/836068

<https://www.kb.cert.org/vuls/id/836068>Nothing new should have been using 
MD5 for a looong time, and people need to know to stay away from it.

Fake SSL certs that exploit this have been produced. It's not just a 
theoretical concern.

On Tuesday, May 10, 2011 12:52:24 AM UTC-7, Nikolay Elenkov wrote:
>
> On Tue, May 10, 2011 at 3:59 PM, gjs <[email protected]> wrote:
>
> > http://developer.android.com/reference/java/security/MessageDigest.html
> >
> > MD5 is weaker than SHA
> >
>
> Qualify 'weaker'. See above.
>
>

-- 
You received this message because you are subscribed to the Google
Groups "Android Developers" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/android-developers?hl=en

Reply via email to