On 04/10/17 23:38, Nick Lamb wrote: > However if I understand the situation correctly, this situation is > already very low risk anyway with no reasonable expectation that it > could be exploited against a competent SSL/TLS client which for some > reason still accepts SHA1 and of course no risk for e.g. modern > Firefox which doesn't accepts SHA1 anyway. If I haven't understood > (please anyone jump in) then my assessment may be utterly wrong.
Of course, this is an argument for ceasing to regulate SHA-1 issuance at all, because no modern browser accepts it, so why bother? But I don't think we are quite ready to go there; it does have the useful secondary effect of going some way to force obsolete software (like old XP) off the Internet. Gerv _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

