On 04/10/17 23:38, Nick Lamb wrote:
> However if I understand the situation correctly, this situation is
> already very low risk anyway with no reasonable expectation that it
> could be exploited against a competent SSL/TLS client which for some
> reason still accepts SHA1 and of course no risk for e.g. modern
> Firefox which doesn't accepts SHA1 anyway. If I haven't understood
> (please anyone jump in) then my assessment may be utterly wrong.

Of course, this is an argument for ceasing to regulate SHA-1 issuance at
all, because no modern browser accepts it, so why bother? But I don't
think we are quite ready to go there; it does have the useful secondary
effect of going some way to force obsolete software (like old XP) off
the Internet.

Gerv
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to