An attempt to backdoor the kernel
Posted Nov 7, 2003 18:55 UTC (Fri) by
zooko (subscriber, #2589)
In reply to:
An attempt to backdoor the kernel by lm
Parent article:
An attempt to backdoor the kernel
If you can find collisions in SHA-1, you can probably use that to forge digital signatures and gain remote authorizations to any system that uses cryptography for authentication. (This includes, among others, any system which uses SSH, TLS, or a cryptographically authenticated VPN.)
Is it a lawsuit waiting to happen to run sshd?
(
Log in to post comments)