may not be as bad as it appears
Posted Aug 18, 2004 18:02 UTC (Wed) by
ajax (guest, #7251)
Parent article:
Crypto researchers abuzz over flaws (News.com)
Generally speaking, an alternate file generating the same MD5
checksum will look like gibberish rather than English or a
C program or whatever. So, for example, if one
download's what one thinks is apache sources, and the checksums
match, and the source looks like apache, then one could have
confidence that it is the unmodified Apache, even if MD5
proves to be flawed.
(
Log in to post comments)