GnuPG 2.1.0 "modern" released
GnuPG 2.1.0 "modern" released
Posted Nov 13, 2014 9:00 UTC (Thu) by dd9jn (✭ supporter ✭, #4459)In reply to: GnuPG 2.1.0 "modern" released by dlang
Parent article: GnuPG 2.1.0 "modern" released
You encrypted to my old public key and thus I can I can decrypt it with my old secret key and encrypt it again to my current public key.
Right, signed mails should be considered unsigned. We can't claim that SHA-1 is broken (which it is currently not) to an extend that Mozilla will soon reject TLS connections made with SHA-1 and at the same time keep on using and trusting MD5 which is known to be weak for 20 years, has easy to create collisions for 8 years, and pre-image attacks are known for 3 or 4 years.
(and yes, I can't understand why ssh still defaults to MD5 fingerprints)
