<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MD5 hash collision gets people worried about PKI</title>
	<atom:link href="http://ajaxian.com/archives/md5-hash-collision/feed" rel="self" type="application/rss+xml" />
	<link>http://ajaxian.com/archives/md5-hash-collision</link>
	<description>Cleaning up the web with Ajax</description>
	<lastBuildDate>Thu, 17 May 2012 07:43:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: shadedecho</title>
		<link>http://ajaxian.com/archives/md5-hash-collision/comment-page-1#comment-270182</link>
		<dc:creator>shadedecho</dc:creator>
		<pubDate>Wed, 31 Dec 2008 18:21:25 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5535#comment-270182</guid>
		<description>The article also makes the important point that SHA-1 (while not YET proven to be broken) should be similarly distrusted and phased out, in favor of SHA-2 (or something equivalent or better).
.
Everyone should check out their own certificates&#039; encryption algorithm (easily explained how near the end of that article) and make sure you are comfortable with the level of protection it provides based on the premise of the paper (ie, not MD5, and preferably not even SHA-1).
.
GoDaddy is who I use, and my two certificates are both SHA-1. I&#039;ve sent them a request asking them to consider upgrading to SHA-2 and re-issuing my certificates.
.
I hope others will pay similar attention and make requests to their providers as they feel necessary. This is quite necessary (especially for those of MD5).</description>
		<content:encoded><![CDATA[<p>The article also makes the important point that SHA-1 (while not YET proven to be broken) should be similarly distrusted and phased out, in favor of SHA-2 (or something equivalent or better).<br />
.<br />
Everyone should check out their own certificates&#8217; encryption algorithm (easily explained how near the end of that article) and make sure you are comfortable with the level of protection it provides based on the premise of the paper (ie, not MD5, and preferably not even SHA-1).<br />
.<br />
GoDaddy is who I use, and my two certificates are both SHA-1. I&#8217;ve sent them a request asking them to consider upgrading to SHA-2 and re-issuing my certificates.<br />
.<br />
I hope others will pay similar attention and make requests to their providers as they feel necessary. This is quite necessary (especially for those of MD5).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ilazarte</title>
		<link>http://ajaxian.com/archives/md5-hash-collision/comment-page-1#comment-270180</link>
		<dc:creator>ilazarte</dc:creator>
		<pubDate>Wed, 31 Dec 2008 16:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5535#comment-270180</guid>
		<description>Maybe this is why Pownce never supported SSL, it&#039;s all broken anyways!</description>
		<content:encoded><![CDATA[<p>Maybe this is why Pownce never supported SSL, it&#8217;s all broken anyways!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

