US Military Websites Still Relying On SHA-1

DEAD7

Veteran
Supporter
Joined
Oct 5, 2012
Messages
51,522
Reputation
4,669
Daps
89,815
Reppin
Fresno, CA.
Netcraft confirms many U.S. Department of Defense websites, including a remote access service used by the Missile Defense Agency, are more vulnerable to man-in-the-middle attacks than most consumer websites. The weaker than previously-thought SHA-1 algorithm is the main culprit, with the DoD today being the most prolific user of SHA-1 signed SSL certificates, even though NIST banned new use of this signature algorithm two years ago. Most of the vulnerable certificates to be issued recently are used by .mil websites, which are operated by agencies, services and divisions of the DoD. All of these sites are consequently vulnerable to attack by enemy governments and criminals who can stump up enough cash ($75,000) to crack the certificates.
 

TRFG

Not who you think
Joined
Mar 7, 2014
Messages
13,798
Reputation
240
Daps
38,518
:ohhh:
Bitcoin wallets are using SHA-256:mjlol:
 
Top