Article 10BSS US military still SHAckled to outdated DoD PKI infrastructure (Netcraft)

US military still SHAckled to outdated DoD PKI infrastructure (Netcraft)

by
ris
from LWN.net on (#10BSS)
Netcraft reportsthat the US Department of Defense (DoD) is still issuing SHA-1 signedcertificates, and using them to secure connections to .mil websites."The DoD is America's largest government agency, and is tasked with protecting the security of its country, which makes its continued reliance on SHA-1 particularly remarkable. Besides the well known security implications, this reliance could already prove problematic amongst the DoD's millions of employees. For instance, Mozilla Firefox 43 began rejecting all new SHA-1 certificates issued since 1 January 2016. When it encountered one of these certificates, the browser displayed an Untrusted Connection error, although this could be overridden. If DoD employees become accustomed to ignoring such errors, it could become much easier to carry out man-in-the-middle attacks against them."
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments