Skip to main content

Verisign Discontinues Flawed MD5 Certificates

posted onJanuary 1, 2009
by hitbsecnews

Verisign (NSDQ:VRSN) Inc. is getting rid of its MD5 digital certificates a month early after researchers revealed that an exploitable flaw in the algorithm could allow hackers to impersonate a banking or retail Web site and steal customers' financial data.

Mountain View, Calif.-based Verisign, a managed security service provider, said that it has immediately discontinued the flawed MD5 cryptographic function used for digital signatures, while offering a free transition for customers to move to the more secure RapidSSL brand certificates using the SHA-1 algorithm.

"We applaud this team's research and efforts to improve online security as well as their disclosure of the findings for the benefit of the broader Internet community," said Chris Babel, Verisign SVP and general manager. "We take issues like these very seriously and work quickly to remedy vulnerabilities that could potentially affect trust and security online."

Source

Tags

Industry News

You May Also Like

Recent News

Monday, May 20th

Thursday, May 16th

Wednesday, May 15th

Tuesday, May 14th

Monday, May 13th

Friday, May 10th

Thursday, May 9th

Wednesday, May 8th