Skip to main content

Verisign Discontinues Flawed MD5 Certificates

posted onJanuary 1, 2009
by hitbsecnews

Verisign (NSDQ:VRSN) Inc. is getting rid of its MD5 digital certificates a month early after researchers revealed that an exploitable flaw in the algorithm could allow hackers to impersonate a banking or retail Web site and steal customers' financial data.

Mountain View, Calif.-based Verisign, a managed security service provider, said that it has immediately discontinued the flawed MD5 cryptographic function used for digital signatures, while offering a free transition for customers to move to the more secure RapidSSL brand certificates using the SHA-1 algorithm.

"We applaud this team's research and efforts to improve online security as well as their disclosure of the findings for the benefit of the broader Internet community," said Chris Babel, Verisign SVP and general manager. "We take issues like these very seriously and work quickly to remedy vulnerabilities that could potentially affect trust and security online."

Source

Tags

Industry News

You May Also Like

Recent News

Wednesday, May 8th

Tuesday, May 7th

Monday, May 6th

Friday, May 3rd

Thursday, May 2nd

Wednesday, May 1st

Tuesday, April 30th