PrntRhd
01-02-2009, 03:02 PM
This is a discovered flaw that attacks the certification process even for SSL, and now that researchers showed the exploit is possible Verisign is changing how it generates hashes:
http://www.freedom-to-tinker.com/blog/felten/researchers-show-how-forge-site-certificates
http://www.freedom-to-tinker.com/blog/felten/researchers-show-how-forge-site-certificates