- http://www.win.tue.nl/~bdeweger/CollidingCertificates/
- http://eprint.iacr.org/2005/067.pdf
- http://www.computing.dcu.ie/~coheigeartaigh/presentations/redbrick_talk.pdf
Don’t start any FUD please, this attack can be thwarted since it requires you know the templates of the certificates and as most serial numbers are long enough randoms or created via a secret, this will mostly foil this as I understand it.


No Comment Received
Leave A Reply