3 ms·
Though annoyingly it's signed using sha1, not sha256. So if they were gonna put effort into making an sha1 collision, they'd probably target the signed payload
by warbiscuit 10y ago
Though annoyingly it's signed using sha1, not sha256.
So if they were gonna put effort into making an sha1 collision, they'd probably target the signed payload, not the overall exe.
Though it doesn't look like sha1 is that broken yet, for the budget of this grade of attacker.