4 ms·
yeah that wouldn't be fun, but maybe we could make a browser add-on to check for the md5 checksum, not a security expert here but sounds like a solution to me
by mrpollo 14y ago
yeah that wouldn't be fun, but maybe we could make a browser add-on to check for the md5 checksum, not a security expert here but sounds like a solution to me
- ars 14y agoMD5 is not acceptable for this purpose since it's possible to create source with the same MD5 as the original. It would need a different hash at a minimum.
- taylorfausak 14y agoI'm not sure what you mean by this. mrpollo recommended using MD5 as a checksum before executing jQuery to ensure that the CDN hasn't been compromised. For instance jQuery 1.8.0's checksum is cd8b0bffc85bb5614385ee4ce3596d07. I was under the impression that MD5 isn't malleable enough to create a non-trivial malicious script with the same hash.
- ars 14y agoAs of right now there are no practical preimage attacks on MD5, but people keep expecting one. It's better to switch to something else and not have to worry about it.
- dalke 14y agoYour impression is incorrect. Quoting one researcher, "Our intent is to raise awareness that MD5 is broken so drastically that its continued use in digital signature schemes and certificates poses realistic threats." See also http://en.wikipedia.org/wiki/MD5 http://en.wikipedia.org/wiki/MD5 . I am no expert. It may be that MD5 is still relatively secure for this specific task. However, SHA2 is more secure. Use that instead.