3 ms·
Flickr's API Signature Forgery Vulnerability
- DrewHintz 17y agoCan we please stop using MD5?
- juli 17y agoMD5 is not the problem here, SHA1 is also vulnerable to the extension attack. They should use HMAC.
- nopal 17y agoDoes anyone know what Flickr did to address this vulnerability? They didn't move to using HMAC. Are they just filtering 0x80 and 0x00?