Playing With Authenticode and MD5 Collisions
I will not post the whole post, as it is not my invention nor my labor, but can’t pass without posting it.. the work is so fascinating, it bugs my mind why has nobody thought of this when designing the signing process? Like, the possibility of MD5 collisions is there for a few years… and I’m more than sure the guys at M$ knew of the issue, but preferred to keep silent about it, hoping it will pass unnoticed… well it didn’t.
What are they gonna do about it now?
http://blog.didierstevens.com/2009/01/17/playing-with-authenticode-and-md5-collisions/
