HN user

stubborndude

8 karma
Posts0
Comments2
View on HN
No posts found.

Random guess - this is probably because many people have a their homepage as a SSL'd google site. In order to be able to show the "login or pay" message to someone when they fire up their browser, Gogo needs to have a cert to communicate over 443 without the browser refusing to display a page.

Not condoning the practice, but thats my guess at the motivation. I also imagine it doesn't work very well, as many new browsers will refuse to display if the cert chain is broken.

Was going to make this point. But lets instead talk about the endorsement aspect, because lots of people in the forensic community take the "its popular so i use them, but i neither endorse nor oopose" position.

There is certainly risk of hash collisions in files, but most attacks require you to generate two different files with the same hash? Do people think a pre-image attack is feasible? If feasible, at what scale? What type of actor can give me a file that has different content, but the same hash as winword.exe. If they can, what is the likelihood that said file will also be executable or contain a linkable library

*similarly, and hypocritically, not an endorsement of md5