Re: StartCom issuing bogus certificates

2017-05-31 Thread Yuhong Bao via dev-security-policy
ailto:yuhongbao_...@hotmail.com>> Cc: mozilla-dev-security-pol...@lists.mozilla.org<mailto:mozilla-dev-security-pol...@lists.mozilla.org>; Matthew Hardeman mailto:mharde...@gmail.com>> Subject: Re: StartCom issuing bogus certificates On Wed, May 31, 2017 at 05:09:57PM +, Yuhong Bao

Re: StartCom issuing bogus certificates

2017-05-31 Thread Yuhong Bao via dev-security-policy
The point is that "misissuance" of example.com is harmless as they are reserved by IANA. From: dev-security-policy on behalf of Matthew Hardeman via dev-security-policy Sent: Wednesday, May 31, 2017 10:08:10 AM To: mozilla-dev-security-pol...@lists.moz

Re: StartCom issuing bogus certificates

2017-05-31 Thread Yuhong Bao via dev-security-policy
It would be better to use example.com and not test.com or anything like that, as that is defined by IANA as a reserved domain. From: dev-security-policy on behalf of Inigo Barreira via dev-security-policy Sent: Wednesday, May 31, 2017 9:21:00 AM To: pa

Re: SHA-1 collision

2017-02-23 Thread Yuhong Bao via dev-security-policy
identical prefix, not chosen prefix. I was more interested in an SHA-1 collision ASIC. From: dev-security-policy on behalf of Adrian R. via dev-security-policy Sent: Thursday, February 23, 2017 8:26:10 AM To: mozilla-dev-security-pol...@lists.mozilla.o