@whispersystems Hey, you ARE pinning the flock TLS cert right? Also you should fix the rest of this stuff https://www.ssllabs.com/ssltest/analyze.html?d=flock-sync.whispersystems.org&s=54.244.91.66&latest …
-
-
Replying to @kyhwana
@kyhwana Ugh, for apps@whispersystems controls, why is most of that even ON?! Twisted defaults? Also, WTF 27-year SHA1 certificate?3 replies 0 retweets 0 likes -
Replying to @sindarina
@sindarina The server is its own authority. Makes no difference what the sig hash is or how long the expiration is.@kyhwana2 replies 0 retweets 0 likes -
Replying to @signalapp
@whispersystems@sindarina how does it not matter if someone can generate a self signed cert with the same SHA1? How are you pinning?3 replies 0 retweets 0 likes
Replying to @kyhwana
@kyhwana The SHA1 scenario you're describing is a "second pre-image" attack, not a "collision attack." That's 2^159 hard. @sindarina
1:15 PM - 27 Apr 2015
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.