· @mtjm
6 followers · 40 posts · Server m.mtjm.eu

I don't understand why ever supported . SSL since 2.0 already used MD5 and other safer hashes, the MD4 RFC recommended MD5 for securer uses in 1992. rfc-editor.org/rfc/rfc6150 does not mention any TLS-related uses of MD4.

If it was fiction, I'd choose the Doylist explanation that OpenSSL needed to add MD4 support in 2000 so could move to it in 2018. (For filename hashing with no likely security impact, but using a library that would later drop its support.)

#openssl #MD4 #Webpack

Last updated 3 years ago