MD5 seems not safe for code signing
December 3, 2007 – 5:19 pmThis paper presents a method for creating the same MD5 hash for different executables - thus beating the idea of identifying executables by comparing their MD5 hashes to stored values.
This paper presents a method for creating the same MD5 hash for different executables - thus beating the idea of identifying executables by comparing their MD5 hashes to stored values.
http://euedge.com/blog/2007/12/03/md5-seems-not-safe-for-code-signing/trackback