Ok I guess I was more tired than I thought when I posted the previous;
I now wish to tone down my original post a bit as it just now occures to me that pretty much everyone use data integrity with their esp as almost all vpn concentrators/clients by default use at minimum md5 for integrity algorithm (and quite a few of us turn it up to sha-1 when configuring tunnels...).
So while the discovery of the weakness is still relatively big news, it's not as alarming as I had led myself to believe....
Ammo




Reply With Quote