mgomes / api_auth

HMAC authentication for Rails and HTTP Clients
MIT License
480 stars 147 forks source link

retire MD2 and MD4 #134

Closed will0 closed 7 years ago

will0 commented 7 years ago

MD2 is retired MD4 is retired further argument against MD4

In particular the linked pdf demonstrates a key recovery attack against MD4. This is from '06 so the state of the art is likely advanced.

mgomes commented 7 years ago

@will0 and @kjg thanks guys! 🙌