[cabfpub] SHA-1 Collision Found

Gervase Markham gerv at mozilla.org
Fri Feb 24 21:08:33 UTC 2017

On 24/02/17 11:56, Ryan Sleevi via Public wrote:
> The value of (4) depends on two things - the security analysis of the
> algorithm itself (which is done in (1)), and the industry balancing of
> risks (which is done in (3)).

That sounds like you agree that a CAB Forum motion with a Statment of
Intent, or even a change to the BRs to list some additional algorithms,
is in fact the next step?


