The MM5 installer is signed using an outdated algorithm [#18179]

Post a reply

Smilies
:D :) :( :o :-? 8) :lol: :x :P :oops: :cry: :evil: :roll: :wink:

BBCode is ON
[img] is ON
[url] is ON
Smilies are ON

Topic review
   

Expand view Topic review: The MM5 installer is signed using an outdated algorithm [#18179]

Re: The MM5 installer is signed using an outdated algorithm

by Peke » Sun Aug 01, 2021 10:04 am

The MM5 installer is signed using an outdated algorithm [#18179]

by TIV73 » Sun Aug 01, 2021 4:13 am

Hi,
I was waiting for update 5.0.1 to replace MM4 as my main day-to-day music player (congratulations on the release!) and noticed that both the regular and debug installer are signed using sha1 which has been deprecated for https encryption and code signing by all major authorities (including the issuer of the cert used by the MM5 installer) a couple of years ago and is not considered safe anymore.

Please note that the actual certificate itself already uses sha384, it's just applied to the installer using digest algorithm sha1. While that's not a immediate dealbreaker I probably wouldn't call it best practice.

Top