Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, OK. My read was that the certs granted by the Enforced Licensing thing were able to sign code. Your explanation makes a ton of sense to me. They just forgot to audit for MD5-based keys and left this alive in the wild.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: