SLOTH
lorecryptography
A 2016 set of attacks abusing obsolete hashes like MD5 in TLS negotiation.
Security Losses from Obsolete and Truncated Transcript Hashes showed that allowing weak hashes such as MD5 in TLS signatures enabled transcript-collision and downgrade attacks. It pushed removal of MD5-based signatures from TLS.
Also known as: SLOTH, Security Losses from Obsolete and Truncated Transcript Hashes
Sources
- SLOTH attack (2016)