2010-06-11 10:54:17
On Fri, 11 Jun 2010, Peter Gutmann wrote:

I assume you're thinking of IE6 there :-).  Was the fix done in CryptoAPI or
in the browser itself?  If it was an update to CryptoAPI then even IE6 should
be OK (can anyone from MS comment on this?).

I *think* the fix was in CryptoAPI. Dan was the one who notified the vendors (OpenSSL, Mozilla, Verisign, etc.) about the MD2 signature transfer problem as well as the other flaws, so he'd be the person to ask (unless someone from MS wants to chime in.)

