<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Daemonic Dispatches - Latest Comments in AWS signature version 1 is insecure</title><link>http://daemonicdispatches.disqus.com/</link><description></description><atom:link href="https://daemonicdispatches.disqus.com/aws_signature_version_1_is_insecure/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 08 Nov 2010 17:00:01 -0000</lastBuildDate><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-95179177</link><description>&lt;p&gt;very interesting article .. Thank you.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mohammed Ali</dc:creator><pubDate>Mon, 08 Nov 2010 17:00:01 -0000</pubDate></item><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-10262211</link><description>&lt;p&gt;Besides using SSL - I thought amazon(like google) had timestamp added as part of request - and hence it could be mis-used only in the next 15 minutes.(assuming in the&lt;br&gt;rare case - someone got hold of the request)&lt;br&gt;&lt;a href="http://docs.amazonwebservices.com/AWSFWS/latest/DeveloperGuide/index.html?SummaryOfAuthentication.html" rel="nofollow noopener" target="_blank" title="http://docs.amazonwebservices.com/AWSFWS/latest/DeveloperGuide/index.html?SummaryOfAuthentication.html"&gt;http://docs.amazonwebservic...&lt;/a&gt;&lt;br&gt;Its better or easier to use then client side certs anyway.(and as secure as it is if the "request" is changing)&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">guest</dc:creator><pubDate>Fri, 29 May 2009 12:17:06 -0000</pubDate></item><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-6327113</link><description>&lt;p&gt;I don't think that's ever specified; but there are no AWS requests for which it's valid to specify the same parameter twice.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">cperciva</dc:creator><pubDate>Tue, 17 Feb 2009 05:57:33 -0000</pubDate></item><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-6277772</link><description>&lt;p&gt;What about multiple keys? How do they sort foo=bar&amp;amp;foo=blaggy ?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris</dc:creator><pubDate>Sun, 15 Feb 2009 14:00:02 -0000</pubDate></item><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-4485698</link><description>&lt;p&gt;Very cool good find, I will be checking to make sure all our endpoints are https&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan_Mayer</dc:creator><pubDate>Thu, 18 Dec 2008 13:45:37 -0000</pubDate></item><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-4477705</link><description>&lt;p&gt;Thanks for posting this!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">curi</dc:creator><pubDate>Thu, 18 Dec 2008 03:39:44 -0000</pubDate></item><item><title>Re: AWS signature version 1 is insecure</title><link>http://www.daemonology.net/blog/2008-12-18-AWS-signature-version-1-is-insecure.html#comment-4477639</link><description>&lt;p&gt;It's very nice to see both act reasonably and rationally in action. It's the kind of situation that should be held as an example. =)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Francis</dc:creator><pubDate>Thu, 18 Dec 2008 03:27:41 -0000</pubDate></item></channel></rss>