http://arstechnica.com/security/2016/01/fatally-weak-md5-function-torpedoes-crypto-protections-in-https-and-ipsec/ (The referenced paper is embargoed behind a password at the moment) I believe after Heartbleed and Poodle I have purged MD5 but now I'm not sure. Have to wait for the paper to open up again and find out.