SSL broken! Hackers create rogue CA certificate using MD5 collisions

Status
Not open for further replies.

NucleusKore

TheSaint
Source: *blogs.zdnet.com/security/?p=2339

Using computing power from a cluster of 200 PS3 game consoles and about $700 in test digital certificates, a group of hackers in the U.S. and Europe have found a way to target a known weakness in the MD5 algorithm to create a rogue Certification Authority (CA), a breakthrough that allows the forging of certificates that are fully trusted by all modern Web browsers.

The research, which will be presented today by Alex Sotirov (top left) and Jacob Appelbaum (bottom left) at the 25C3 conference in Germany, effectively defeats the way modern Web browsers trust secure Web sites and provides a way for attackers to conduct phishing attacks that are virtually undetectable.

Read On..........
 

RCuber

The Mighty Unkel!!!
Staff member
^^ if we look at history , SSL was just surfacing in 1993 , and by 1996 it started to show some strength.. so it took hackers about 12-13 years to crack it :p . Are they One step ahead? :D :p ;)
 

gary4gar

GaurishSharma.com
^^ if we look at history , SSL was just surfacing in 1993 , and by 1996 it started to show some strength.. so it took hackers about 12-13 years to crack it :p . Are they One step ahead? :D :p ;)
I am talking in General.

see tell me, one example of any un-hackable system?
if you tell, then i would be your follower, uncle ji :p :lol:
 

Sukhdeep Singh

Host4Cheap.org
^^ if we look at history , SSL was just surfacing in 1993 , and by 1996 it started to show some strength.. so it took hackers about 12-13 years to crack it :p . Are they One step ahead? :D :p ;)

Blame it on Sony for coming so late with PS3 Processor Power:D
 
Great. Now all the hacker needs is 200 PS3s to hack a bank.
Considering the price of a PS3, he'll be better off looting the bank at gun point than to go through that effort.
 

comp@ddict

EXIT: DATA Junkyard
Hackers r always 1 step ahead - just like torrent guys, u get movies and games the day b'fore or the day of release.
 

Vishal Patil

Linux all the way
there's nothing that cannot be cracked... updating technology is the only was to ensure that yiou stay safe from attacks. As computing power increases so does the need for make security changes..
 

MitchNelson

Right off the assembly line
Verising has resolve the issue much faster then expected. It was MD5 Signature which was cracked. Now, they are offering SHA-1 sing certificate.

Also, you cannot say its cracked because they have not broke the certificate in between and try for Man in Middle attack. Its only that they have created fake certificate which looks like RapidSSL certificate.

:eek::):D:-D:mrgreen:
 
Status
Not open for further replies.
Top Bottom