, 2009-01-05
A few days ago at the Chaos Communication Congress in Berlin, researchers presented a paper in which they had used an MD5 collision attack and substantial computing firepower to create a false SSL certificate using the RapidSSL brand of SSL certificate. In the intervening time we have seen a great deal of confusion and misinformation in the press and blogosphere about the specifics of this attack and what it means to the online ecosystem.
Expand all |
Post comment
MD5 Hack Interesting, But Not Threatening
2009-01-06
Charlie Miller (1 replies)
Charlie Miller (1 replies)
Re: MD5 Hack Interesting, But Not Threatening
2009-01-06
Robert Lemos (5 replies)
Robert Lemos (5 replies)
Verisign were notified about this work prior to the presentation
2009-01-06
Alexander Sotirov (1 replies)
Alexander Sotirov (1 replies)
MD5 Hack Interesting, But Not Threatening
2009-01-08
Charles Hunter (1 replies)
Charles Hunter (1 replies)
Re: MD5 Hack Interesting, But Not Threatening
2009-01-09
Robert Lemos (2 replies)
Robert Lemos (2 replies)

What about all of the certificates that RapidSSL and Verisign issued since 1996? And since Wang's attack in 2004? And since 2007?
How many of the submitted certificate signing requests included chosen prefix collisions? And what has Verisign done to detect possible attacks in the past or the future? Verisign certainly hasn't published anything on the subject and it's because they have nothing to show.
How can Verisign answer this question hours after they first learned of the issue? They cannot.
How can it say definitively that there is no risk and that no one has attacked their CAs? Did they even detect the public attack? It seems doubtful.
In addition, the claim of substantial computing power is laughable. The researchers estimated $1000 of Amazon EC2 time for each attempt. Renting a cluster is normal and a botnet isn't an unthinkable resource for an attacker.
Verisign should address the real issues. Verisign should revoke all of the CA certs that have *ever* issued MD5 signatures. Remove MD5 from everything and prepare for the SHA-1 break that is coming.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/488/35310#35310