Advertisement
Promo

Become a member of the ZDNet UK community

David Meyer

View blog's RSS Feed

Communication Breakdown

Communications from the world of, er, communications. And other stuff.

Wednesday 31 December 2008, 11:30 AM

SSL certificate crack threatens e-commerce sites

Posted by David Meyer

A group of security researchers has demonstrated that it is possible to create a "rogue" SSL certificate allowing them to impersonate "any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol".

All current browsers would be fooled, the researchers claim.

Shown at the Chaos Computer Club's annual conference in Berlin, the dummy certificate has an expiry date backdated to 2004, so as to make it practically useless. Nonetheless, the researchers claim it is good enough to fool the best of 'em.

The basis of the crack lies in an apparent vulnerability in the MD5 signature algorithm, so the researchers are urging certification authorities (CAs) to switch to newer, more secure alternatives such as SHA-2. It seems that MD5 has long been shown to have a potential for exploitation, but the researchers are claiming their rogue certificate as the first definitive proof.

According to our sister publication, News.com, Verisign has already closed the hole, speeding up the purge of MD5 signing in its certificates. Internet Explorer-maker Microsoft has shrugged its shoulders, saying the researchers have "not published the cryptographic background to the attack" and claiming this makes their exploit unrepeatable.

The piece also quotes the ever-reliable Bruce Schneier:

"SSL protects data in transit but the problem isn't eavesdropping on the transmission. Someone can steal the credit card on some server somewhere. The real risk is data in storage. SSL protects against the wrong problem," he said.

"This is good work, great cryptography. I love the research, but this doesn't matter a whit," Schneier added. "There are half a dozen ways to forge certificates and nobody checks them anyway."

Comments on this post

iamscared

MD5 is not a signature algorithm, it's a hash function.
MD5 is broken since 2004 and should not be used.

Journalists should try harder.

Posted by iamscared on Jan 3, 2009 3:14 PM

David Meyer

It is true that MD5 is a hash function, and I should have not referred to it as a signature algorithm - although the hash function does implicitly involve an algorithm. Also, I agree - as it says in the above post - that MD5 has long been known to be vulnerable.

Thank you for pointing out the incorrect phrasing.

Posted by David Meyer on Jan 5, 2009 10:08 AM

bobdowne

David Meyer, referring to MD5 as a signature algorithm is entirely acceptable in this context. SSL Certificates use hash functions as a means of generating the signature, so you were right. imscared isn't as smart as he thinks he is.

Posted by bobdowne on Mar 2, 2009 10:52 PM

David Meyer
  • David Meyer
  • London, UK
  • Member since: October 2006
ZDNet Staff

Contacts' Latest Discussions

Number of Tracked Discussions: 2,305

Jake Rayson Jake Rayson

Tweaking my Karmic Koala

Monday 9 November 2009, 2:15 PM

2 comments
J.A. Watson J.A. Watson

The Shine is off the Polish

Monday 9 November 2009, 1:48 PM

2 comments
ator1940 ator1940

"polished Moblin"

Monday 9 November 2009, 1:32 PM

2 comments
J.A. Watson J.A. Watson

Using Windows Is Like...

Sunday 8 November 2009, 8:38 PM

6 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 11


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters