Submit a Story!
topics:

 		SSL broken! Hackers create rogue CA certificate using MD5 collisions | Zero Day
SSL broken! Hackers create rogue CA certificate using MD5 collisions | Zero Day
December 30th, 2008 SSL broken! Hackers create rogue CA certificate using MD5 collisions Posted by Ryan Naraine @ 6:00 am Categories: Zero-day attacks , Microsoft , Browsers , Punditocracy , Responsible disclosure , Spam and Phishing , Spyware and Adware , Botnets , Exploit code , Data theft , ...
MD5 collision used to create a forged certificate authority
MD5 collision used to create a forged certificate authority
hackszine.com — A group of researchers were recently able to subvert the public key infrastructure used by common web... browsers using an MD5 hash collision. The MD5 hash algorithm was proven vulnerable to collisions some time ago, but this is a huge real-world ... (more) MD5 collision used to create a forged certificate authority
Comments
Blog Reactions

MD5 collision creates rogue Certificate Authority
CrunchGear — ... certain attacks, though, so it might be better for the vulnerable CAs to jump right to SHA-2 or SHA-3. Bottom line: as always, be cognizant of your browsing habits. If something looks or feels fishy, don’t provide any account names or passwords. Use different passwords for different websites, so that if you do get suckered by a phishing attack the phishers don’t get the keys to your online kingdom. Link: 25C3: MD5 considered harmful today Via: ZDnet

PlayStation 3 used to hack SSL, Xbox used to play Boogie Bunnies
Engadget — ... web sites you're visiting could be counterfeit, and you'd have no way of knowing. Sure, this is all pretty obscure stuff, and the kids who managed the hack said it would take others at least six months to replicate the procedure, but eventually vendors are going to have to upgrade all their CAs to use a more robust algorithm. It is assumed that the Wii could perform the operation just as well, if the hackers had enough room to spread out all their Balance Boards. [Via ZD Net] ...

Afternoon Linkage for December 30th, 2008
GEARFUSE — ... tech-inspired Draw Music With Drawdio DIY: Draw Music With Drawdio Munny Tusken Raider DESIGN: Munny Tusken Raider Glow In The Dark Funguse SCIENCE: Glow In The Dark Funguse Afternoon Linkage for December 30th, 2008 By Vince Veneziani December 30, 2008 Comments (0) Filed under: Features I threw my back out this morning. I shall be cured through the power of cereal and fresh links! SSL has been broken! Yikes! Steve Jobs is dying Punch Out! Apparel DIY 3-D ...

Related: ssl certificate
Website security in question now VeriSign’s SSL hackedTECH.BLORGE.com
A team of researchers hacked VeriSign’s RapidSSL.com certificate, demonstrating what they say is a means [...]
Researchers Create Web Skeleton Key With 200 PS3s [PS3]Gizmodo
Using a cluster of 200 PS3s, an international group of researchers have crafted a "skeleton key" digital certificate that can perfectly impersonate any website on the internet. The weak point that allows the technique to work—which researchers will be detailing at the 25th Chaos ...