Home > Security > MD5 considered harmful today

MD5 considered harmful today

janeiro 15th, 2009

Creating a rogue CA certificate

We have identified a vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure websites. As a proof of concept we executed a practical attack scenario and successfully created a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate allows us to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol.

Source: http://www.win.tue.nl/hashclash/rogue-ca/

[ ]’s

Security

Comments are closed.