Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 31-12-2008, 10:11 PM   #1 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default SSL broken! Hackers create rogue CA certificate using MD5 collisions


Source: http://blogs.zdnet.com/security/?p=2339

Using computing power from a cluster of 200 PS3 game consoles and about $700 in test digital certificates, a group of hackers in the U.S. and Europe have found a way to target a known weakness in the MD5 algorithm to create a rogue Certification Authority (CA), a breakthrough that allows the forging of certificates that are fully trusted by all modern Web browsers.

The research, which will be presented today by Alex Sotirov (top left) and Jacob Appelbaum (bottom left) at the 25C3 conference in Germany, effectively defeats the way modern Web browsers trust secure Web sites and provides a way for attackers to conduct phishing attacks that are virtually undetectable.

Read On..........
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 01-01-2009, 12:28 AM   #2 (permalink)
Rubik's Uncle!!
 
Charan's Avatar
 
Join Date: Sep 2004
Location: ಬೆಂಗಳೂರು (Bengaluru)
Posts: 3,791
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Cr@p
__________________
i5 2400 | DH67BL | G.Skill Ripjaw 4 GB | FSP SAGA II 500W | CM 430 Black Elite | MSI R6850 Cyclone PE/OC | XBox 360 Controller | 21.5" Samsung Sync Master 2233 | 4 Mbps @75GB FUP :)
Battlefield 3 Multiplayer Discussion | Battlefield 3 Low Latency Servers List
Charan is offline  
Old 01-01-2009, 01:38 AM   #3 (permalink)
GaurishSharma.com
 
gary4gar's Avatar
 
Join Date: May 2005
Location: Jaipur
Posts: 4,116
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Seems Hackers always one step ahead
gary4gar is offline  
Old 01-01-2009, 02:02 AM   #4 (permalink)
Rubik's Uncle!!
 
Charan's Avatar
 
Join Date: Sep 2004
Location: ಬೆಂಗಳೂರು (Bengaluru)
Posts: 3,791
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

^^ if we look at history , SSL was just surfacing in 1993 , and by 1996 it started to show some strength.. so it took hackers about 12-13 years to crack it . Are they One step ahead?
__________________
i5 2400 | DH67BL | G.Skill Ripjaw 4 GB | FSP SAGA II 500W | CM 430 Black Elite | MSI R6850 Cyclone PE/OC | XBox 360 Controller | 21.5" Samsung Sync Master 2233 | 4 Mbps @75GB FUP :)
Battlefield 3 Multiplayer Discussion | Battlefield 3 Low Latency Servers List
Charan is offline  
Old 01-01-2009, 02:08 AM   #5 (permalink)
GaurishSharma.com
 
gary4gar's Avatar
 
Join Date: May 2005
Location: Jaipur
Posts: 4,116
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Quote:
Originally Posted by Charan View Post
^^ if we look at history , SSL was just surfacing in 1993 , and by 1996 it started to show some strength.. so it took hackers about 12-13 years to crack it . Are they One step ahead?
I am talking in General.

see tell me, one example of any un-hackable system?
if you tell, then i would be your follower, uncle ji
gary4gar is offline  
Old 01-01-2009, 02:17 AM   #6 (permalink)
Rubik's Uncle!!
 
Charan's Avatar
 
Join Date: Sep 2004
Location: ಬೆಂಗಳೂರು (Bengaluru)
Posts: 3,791
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Quote:
Originally Posted by gary4gar View Post
I am talking in General.

see tell me, one example of any un-hackable system?
yea , in general all systems will have flaw or will be reverse engineered, its only a matter of time.
Quote:
uncle ji
Grrrrrr...
__________________
i5 2400 | DH67BL | G.Skill Ripjaw 4 GB | FSP SAGA II 500W | CM 430 Black Elite | MSI R6850 Cyclone PE/OC | XBox 360 Controller | 21.5" Samsung Sync Master 2233 | 4 Mbps @75GB FUP :)
Battlefield 3 Multiplayer Discussion | Battlefield 3 Low Latency Servers List
Charan is offline  
Old 01-01-2009, 10:04 AM   #7 (permalink)
Host4Cheap.org
 
Sukhdeep Singh's Avatar
 
Join Date: May 2005
Location: Digit Forum
Posts: 2,102
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Quote:
Originally Posted by Charan View Post
^^ if we look at history , SSL was just surfacing in 1993 , and by 1996 it started to show some strength.. so it took hackers about 12-13 years to crack it . Are they One step ahead?
Blame it on Sony for coming so late with PS3 Processor Power
__________________
★ Want to start your Website, No worries - here is how ★
http://www.thinkdigit.com/forum/showthread.php?t=66717

★ Host4Cheap - cPanel Webhosting & Reseller Plans ★
http://www.host4cheap.org/
Sukhdeep Singh is offline  
Old 01-01-2009, 11:09 AM   #8 (permalink)
!! RecuZant By Birth !!
 
naveen_reloaded's Avatar
 
Join Date: May 2005
Location: In Everyone`s Heart
Posts: 2,985
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

200 ps3 ??? wow !!! thats real power....
__________________
Know My Thoughts..
Visit my Blog @ www.Urssiva.com
Visit My Tech Blog @ www.CloudTechnica.com
naveen_reloaded is offline  
Old 01-01-2009, 11:15 AM   #9 (permalink)
AFK
 
thewisecrab's Avatar
 
Join Date: Oct 2006
Location: Bombay
Posts: 1,599
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Great. Now all the hacker needs is 200 PS3s to hack a bank.
Considering the price of a PS3, he'll be better off looting the bank at gun point than to go through that effort.
__________________
Follow me on http://twitter.com/thewisecrab

"This Jen, is the internet"
thewisecrab is offline  
Old 01-01-2009, 12:53 PM   #10 (permalink)
Human Spambot
 
Join Date: Jan 2007
Location: Lat 28.38°N , Longt 77.13°E
Posts: 2,431
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Quote:
Originally Posted by gary4gar View Post
Seems Hackers always one step ahead
+1

Blu Ray copy protection cracked months ahead of schedule.
ThinkFree is offline  
Old 01-01-2009, 01:31 PM   #11 (permalink)
EXIT: DATA Junkyard
 
comp@ddict's Avatar
 
Join Date: Aug 2008
Location: New Delhi
Posts: 5,019
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Hackers r always 1 step ahead - just like torrent guys, u get movies and games the day b'fore or the day of release.
__________________
About me:
http://about.me/preetam_nath
comp@ddict is offline  
Old 01-01-2009, 11:52 PM   #12 (permalink)
Rubik's Uncle!!
 
Charan's Avatar
 
Join Date: Sep 2004
Location: ಬೆಂಗಳೂರು (Bengaluru)
Posts: 3,791
Talking Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Quote:
Originally Posted by thewisecrab View Post
Great. Now all the hacker needs is 200 PS3s to hack a bank.
Considering the price of a PS3, he'll be better off looting the bank at gun point than to go through that effort.
ROFL ... man this made my day ..
__________________
i5 2400 | DH67BL | G.Skill Ripjaw 4 GB | FSP SAGA II 500W | CM 430 Black Elite | MSI R6850 Cyclone PE/OC | XBox 360 Controller | 21.5" Samsung Sync Master 2233 | 4 Mbps @75GB FUP :)
Battlefield 3 Multiplayer Discussion | Battlefield 3 Low Latency Servers List
Charan is offline  
Old 03-01-2009, 08:50 AM   #13 (permalink)
Linux all the way
 
Join Date: Mar 2008
Location: Rasayani
Posts: 157
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

there's nothing that cannot be cracked... updating technology is the only was to ensure that yiou stay safe from attacks. As computing power increases so does the need for make security changes..
__________________
At times life takes a U turn and you get back where you were...
Vishal Patil is offline  
Old 15-01-2009, 08:00 PM   #14 (permalink)
Right Off the Assembly Line
 
Join Date: Jan 2009
Posts: 1
Default Re: SSL broken! Hackers create rogue CA certificate using MD5 collisions

Verising has resolve the issue much faster then expected. It was MD5 Signature which was cracked. Now, they are offering SHA-1 sing certificate.

Also, you cannot say its cracked because they have not broke the certificate in between and try for Man in Middle attack. Its only that they have created fake certificate which looks like RapidSSL certificate.

MitchNelson is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Broken LCD... broken heart Nilotpal Datta Hardware Q&A 2 05-11-2008 10:11 AM
Stay Away From These Rogue Threats. anandk Technology News 5 24-09-2007 06:07 PM
how to create a digital certificate to fill a online form rahul.ims Chit-Chat 2 31-07-2007 07:55 PM
Linux hackers offer to create device drivers for free gary4gar Open Source 9 05-02-2007 01:14 PM
Rogue/Suspect Anti-Spyware Products rajat22 QnA (read only) 1 12-11-2005 08:03 PM

 
Latest Threads
- by Who
- by abhidev
- by Tenida
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 10:16 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2