Breaking Down Broken SSL
ID: 73c7a0dd-26ce-55ca-bdb9-5d0419856a63
STIX ID: report--73c7a0dd-26ce-55ca-bdb9-5d0419856a63
Feed Name: Zscaler Security Research Blog
Researchers demonstrated in 2008 that chosen-prefix MD5 collisions can be used to create a rogue intermediate CA certificate, allowing issuance of fraudulent SSL site certificates that browsers would accept; the attack required significant compute (a PS3 cluster), advanced knowledge, and traffic redirection, and was facilitated by Certificate Authorities still signing with MD5 and predictable serial/validity practices. The report emphasizes the difficulty of detection once a rogue CA exists and calls for CAs to phase out MD5, add randomness (e.g., to serial numbers), and improve signing procedures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
