logo

Breaking Down Broken SSL

ID: 73c7a0dd-26ce-55ca-bdb9-5d0419856a63

STIX ID: report--73c7a0dd-26ce-55ca-bdb9-5d0419856a63

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Researchers demonstrated in 2008 that chosen-prefix MD5 collisions can be used to create a rogue intermediate CA certificate, allowing issuance of fraudulent SSL site certificates that browsers would accept; the attack required significant compute (a PS3 cluster), advanced knowledge, and traffic redirection, and was facilitated by Certificate Authorities still signing with MD5 and predictable serial/validity practices. The report emphasizes the difficulty of detection once a rogue CA exists and calls for CAs to phase out MD5, add randomness (e.g., to serial numbers), and improve signing procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.