Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 31, 2008

MD5 Collisions Put PKI At Risk

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

A new paper outlines how it's possible to use MD5 collisions to spoof a legitimate certificate authority's (CA) certificate, which means someone could spoof the security of nearly any site - even banks.

The basic problem is that two different blocks of data could have the exact same MD5 hash sum. That of course means that you can't totally rely on the MD5 algorithm to provide an adequate check and balance. Unfortunately some CA's still use MD5 to sign certificates - that's one of those "Really Bad Things ™" that we hear about now and then.

Some of the offending CA's include (surprisingly) RSA Data Security, Verisign (Japan), Thawte, FreeSSL, Rapid SSL, and TC TrustCenter AG (Germany).

In their whitepaper, researchers Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, and Benne de Weger said that they collected roughly 30,000 certificates from around the Internet and of those approximately 9000 were signed using MD5. Wow. That's a high percentage.

Of course Microsoft published an advisory saying that they "no longer use MD5 to sign certificates, but have upgraded to the more secure SHA-1 algorithm," which is good.

But Microsoft's related advisory also says that "this new disclosure does not increase risk to customers significantly, as the researchers have not published the cryptographic background to the attack, and the attack is not repeatable without this information."

For those of you that aren't already ROFL at Microsoft's downplay of the risk, don't believe them. We've seen time and time again how once tipped off to a vulnerability savvy hackers can craft their own exploit code in short order.

If you have SSL certs issued for use on your own sites then view the certificates details to inspect the associated signature algorithm (you can use your Web browser to do that). If it was signed using MD5 then you should ask the issuing agent to re-issue the cert using a more secure signing algorithm such as SHA-1, if not something much stronger.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Security Matters
 
Security Matters
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Security Matters
Wordpress 2.8.4 Fixes A Big Security Hole
Make a Comment
Microsoft Releases 5 Critical Patches
Make a Comment
How To Help Secure HTTP Data Without SSL

Last Comment
The article has very less information. Need some elaboration....
(1 Comments)
Sometimes The Cookie Doesn't Crumble
Make a Comment
SecureTweets for Twitter
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement