Tuesday, December 30, 2008

VeriSign's SSL Cracked

I am very much surprised to see MD5 algorithm cracked, oops here is glimpse from the article to read more use the link below

With the help of about 200 Sony Playstations, an international team of security researchers has devised a way to undermine one of the algorithms used to protect secure Web sites — a capability that the researchers said could be used to launch nearly undetectable phishing attacks.


To accomplish that, the researchers said today that they had exploited a bug in the MD5 hashing algorithm used to create some of the digital certificates used by Web sites to prove they are what they claim to be. The researchers said that by taking advantage of known flaws in the algorithm, they were able to hack VeriSign Inc.'s & RapidSSL.com certificate authority site and create fake digital certificates for any Web site on the Internet.

To read more about the article click here and here and CNET artlice

0 comments: