Detta är ett hittat inlägg som jag delat ut via Google Reader. Alla rättigheter tillhör orginalskribenten. (Föregående Nästa )

CCC Create a Rogue CA Certificate

t3rmin4t0r writes “Just when you were breathing easy about Kaminsky, DNS and the word hijacking, by repeating the word SSL in your head, the hackers at CCC were busy at work making a hash of SSL certificate security. Here’s the scoop on how they set up their own rogue CA, by (from what I can figure) reversing the hash and engineering a collision up in MD5 space. Until now, md5 collisions have been ignored because nobody would put in that much effort to create a useful dummy file, but a CA certificate for phishing seems juicy enough to be fodder for the botnets now.”

Read more of this story at Slashdot.

Orginalpost: CCC Create a Rogue CA Certificate

OBS! Det är inte möjligt att kommentera delade inlägg här, gör det istället där det först publicerades.

« Copyriot: Omvärldsbevakarnas pinsamma säkerhetsluckor
30 dec, 2008 »

Eventuellt relaterat