Researchers Prove Attacks Against MD5 Feasible

Researchers, via the 25th Chaos Communication Congress (25C3)], have present a paper effectively proving the feasibility of collision attacks against the MD5 standard. Meanwhile, the root of the issue is MD5 has been broken for over 4 years…Four Years! Fundamentally, the issue is the creation of rogue Certificate Authorities. I will let the researchers speak for themselves – in a document released at the Chaos Communications Congress yesterday – “MD5 Considered Harmful Today Creating a Rogue CA Certificate by Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger. All respected security researchers.
The original presentation document can be downloaded from the Infosecurity.US Public Document Repository or via the Chaos Communications Conference.

The MD5 Team
- Researchers Use PlayStation Cluster to Forge a Web Skeleton Key
- MD5 collision creates rogue Certificate Authority
- Web browser flaw could put e-commerce security at risk
- Researchers devise undetectable phishing attack
- Researchers Show How to Forge Site Certificates (Ed Felten/Freedom to Tinker)
- CA issues no-questions asked Mozilla cert
![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_b.png?x-id=9b6f8055-f7bb-4247-96c7-0d5a70793dfc)





