Technology Review - Published By MIT
Advertisement

Weakened Algorithm Threatens Trust Online

Continued from page 1

By Erica Naone

Monday, January 12, 2009

smaller text tool iconmedium text tool iconlarger text tool icon

To pull off the attack, the team created a normal certificate and had it signed by a certificate authority that still uses MD5. However, the team engineered a collision to create a second certificate--an "evil twin"--that matched the signature of the first and also seemed to say that the original certificate authority had delegated its certificate-signing powers to the owner of the evil twin.

The evil-twin certificate could then be used to create certificates for any website on the Internet, allowing a malicious individual to impersonate trusted banking websites, padlock icon and all, without raising any of the alarms meant to protect users.

RapidSSL, a certificate authority owned by Verisign, issued the MD5 certificates that the team exploited. Independent security researcher Alexander Sotirov, who helped turn the theoretical work on MD5 into the real attack, says that the attack was possible not only because of MD5, but because of lax security in the way that RapidSSL issues certificates, which made it easy to produce a collision.

Just six hours after the researchers gave their presentation, Verisign announced that RapidSSL had moved to a more secure hash function. Tim Callan, vice president of product marketing for Verisign, explains that the company had been working on the move since it bought RapidSSL in 2006. However, he says, the company was proceeding cautiously because it didn't want to disrupt the SSL services already offered to its partners. "If you are arbitrary or capricious with that, then what happens is that people will respond by using lower-security alternatives," Callan says.

Sotirov credits Verisign for acting quickly in response to the attack, but says that the current infrastructure for certificates "is not working very well at all." He adds, "It's worrisome that so many certificate authorities are equally trusted," particularly when different authorities use different standards to verify the identity of potential clients and to secure the certificates that they issue. He says that market forces, which reward certificate authorities for fast response times and low prices rather than for good security, are creating a "race to the bottom" that increases the chance of security issues in the future.

Sam Curry, vice president of product management for security company RSA, which abandoned MD5 in its certificate authorities about a decade ago, says that he thinks it's important for companies to stay on top of theoretical attacks before they become real ones. "I'm thrilled, in a way, when people find these theoretical weaknesses because it means that we're actually doing real testing and real, deep thinking about it," Curry says. "I'm not thrilled when the practical ones roll out, because that's when people get hurt."

But Kocher says that it's unlikely that average users will be affected. While certificate authorities should pay serious attention to the researchers' attack, he says that, unfortunately, there are much easier ways to scam users online.

Comments

  • This is old news
    This was reported in Bruce Schneier's blog in December (with a little more technical detail):
    http://www.schneier.com/blog/archives/2008/12/
    Rate this comment: 12345

    Nostromo
    01/12/2009
    Posts:3
    Avg Rating:
    3/5
  • Browsers vs CA
    It's interesting all the different takes on the relationship between Browser - CA - Issuer. 

    ie. some Browsers can't tell the difference between a forged SSL cert and a genuine one, and Browsers need to implement updates and keep pace with the new security features.  

    Or as mentioned in this article the  entire browser trust model relies on all of the certificate authorities acting well. ie. keeping pace computing power, updated algorithms.  

    Several reports included the fact that EV-SSL was not affected, leaving me to believe a best-practice solution would be to implement EV SSL which seems proven to be less vulnerable. 

    In the end its all about user-security and providing the safest online financial transactions.  Having visual cues- such as the padlock or with EV-SSL the Green Bar, gives users additional "peace of mind". 
    Rate this comment: 12345

    djenkins
    01/12/2009
    Posts:1
    Avg Rating:
    1/5

Log In

Forgot your password?     Register »
Advertisement

Videos

The Marcellus Shale Gas Rush
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.