So, the Internet gets broken one last time in 2008.
Complete details are up and it is a really good write up. Take the time to read the whole thing. The short detail of it is MD5 in SSL is bad and should not be used. Using the attack detailed in the write up, the group was able to create a rogue CA certificate allowing them to "issue SSL certificates to any website we like, including rogue websites claiming to be legitimate ones". This is bad, bad news. Users have been (attempted to be) trained to look for the "lock" symbol to see if sites are legitimate or not. This invalidates those sorts of checks for users, destroying any sort of trust on the Internet.
There are a number of CAs which could be attacked in such a manner.
Criticism has been thrown already saying that a demo of this attack was not needed, that all it did was help the bad guys. I disagree, as this sort of attack has been a theory for quite a while. But as it was never demonstrated, no one took it serious. Now it should be taken serious. You have to remember, vendors have no desire to release secure products. They have a desire to make money. Secure products are only desired in so far as it is a selling point to have them and it turns customers away when you don't have them.
Congrats to the group for putting this together. And here is hoping this problem is taken care of soon.
Oh, and I do find it interesting a cluster of PS3s were utilized to assist with the attack.
- 4cast (1)
- aboutus (1)
- apple (3)
- attacks (1)
- authors (1)
- backontrack (1)
- backtrack (2)
- blog (1)
- botnet (1)
- breach (1)
- cell phone (2)
- cell phone forensics (2)
- cellebrite (1)
- chain of custody (1)
- challenge (1)
- copyright (1)
- crime (1)
- crypto (1)
- cyber security (6)
- cyber stalking (2)
- cybercrime (4)
- cyberwar (1)
- data size (1)
- economy (1)
- encase (1)
- encryption (3)
- enticement (1)
- evidence (3)
- exploit (3)
- facebook (4)
- fail (1)
- forensics (16)
- free (1)
- free speech (2)
- ftk (1)
- ftw (3)
- funny (1)
- future (1)
- game systems (2)
- government (1)
- gps (1)
- guidance (1)
- harassment (1)
- imaging (1)
- interview (6)
- investigation (8)
- ip (1)
- ip address (1)
- iphone (2)
- law (3)
- links (22)
- mac (2)
- model (1)
- news (16)
- pentest (2)
- podcast (1)
- printers (1)
- privacy (12)
- products (1)
- ps3 (1)
- quickhit (1)
- registry (1)
- regripper (2)
- review (1)
- riaa (1)
- sim card (1)
- skype (1)
- social engineering (2)
- social networking (1)
- theft (1)
- threats (8)
- tools (2)
- triage (1)
- Twitter (1)
- video (2)
- vpn (1)
New Website
Check out MattChurchill.net. I have migrated most of the content over to this site and will mostly be using it from now on. Thanks.
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment