Later archive addition
Creating a Rogue CA Certificate
Announcement of the 25C3 result in which an MD5 chosen-prefix collision was used against a commercial CA still signing with MD5, producing a rogue intermediate CA certificate trusted by every common browser. It can impersonate any HTTPS site, making phishing against banking undetectable. Links the write-up, slides, colliding certificates and a demo site.
Record
- Researcher
- Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger
In the archive
- Added to the 2008 archive after the original list was published
- Ranked #1 in the 2009 Top 10 Web Hacking Techniques
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger, first published at the original source. Preserved copies are kept so the citation survives its host.