Web Hack List

Collected research

Creating a Rogue CA Certificate

Creating a rogue CA certificate

Announcement of the 25C3 result in which an MD5 chosen-prefix collision was used against a commercial CA still signing with MD5, producing a rogue intermediate CA certificate trusted by every common browser. It can impersonate any HTTPS site, making phishing against banking undetectable. Links the write-up, slides, colliding certificates and a demo site.

Record

Document
Creating a rogue CA certificate
Researcher
Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger
Published by
phreedom.org
Topic
Crypto

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .