Collected research
Creating a Rogue CA Certificate
Creating a rogue CA certificate
Announcement of the 25C3 result in which an MD5 chosen-prefix collision was used against a commercial CA still signing with MD5, producing a rogue intermediate CA certificate trusted by every common browser. It can impersonate any HTTPS site, making phishing against banking undetectable. Links the write-up, slides, colliding certificates and a demo site.
Record
- Document
- Creating a rogue CA certificate
- Researcher
- Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger
- Published by
- phreedom.org
- Topic
- Crypto
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .