SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Rogue SSL certificate exploit puts VeriSign on the spot

Rogue SSL certificate exploit puts VeriSign on the spot

By:  Ellen Messmer  On: 05 Jan 2009 For: Network World (U.S.) (GM) Creator

Researchers claim they can use a rogue certificate to impersonate any Web site on the Internet. Find out what experts say about MD5

Following the success of researchers last week in creating a false SSL certificate based on VeriSign's RapidSSL brand, the company is scrambling to explain how it happened, how it's preventing it from reoccurring, and whether its other SSL certificate-generation services are at risk.

SSL certificates are supposed to be unique identifiers for Web sites and other purposes, but on Dec. 30, an international team of researchers demonstrated at the Berlin Chaos Communication Congress event how they could exploit a weakness in the MD5 hash algorithm in VeriSign's automated RapidSSL certificate-issuance service to gain possession of what they call a "rogue Certificate Authority certificate."

"This certificate allows us to impersonate any Web site on the Internet, including banking and e-commerce sites secured using the HTTPS protocol," stated the researchers in their paper discussing the attack methodology. (Researchers who conducted this work include Alexander Sotirov, Marc Stevens, Jacob Applebaum, Arjen Lenstra, David Molnar, Dag Arne Osvik and Benne de Weger.)

More security news in Network World

Budget constraints might hamper DNS security

A hash is a mathematical construct used in software to create a unique digital "fingerprint," but experts have speculated about potential weaknesses in the MD5 hash algorithm for more than four years. The international team at the Berlin event proved that with enough computing firepower they could create a certificate that could fool any Web browser into trusting what would be a rogue Web site, if the fake certificate were used.

"As a proof of concept, we executed a practical attack scenario and successfully created a rogue Certification Authority certificate trusted by all consumer Web browsers," the researchers state in their paper. The group emphasized: "Don't use the MD5 algorithm." They also pointed out that they see the potential for a mass denial-of-service attack on the Web based on the kind of exploit they demonstrated.

Four hours after the researchers' proof-of-concept demonstration, VeriSign switched out MD5 for SHA-1 for use in its RapidSSL certificate service, says Tim Callan, vice president of product marketing.

SHA-1 is another hash algorithm and a U.S. government standard, but it too is expected to be replaced with something stronger over the next five years under the hash competition process that the National Institute of Standards and Technology is overseeing. Callan expressed some frustration that the researchers hadn't contacted VeriSign prior to their demonstration of RapidSSL's vulnerability.

"VeriSign feels this kind of 'white hat' research is important, but we encourage them to share their findings with us," he says. Despite some talk that VeriSign might consider taking legal action against such research, Callan emphasizes, "We wouldn't use legal response to prevent disclosure." RapidSSL is one of several VeriSign certificate-generation services. "We're not revealing how many seats are out there, but RapidSSL, which we acquired from GeoTrust in 2006, has as its target customer the very small business."


Sign up for our Newsletters












Print |  Views: 1202   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Ellen Messmer Ellen Messmer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Mandate for federal desktop security set to kick in
Mandate for federal desktop security set to kick inThe federal government's desktop security mandate kicks in this week, requiring government agencies to support standard secure configurations for Windows XP and Vista operating systems. Known as the Federal Desktop Core Configuration standard, the FDCC will require agencies to apply and maintain standard security settings on all desktops and laptops.
Certicom launches digital certificate service
Certicom launches digital certificate serviceMississauga, Ont.-based company targets device manufacturers with new service offering
High-tech birth certificates in B.C. fight ID theft
High-tech birth certificates in B.C. fight ID theftBritish Columbia will be issuing a new, highly secure birth certificate document beginning January 2008. The province's Ministry of Health says the new format will help British Columbians protect themselves against identity theft and other forms of fraud. Other provinces are expected to follow suit.
'Undoing' the math
it's all about the math, right? not so, says karl fant. he's the founder of theseus research and he's feels there's something fundamentally wrong with using the algorithm as the basic paradigm of computer systems.for a start, many functions of a computer system don't fit the definition of an algorithm (algorithms terminate in a finite number of steps, for example; operating systems don'

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.