MD5 is broken: a rogue certificate authority
Summary
An international team of researchers demonstrates how MD5 collisions made a validly signed intermediate certificate for a rogue certificate authority possible. The attack produced a fraudulent CA certificate that browsers would accept. System-wide security follows the weakest algorithm that is still accepted.
Ideas
- A weak hash can completely devalue an otherwise valid certificate chain.
- Chosen-prefix collisions give different certificate contents the same MD5 value.
- Predictable serial numbers and timestamps made precise preparation of the attack easier.
- A rogue intermediate CA can sign any website so that it appears trustworthy.
- Cryptographic migration must happen before known weaknesses are exploited in practice.
- Individual issuers lagging behind endanger trust in the entire PKI ecosystem.
Insights
- Theoretical cryptanalysis becomes dangerous as soon as protocol fields can be controlled sufficiently.
- Compatibility concerns can preserve known risks for longer than is justifiable.
Quotes
Creating a rogue CA Certificate
– subtitle of the talk
Habits
- The team combined mathematical cryptanalysis with careful observation of real issuing processes.
References
- CCC: MD5 considered harmful today
- MD5: hash function vulnerable to collisions.
- X.509 public key infrastructure: the trust model under attack.
Critique
- The demonstration concerns specific issuing practices of the time and not every use of MD5 to the same extent.
- For the details, the talk assumes considerable knowledge of X.509 and collision attacks.
Remarks
- The practical demonstration accelerated the end of MD5-signed web certificates.
- Historically, the case shows the danger of transition periods that are technically overdue.
Recommendations
- Remove broken algorithms from issuing and trust validation.
- Take inventory of legacy cryptographic methods together with a binding switch-off date.
- Check protocol fields that attackers can control for collision prefixes.
Links to the original source and the Web Archive open in a new tab.