bk99.de entertain the web since 1997

MD5 is broken: a rogue certificate authority

Summary

An international team of researchers demonstrates how MD5 collisions made a validly signed intermediate certificate for a rogue certificate authority possible. The attack produced a fraudulent CA certificate that browsers would accept. System-wide security follows the weakest algorithm that is still accepted.

Ideas

  • A weak hash can completely devalue an otherwise valid certificate chain.
  • Chosen-prefix collisions give different certificate contents the same MD5 value.
  • Predictable serial numbers and timestamps made precise preparation of the attack easier.
  • A rogue intermediate CA can sign any website so that it appears trustworthy.
  • Cryptographic migration must happen before known weaknesses are exploited in practice.
  • Individual issuers lagging behind endanger trust in the entire PKI ecosystem.

Insights

  • Theoretical cryptanalysis becomes dangerous as soon as protocol fields can be controlled sufficiently.
  • Compatibility concerns can preserve known risks for longer than is justifiable.

Quotes

  • Creating a rogue CA Certificate – subtitle of the talk

Habits

  • The team combined mathematical cryptanalysis with careful observation of real issuing processes.

References

Critique

  • The demonstration concerns specific issuing practices of the time and not every use of MD5 to the same extent.
  • For the details, the talk assumes considerable knowledge of X.509 and collision attacks.

Remarks

  • The practical demonstration accelerated the end of MD5-signed web certificates.
  • Historically, the case shows the danger of transition periods that are technically overdue.

Recommendations

  • Remove broken algorithms from issuing and trust validation.
  • Take inventory of legacy cryptographic methods together with a binding switch-off date.
  • Check protocol fields that attackers can control for collision prefixes.

Watch the talk

Search the Web Archive