Results 1 to 4 of 4

Thread: The MD5 algorithm used by many sites, is not reliable

  1. #1
    Join Date
    Oct 2005
    Posts
    2,358

    The MD5 algorithm used by many sites, is not reliable

    When you visit a Web site whose address begins with "https", a small padlock appears. In theory, this means that the site is secured by an electronic certificate. In practice, all risks are possible. Especially if the certificate uses the MD5 algorithm, which is still used by several authorities of electronic certification.

    At a meeting of hackers Chaos Computer Club, which has just ended in Berlin, the results presented Tuesday 30 December leave more room for doubt: this piece of Internet infrastructure is not reliable, and allows hackers create certificates recognized as valid by all browsers.

    The news is all the more disturbing ... it is not. This is not the first time, in fact, that the weakness of the cryptographic hash function MD5 is denounced. In 2004, a team of Chinese researchers had reported being able to create with it an attack "collision", by creating two different messages with the same signature.

    In 2007, Swiss and Dutch researchers have demonstrated that there was an almost total freedom in the choice of two messages that come into collision. A concept with which these same researchers, who joined an American, are in fact create a false certification authority recognized by reliable Internet browsers.

    Their goal? "Encouraging the use of encryption standards safer." Their weapon: a "cluster" (machines used to produce a supercomputer) of more than 200 game consoles available in trade, capable of generating a false Having lost his certificate validity (to prevent any real damage). Means available to hackers. Which could thus, making them bite the hook by "phishing", without their knowledge redirect users to fake banking sites or e-commerce.

    Former "Mr. Security" V Mwari Inc. and first signatory of this communication, Alexander Sotirov (New York) was surprised to note that "despite years of warnings, several certification authorities continue to use this algorithm. Out of 30 000 certificates of Web sites, researchers have indeed found almost a third (9 000) employing DM5 in 2008.

    "The main browsers and Internet players, such as Mozilla and Microsoft, have been informed of our discovery and some have already responded to better protect their users," reassures Arjen Lenstra, head of cryptographic algorithms laboratory at the Ecole Polytechnique Federal Lausanne. It does not so much as "imperative" that the navigation systems and certification authorities "do not use MD5 and migrate to more robust alternative." As SHA-2, already available, even to his future successor, SHA-3.
    I'm the Proud Owner of the most dangerous weapon
    known to man kind: Human Brain

  2. #2
    Join Date
    Dec 2008
    Posts
    43

    Re: The MD5 algorithm used by many sites, is not reliable

    Of course! There is no lock that has no key. Because you can never stop someone from making a key, the principle of protection is to periodically change the locks (proposed SHA-n) or to ensure that the time of manufacture is a key long enough for Information evening become obsolete. Next step: SHA2 and SHA3 are not safe.

  3. #3
    Join Date
    Dec 2008
    Posts
    28

    Re: The MD5 algorithm used by many sites, is not reliable

    We would have appreciated that the author provides information on the likelihood that this vulnerability is actively exploited short / medium term before waving their arms as if disaster had arrived. MD-5 will be replaced in time, everything is in place.

  4. #4
    Join Date
    Nov 2008
    Posts
    38

    Re: The MD5 algorithm used by many sites, is not reliable

    Not surprisingly, there is a likelihood. For commercial reasons we have some experts to believe the invulnerability of cryptographic systems. It could be on the basis of this article have doubts about the invulnerability of information technology Quotes and ask all relevant questions on the role of mathematics and computer science in rogue wave of the current economic crisis: everything is wrong at the base, we were believers

Similar Threads

  1. Replies: 5
    Last Post: 28-02-2012, 09:03 PM
  2. DES ALGORITHM in C Language
    By sayanmaji in forum Software Development
    Replies: 2
    Last Post: 21-03-2010, 11:23 AM
  3. iWeb : An error occurred while publishing file /Web/Sites/Sites.rss
    By roshan45 in forum Networking & Security
    Replies: 5
    Last Post: 21-02-2010, 01:36 AM
  4. Replies: 2
    Last Post: 11-09-2008, 05:21 AM
  5. Adding sites to Trusted and Intranet Sites using Group Policy
    By cbob66@aol.com in forum Windows Server Help
    Replies: 2
    Last Post: 18-09-2007, 07:22 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,474,762.49010 seconds with 17 queries