Gizmodo

  • Gizmodo
  • bestmodo
  • lifehacker
  • kotaku
Profile logout login
25 New Ads to Introduce Xfinity to the Masses

25 New Ads to Introduce Xfinity to the Masses #photoshopcontest #photoshop

What Is Google Buzz?

What Is Google Buzz? #google #googlebuzz

74 Phenomenal Panoramic Planets

74 Phenomenal Panoramic Planets #photography #shootingchallenge

Canon Rebel T2i DSLR: 18MP and Legit 1080p Video for $899

Canon Rebel T2i DSLR: 18MP and Legit 1080p Video for $899 #digitalcameras #canonrebelt2i

Apple iPad: Everything You Need to Know

Apple iPad: Everything You Need to Know #apple #appleipad

Super Bowl Ads 2010: Lots of Chips and Beer, Light On Gadgets

Super Bowl Ads 2010: Lots of Chips and Beer, Light On Gadgets #superbowl #superbowlads

The Month's Best Android Apps

The Month's Best Android Apps #androidapps #android

Gizmodo

FAQ. Include # before tag:
#tips, #whitenoise, #broken, #lifechanger, etc.

New York, 3:44 PM
Tue Feb 9
68 posts in the last 24 hours

FR | IT | DE | SP | JP | AU | BR

GIZMODO TEAM

Tip Your Editors:


Editorial Director:
Brian Lam | | Twitter

Editor:
Jason Chen
| AIM | Twitter

Features Editor:
Wilson Rothman
| Twitter

Senior Contributing Editors:
Jesus Diaz
| AIM | Twitter
Mark Wilson, Reviews
| AIM | Twitter

Contributing Editors:
Matt Buchanan
| AIM | Twitter
Adam Frucci
| Twitter
Sean Fallon
| Twitter
Jack Loftus
| Twitter
John Herrman
| Twitter
Dan Nosowitz

Chris Mascari

Kat Hannaford
| Twitter
Rosa Golijan
| Twitter
Chris Jacob


Columnist:
Brendan I. Koerner

Interns:
Don Nguyen

Kyle VanHemert


Heroes and Friends

Comment Account Questions:

SUBSCRIBE TO GIZMODO RSS

New: Breaking news and daily top stories via email
9515 Subscribers


Please confirm your birth date:

Please enter a valid date
Please enter your full birth year
This content is restricted.

Researchers Create Web Skeleton Key With 200 PS3s

Using a cluster of 200 PS3s, an international group of researchers have crafted a "skeleton key" digital certificate that can perfectly impersonate any website on the internet.

The weak point that allows the technique to work—which researchers will be detailing at the 25th Chaos Communication Congress in Berlin—is the MD5 hash algorithm, which, basically, is what's used to create a fingerprint that makes it hard to forge digital certificates. Verisign's RapidSSL still uses the MD5 hash algorithm.

So, where do the crack-friendly PlayStation 3s come in? Well, they have to generate CA certificiate—the certificate that allows them to sign and verify certificates for any other site—and a website certificate that produce the same MD5 hash. A cluster of 200 PS3s were used to figure out where the MD5 hashes of their forged CA certificate and website certificate "collide," allowing them to "crunch out their forgery in about three days."

What's all this mean? David Molnar, a computer science PhD candidate, Threat Level talked to, explains it best: ""We can impersonate Amazon.com and you won't notice...The padlock will be there and everything will look like it's a perfectly ordinary certificate." Thankfully, the hack is hard, but the solution is pretty easy—just switch to a more secure hash, which many companies have done. Verisign is currently in the process of phasing out the MD5 hash. [Threat Level]


Send an email to matt buchanan, the author of this post, at matt@gizmodo.com.


Upload an image | Add an image URL ×
×
×
Choose a file to upload:
×
Dsmvwl  Admin  Promote to frontpage Approve user Ban user ×
Loading comments ... -/|\
Earlier discussions Paging in progress... | Other discussions | Show all discussions | Show featured discussions only | Expand all threads Collapse all threads
Start a new discussion
By matt buchanan
Dec 30, 2008 05:40 PM 29,782 84
Edit » Set to Draft » Invite » Syndicate »

Syndicate this post


Site:
Mode:

sending request
cancel
more about #playstation3
Alien Chestburster Finds Loving Host in PS3
Sony Still Loses Money on Every PS3 They Sell
Sony is 'Thinking About Charging' for PSN
read more: #ps3, #playstation3, #ssl, #verisign, #internet, #security, #hack, #crack, #cryptography
 
  • Archives
  • About
  • Advertising
  • Legal
  • Help
  • Report a Bug
  • FAQ
Original material is licensed under a Creative Commons License permitting non-commercial sharing with attribution.

Login

Enter your username and password.

Please enter a username.
Please enter your password.
logging in
Login via Facebook | Sign Up | Forgot Password?

Reset Password

Please enter your email address to have your password reset.

Please enter your email address.
Please enter a valid email address.
requesting password reset

Register

Registering will give you a user profile and the ability to add other users as friends. To become a commenter, however, you need to audition.

Want to know more? Consult the Comment FAQ and legal terms.

Please enter a username.
Please enter a password.
Please confirm your password.
Passwords are not identical.
Please enter a valid email address.
registration sent, waiting for reply

Submit Your Comment

You don't need to login to comment. Just enter your email address below.

See how your address will be displayed in the Comment FAQ.

Please enter a valid email address.
Please enter a valid email address.
logging in

Login with your Facebook or Gizmodo account.

Sign up here.



Send An Invitation

To invite commenters to this page, paste in a list of comma-separated email addresses, and then select send invites.

Please enter at least one email address.
Please use valid email addresses.
Please use unique email addresses.
Please enter fewer addresses.
requesting invites

Send a link

Send a link to this post 'Researchers Create Web Skeleton Key With 200 PS3s' via email:

Please enter your name.
Please enter your email address.
Please enter a valid email address.
Please enter your recipient's email address.
Please enter a valid email address.
Please enter your message.
Sending message