Skip to main content

Crypto guru urges incentives for SSL cert recall

posted onJune 25, 2009
by hitbsecnews

An SSL security guru is urging incentives to promote website certificate upgrade in response to problems with a widely-used digital-signature algorithm.

Collisions in the MD5 hashing algorithm mean that two different inputs can produce the same output. Last year independent researchers showed how the cryptographic flaw might make it possible to forge counterfeit digital certificate credentials.

The trick might be used to set up phony websites with bogus certificates that, as far as a visiting surfer's browser is concerned, are indistinguishable from the real thing Dr Taher Elgamal, chief security officer at Axway, who is credited as the inventor of Secure Socket Layer (SSL) technology, told El Reg that solving the problem means moving onto digital certificates that use a more secure SHA-1 or SHA-2 hash function

Source

Tags

Encryption

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th