4 ms·
> break SHA1 SSL certs. It's not possible to break existing SHA1 certificates because this attack is to generate collisions, not finding preimages.
by stepik777 10y ago
> break SHA1 SSL certs.
It's not possible to break existing SHA1 certificates because this attack is to generate collisions, not finding preimages.
- xyzzyz 10y agoYou are thinking about this in a wrong way. It is in fact true that being able to generate collisions allows you to break SSL. What you do is this: generate two certificates with colliding hashes, one for google.com, the other for your own domain. Verisign will gladly sign the second one, since you own the domain, but since the hashes match, you can also use the same signature for the first one. Now you can impersonate google.com. Of course, the real certificate issuance process is more complicated and has some extra precautions to protect from it, my point is that you don't need preimage, collisions should suffice for breaking SSL.
- mike_hearn 10y agoMoreover, how quickly we forget! An intelligence agency did in fact carry out such an attack on code signing certificates using an MD5 collision as part of the FLAME malware.
- deleted 10y ago[deleted]
- agrajag 10y agoThose extra precautions are designed explicitly to prevent the ability to get a certificate using a collision attack. CA's now must explicitly introduce entropy into a certificate to prevent exactly this, and will not sign a certificate exactly to the specifications of a client. There's a great deal of handwaving there saying that a collision attack alone is sufficient for breaking SSL.