3 ms·
It's possible that a MitM like this is feasible. Recall that the author of the Flame malware that targeted Iranian computers used a hash collision attack on th
by trunnell 13y ago
It's possible that a MitM like this is feasible. Recall that the author of the Flame malware that targeted Iranian computers used a hash collision attack on the MD5 hash for a trusted certificate, which essentially allowed them to create their own certificate that hashed to the same value as the real certificate. [1]
The SHA-1 hash in your average SSL cert might be more expensive to attack than MD5, but that doesn't make me feel much better.
The mitigating factor here is that it seems like this could only be used on a case by case basis against a small number of people, since it would be found out if widely deployed.
Also, we only have evidence of traffic interception and not tampering. Actually writing to the stream, i.e. performing a MitM on an SSL connection, is probably a lot harder than just copying all traffic.
[1] http://arstechnica.com/security/2012/06/flame-crypto-breakthrough/ http://arstechnica.com/security/2012/06/flame-crypto-breakth...
- uh_oh 13y agoWhen the forged certificate was created MD5 has been _throughly_ broken for a long time, much more so than SHA-1 even now.