Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Web browser flaw could put e-commerce security at risk
CNET News ^ | December 30, 2008 | Jonathan Stray

Posted on 01/03/2009 9:26:06 AM PST by snowsislander

BERLIN--A key piece of Internet technology that banks, e-commerce sites, and financial institutions rely on to keep transactions safe suffers from a serious security vulnerability, an international team of researchers announced on Tuesday.

They demonstrated how to forge security certificates used by secure Web sites, a process that would allow a sufficiently sophisticated criminal to fool the built-in verification methods used by all modern Web browsers--without the user being alerted that anything was amiss.

The problem is unlikely to affect most Internet users in the near future because taking advantage of the vulnerability requires discovering some techniques that are not expected to be made public as well as overcoming engineering hurdles: performing the initial digital forgery consumed approximately two weeks of computing time on a cluster of 200 PlayStation 3 consoles. In addition, a criminal needs to find a way to reroute traffic from a legitimate Web site to his own, perhaps through techniques that have become well-known in the last few years.

Yet if one group can do it today, others eventually will. "We have a proof-of-concept that allows us to impersonate any supposedly secure Web site on the Internet," said David Molnar, a doctoral student in computer science at the University of California at Berkeley.

(Excerpt) Read more at news.cnet.com ...


TOPICS: Business/Economy; News/Current Events; Technical
KEYWORDS: cybersecurity; ecommerce; md5; ssl
Here are some related articles:

Microsoft: MD5 hack poses no major threats to users

Creating a rogue CA certificate (original source; good technical explanations and it has collected official responses from Microsoft, Mozilla, Verisign, and others.)

SSL Crack Shows You Must Advance Your Security

MD5 insecurity affects all internet users

1 posted on 01/03/2009 9:26:06 AM PST by snowsislander
[ Post Reply | Private Reply | View Replies]

To: snowsislander

In one article these guys are an “international team or researchers” and in another they are “hackers”. What gives?


2 posted on 01/03/2009 9:34:13 AM PST by maclay (SEEKING: Global Warming Alarmist for Martian Terraform Press Secretary)
[ Post Reply | Private Reply | To 1 | View Replies]

To: maclay

or = are, sorry


3 posted on 01/03/2009 9:34:53 AM PST by maclay (SEEKING: Global Warming Alarmist for Martian Terraform Press Secretary)
[ Post Reply | Private Reply | To 2 | View Replies]

To: snowsislander

Isn’t it nice of the press to offer them the Betty Crocker Crook Book?


4 posted on 01/03/2009 9:35:04 AM PST by G Larry (BarackÂ’s character has been molded by extremists)
[ Post Reply | Private Reply | To 1 | View Replies]

To: G Larry

The bad guys and the good guys have know this was possible for months/years.


5 posted on 01/03/2009 9:46:32 AM PST by DevNet (!dimensio || !solitron)
[ Post Reply | Private Reply | To 4 | View Replies]

To: snowsislander

Alarmism and the ‘net go hand in hand but SSL underpins all current e-commerce sites.

Think of it as having a passkey to every room in every hotel and you can grasp the potential impact.


6 posted on 01/03/2009 9:47:50 AM PST by relictele
[ Post Reply | Private Reply | To 1 | View Replies]

To: DevNet

It’s kinda like legalizing drugs, expanding the pool and rate of decay doesn’t help anybody.


7 posted on 01/03/2009 9:51:59 AM PST by G Larry (BarackÂ’s character has been molded by extremists)
[ Post Reply | Private Reply | To 5 | View Replies]

To: G Larry
It’s kinda like legalizing drugs,

Maybe using drug warrior logic, I guess. In reality, the failed drug war is a farce.
8 posted on 01/03/2009 9:55:10 AM PST by mysterio
[ Post Reply | Private Reply | To 7 | View Replies]

To: maclay
In one article these guys are an “international team or researchers” and in another they are “hackers”. What gives?

They are researchers.

9 posted on 01/03/2009 9:56:28 AM PST by snowsislander (NRA -- join today! 1-877-NRA-2000)
[ Post Reply | Private Reply | To 2 | View Replies]

To: mysterio
I don't much care about opinions on the success or failure of the drug war.

The fact is that expanding the pool of pollutants in society doesn't help.

10 posted on 01/03/2009 10:27:23 AM PST by G Larry (BarackÂ’s character has been molded by extremists)
[ Post Reply | Private Reply | To 8 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson