25C3: MD5 collisions crack CA certificate (heise online)
Posted Jan 2, 2009 13:44 UTC (Fri) by
vonbrand (subscriber, #4458)
In reply to:
25C3: MD5 collisions crack CA certificate (heise online) by tialaramex
Parent article:
25C3: MD5 collisions crack CA certificate (heise online)
Setting up a CA costs next to nothing, creating a certificate a few pennies (OK, make that dollars if you want) apiece. What does cost real money (and a fixed amount at that) is getting it into MSIE, Firefox, et al. If you set up such a business, you'd want to rake in as much as possible, i.e., compete on end-user price (can't compete on quality, they are all the same; can't compete on "extra services"; "doing things right" is expensive and furthermore drives customers away).
This sort of PKI is fundamentally flawed.
(
Log in to post comments)