LWN.net Logo

25C3: MD5 collisions crack CA certificate (heise online)

25C3: MD5 collisions crack CA certificate (heise online)

Posted Jan 2, 2009 13:44 UTC (Fri) by vonbrand (subscriber, #4458)
In reply to: 25C3: MD5 collisions crack CA certificate (heise online) by tialaramex
Parent article: 25C3: MD5 collisions crack CA certificate (heise online)

Setting up a CA costs next to nothing, creating a certificate a few pennies (OK, make that dollars if you want) apiece. What does cost real money (and a fixed amount at that) is getting it into MSIE, Firefox, et al. If you set up such a business, you'd want to rake in as much as possible, i.e., compete on end-user price (can't compete on quality, they are all the same; can't compete on "extra services"; "doing things right" is expensive and furthermore drives customers away).

This sort of PKI is fundamentally flawed.


(Log in to post comments)

25C3: MD5 collisions crack CA certificate (heise online)

Posted Jan 2, 2009 16:05 UTC (Fri) by tbleher (guest, #48307) [Link]

> This sort of PKI is fundamentally flawed.

Like Matt Blaze once aptly said:
> A CA will protect you against anyone from whom it won't take money.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds