Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Issues » 2009 » 100 » BROKEN CHAIN OF TRUST  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

The death of MD5 (and some SSL certificates)

BROKEN CHAIN OF TRUST

Author(s): KURT SEIFRIED

Researchers set out to compromise MD5 in an effort to convince people to stop using it. We explain how the attack worked and what this means for you.

Message Digest algorithm 5 (MD5 for short) is a one-way cryptographic hashing function. Put in its simplest terms, it takes input, mangles it, and generates a 128- bit value (usually expressed as a 32-character hexadecimal number). The same input (e.g., password) will alwayshave the same output. So why use MD5? When cryptographically signing data (such as email or SSL certificates), it is much more efficient to sign a cryptographic signature of the data rather than the entire block of data itself.


Read full article as PDF »


Comments

ND5 signing certificates

David Williams Feb 05, 2009 12:23pm GMT

An interesting article on encryption algorithms, but more detail is needed about some of the comments about CAs in web-browsers. As Kurt states, some (but not all) of the Thawte & Verisign CAs use MD5 (& in some cases MD2) as their signature algorithm. However as far as I can tell this is not the case for any of the certificates from Comodo - they all seem to use SHA1. Perhaps I have a fully updated system for these certificates (I hope so) which has addressed the concerns, or are Kurt's comments about a different company?

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
TAG MASTER Public key infrastructure with the Dogtag certificate system
Get your backstage pass to Linux!

If you're ready for a deeper look, Linux Magazine gives you a view behind the scenes.

Don't miss out on the tools, tutorials, and reviews you'll need to unlock the secrets of Linux.

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]