Results tagged “firefox”

Forged CA Certificate

This news is a couple weeks old, but I wanted to mention it anyway. Several years ago I mentioned a flaw in MD5. Seeking a proof of concept, a team of researchers successfully forged a CA certificate that could sign any certificate they desired. The resulting certificate would be implicitly trusted by all major web browsers. The team presented their results at the 25th Chaos Communication Congress last month in Berlin.

I wanted to briefly describe their ingenious technique but gave up after realizing how many prerequisite concepts I'd need to introduce. Read their excellent paper if you're interested in the details. The team used a farm of PlayStation 3 consoles to compute a CA certificate that collided with a carefully crafted certificate issued by RapidSSL.

There's no immediate risk to users. This development is primarily a wakeup call to certificate authorities to stop relying on MD5 immediately. MD5 is broken.

50 Million Downloads

The popular open-source Firefox web browser hit 50 million downloads yesterday. TechWeb estimates that 1 in 10 "business professionals" use Firefox, and that percentage is expected to double again next quarter.

1
Creative Commons License
This blog is licensed under a Creative Commons License.

Find recent content on the main index or look in the archives to find all content.

Recent Comments

  • jay Donnell: I'm sure they will go in that direction in the read more
  • jay: I'm going tomorrow :) read more
  • jay: You should have linked some of the stats :) I'm read more
  • Sue Denim: I only have on thing to say: XBOX read more
  • jay: If unemployment is high would a lack of a minimum read more
  • jay: Saying that we need to cut unnecessary social programs (I'm read more
  • Matthew: Davis's tripling of the vehicle registration fees amounted to some read more
  • jay: You're point is a bit implicit so please forgive me read more
  • Zack: That's pretty awesome. read more
  • Zack: I knew it. I'm going to go invent my own read more