PDA

View Full Version : MD5 officially Insecure



Nflight
01-05-2009, 09:38 AM
http://www.dailytech.com/MD5+Is+Officially+Insecure+Hackers+Break+SSL+Certi ficates+Impersonate+CA/article13842.htm

Now what are they gonna use in its replacement? :sad5:

AMDave
01-05-2009, 10:29 AM
The 25C3 presenters claim they were able to run the attack in only four weekends, using a network of 200 PlayStation 3 game consoles at a cost of $657.That is 3 Dollars and 28 cents per console.
I don't see any of those in the shops. :icon_lol:

Yes, I know that they really mean the rented them for 4 weekends
8 days
41 cents per console per day.
Hey.
That IS really cheap for a cluster lease rate.

They did answer your question though:

many CAs have moved on to the more secure SHA-1 or SHA-2 algorithms

Brucifer
01-05-2009, 05:06 PM
Nothing is secure. Nothing is unbreakable. Whether or not it is worth the time and effort to crack something is the question. A padlock just stops a large number of people, not the ones that really want to destroy the padlock and have the toolbox with them to do it. The same goes with the crypto world. The banking world and all the hacking that goes on by the "forces of evil" demonstrate over and over how insecure much of the worlds public and commercial business security is. What has surprised me really is that after the issues of MD5 became known, that the applied science in encryption didn't move forward another generation and replace it..... well really we all know why... it would have cost some entity more money than they cared to put into it. And maybe, just maybe some ego's would have to be swallowed. A no brainer really as we seem to keep repeating this scenario over an over on about everything humans get involved with.

Frederic Brillouet
01-07-2009, 11:10 AM
I think we need to get a simpler algorithm: you crack my code, I put an axe in your head. Medieval style :icon_razz:

Brucifer
01-07-2009, 05:26 PM
I think we need to get a simpler algorithm: you crack my code, I put an axe in your head. Medieval style :icon_razz:

Golly Gee, that wouldn't be politically correct! :icon_rolleyes::icon_rolleyes:

Nflight
01-07-2009, 05:34 PM
I think we need to get a simpler algorithm: you crack my code, I put an axe in your head. Medieval style :icon_razz:

Coming from a man who is studying how to use a scalpel correctly you have an evil side to you Frederic, Just don't let your future patients see that and you will be ok~!

liuqyn
01-07-2009, 06:22 PM
Coming from a man who is studying how to use a scalpel correctly you have an evil side to you Frederic, Just don't let your future patients see that and you will be ok~!

they would be sedated anyway, so no worry there.:icon_twisted: