Welcome | Sign In
CRMBuyer.com
Exploits & Vulnerabilities

Security Wonks Find Gaping Hole in Trusted Site System

Print Version
E-Mail Article
Reprints
Security Wonks Find Gaping Hole in Trusted Site System

Security researchers have cracked open a significant hole in the digital certificate system used by banks and other online businesses. The exploit would allow hackers to more convincingly imitate a trusted site, presenting an opportunity to phish personal information from the victim. The researchers say they informed leading browser makers before going public with the flaw.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

An international group of independent security researchers announced Tuesday that they have found a significant weakness in the Internet digital certificate infrastructure used by many Internet businesses. The flaw could conceivably allow cybercriminals to create fake certificates that would then be accepted and trusted by many widely used Internet browsers.

The purported weakness could enable a hacker to impersonate secure Web sites and e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse servers to launch virtually undetectable phishing attacks, according to the researchers from California, the Netherlands and Switzerland.

The concern is that this bit of technology, known as "Secure Sockets Layer" (SSL), is what banks and other financial institutions as well as online retailers and e-commerce sites use to maintain the security of their transactions.

"The major browsers and Internet players -- such as Mozilla and Microsoft (Nasdaq: MSFT) -- have been contacted to inform them of our discovery and some have already taken action to better protect their users," reassures Arjen Lenstra, head of EPFL's Laboratory for Cryptologic Algorithms.

"To prevent any damage from occurring, the certificate we created had a validity of only one month -- August 2004 -- which expired more than four years ago. The only objective of our research was to stimulate better Internet security with adequate protocols that provide the necessary security," he added.

Weakened Net

Internet users may sometimes notice a small padlock icon that appears at the bottom of the browser when they visit certain Web sites. The icon provides users with assurance that the site they are visiting is secured using a digital certificate issued by the one of a few Certification Authorities (CAs). The certificates act as voucher, enabling the browser to verify its signature using standard cryptographic algorithms.

That's where researchers discovered the weakness. One of the algorithms, MD5, can apparently be used to forge certificates. This, according to the researchers, demonstrates that "a critical part of the Internet's infrastructure is not safe."

Previous MD5 Concerns

This, however, is not the first report of a problem with MD5. In 2004, a team of Chinese researchers presented findings that they were able to conduct a "collision attack," the process of finding two arbitrary values whose hashes collide, and were able to create two separate messages with the same digital signature. Although the Chinese effort was severely limited, another much stronger collision construction was announced in May 2007 by researchers elsewhere.

"It's been known about four years, and there are other certificate policies that could be used. Consumers should know that they can't really trust any site," said Avivah Litan, an analyst at Gartner (NYSE: IT) Research.

Criminals, she told TechNewsWorld, have been successful at launching phishing attacks even without the certificates.

"They don't really need it, and they just keep making more methods that allow them to pose as a legitimate site. [Forging SSL certificates] is a lot of work for very little reward. But it's still not good news that the Internet's security structure is flawed," Litan said.

While Litan said it will take an act of Congress to make the Internet more secure, there are simple measures consumers can implement to better safeguard their financial data.

"The basic step they can take is not to fall for phishing attacks ... You just have to be savvy, never give your PIN (personal identification number) and bank account number away," Litan noted.

Consumers should also be aware and learn how to recognize false forms.

"No retailer is every going to ask for your driver's license, DOB (date of birth), bank account number, etc. Make sure your bank has a policy to protect you. Don't shop at a retailer you're not sure about, and don't use ATMs in the middle of nowhere, don't enter your PIN at a gas station. I only use bank ATMs, never convenience stores, airports, malls, etc. I avoid giving my PIN away even though that's supposed to be more secure. That's the best you can do, and don't give away information that they don't need," she concluded.


Print Version E-Mail Article Reprints More by Walaika Haskins


Talkback: Join the Discussion.
MD5 Encryption on Digital Certificates / SSL
gehansr
Posted 2008-12-30
I maybe wrong here, but isnt MD5 like way out-dated now...? with encryption mechanisms like ...

More by Walaika Haskins

ZeeVee's Zinc Browser Gets Web TV Right
April 29, 2009
The Zinc Browser from ZeeVee updates the old Zviewer with tighter navigation and better catalog options. The finished application offers a great way to find TV shows and movies anywhere on the Web, regardless of whether they're hosted by Hulu, CBS, Netflix, Amazon's on-demand service or others.
Game Sales Sputter, 'GTA' Fails to Steal the Show
April 23, 2009
It may appear as though the video game industry is beginning to join the economy at large in its slump, as March numbers from NPD were less than encouraging. However, a year-over-year perspective is difficult due to the timing of game releases and holidays. Meanwhile, Take-Two hasn't seen much success in introducing its violent "GTA" series to the Nintendo DS.
Can Microsoft Win the Online Game?
April 16, 2009
Now that the major video game consoles have been on the market for two and a half years -- or more -- hardware sales have slowed considerably. Online services, however, still have room to grow. InStat says subscriber bases will take off in the coming years, and Microsoft's Xbox platform may come out the big winner.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network