[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [saag] X.509 certificate collision, via MD5 collisions
At 18:58 04/03/2005, Robert Zuccherato wrote:
The reason why the randomness in the serial number is able to prevent this
particular attack is that the attacker cannot predict it's value and thus
cannot predict the value of the hash function chaining variable at the
point the public keys begin to get processed. This appears to prevent the
construction of collisions in the public keys.
This was why I suggested in TSP we removed the 'monotonic increasing'
requirement for a TSA serial number during final draft. Mananaging 'random'
serial numbers is not so easy but I rather think it is a requirement.
The attacks highlight the importance of making every bit significant in the
message to be hashed. Aside from certificates, I've got increasingly
worried about the non-rendered and/or highly redundant junk in documents. I
trust logos aren't going to cause problems here.
Adrian Pickering/
University of Southampton, UK