Recent advances push Big Tech closer to the Q-Day danger zone



Sometime around 2010, sophisticated malware known as Flame hijacked the mechanism that Microsoft used to distribute updates to millions of Windows computers around the world. The malware—reportedly jointly developed by the US and Israel—pushed a malicious update throughout an infected network belonging to the Iranian government.

The lynchpin of the “collision” attack was an exploit of MD5, a cryptographic hash function Microsoft was using to authenticate digital certificates. By minting a cryptographically perfect digital signature based on MD5, the attackers forged a certificate that authenticated their malicious update server. Had the attack been used more broadly, it would have had catastrophic consequences worldwide.

Getting uncomfortably close to the danger zone

The event, which came to light in 2012, now serves as a cautionary tale for cryptography engineers as they contemplate the downfall of two crucial cryptography algorithms used everywhere. Since 2004, MD5 has been known to be vulnerable to “collisions,” a fatal flaw that allows adversaries to generate two distinct inputs that produce identical outputs.

Read full article

Comments



Source link

  • Related Posts

    Google’s AI Mode can now help you find products in stock nearby

    Google is rolling out new features that are designed to help with planning summer travel. The tech giant announced on Friday that its agentic AI within AI Mode can now…

    Roblox agrees to a $12 million settlement with Nevada

    Amidst ongoing legal trouble with several states and more than 100 pending lawsuits, this week Roblox announced a $12 million settlement with Nevada, allowing the company to avoid going to…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Google’s AI Mode can now help you find products in stock nearby

    Google’s AI Mode can now help you find products in stock nearby

    UPS Pilot Aborts Landing As Runway Safety Violated

    UPS Pilot Aborts Landing As Runway Safety Violated

    Birmingham is awash with local election candidates – but will result be a ‘coalition of chaos’? | Birmingham

    Birmingham is awash with local election candidates – but will result be a ‘coalition of chaos’? | Birmingham

    Singer D4vd arrested in connection with death of teen girl

    Singer D4vd arrested in connection with death of teen girl

    Iran announces the Strait of Hormuz is open

    Iran announces the Strait of Hormuz is open

    Roblox agrees to a $12 million settlement with Nevada

    Roblox agrees to a $12 million settlement with Nevada