Verisign/RapidSSL Responds To Certificate Vulnerability
blogs.verisign.com
blogs.verisign.com
I really like this, especially the last sentence. That's refreshingly direct communication.
A: Zero. No end entity certificates are affected by this attack. The attack, when it worked, was a potential method for a criminal to create a new, false certificate from scratch. Existing certificates are not targets for this attack."
This answer seems a little bit, well, disingenuous. Does he not understand the attack or does he not understand SSL?
http://www.win.tue.nl/hashclash/rogue-ca/
Scroll to the bottom in the question/answer section. It's interesting they only used 200 PS3 game consoles to do their computations with.
"Question. Suppose that a criminal creates by our method his own rogue Certification Authority that is trusted by all browsers. Are then only websites with certificates from the CA whose signature he used vulnerable to impersonation attacks? Are only websites with certificates based on MD5 vulnerable to impersonation attacks?
Answer. No. When a criminal uses redirection attacks in combination with a rogue but trusted CA certificate, all websites are equally vulnerable."
Gotta admit, a solid response.
That being said, I would have liked for them to say that they've reviewed their logs and saw no other issuance activity that followed the same pattern as the researchers, and that they will improve their operational monitoring and serial number sequencing to help protect against future potential attacks.