Hack

Sharing Fingerprints

  • March/April 2009
  • By Erica Naone

Hackers can manipulate outdated algorithms to give two very different documents the same digital signature.

   

Sensitive online documents, such as certificates that vouch for banking sites, bear "digital fingerprints" that identify them without revealing their contents. The fingerprints are produced from the documents' contents by algorithms that are supposed to be irreversible. But recently, older varieties of the algorithms have been weakened. The venerable MD5, for example, has been broken, making it easy to introduce a forgery. Marc Stevens, a PhD student in cryptology at the Centrum Wiskunde and Informatica in Amsterdam, the Netherlands, has created a series of demonstrations of how MD5 can fail. One is shown here: though the two faces are different, their digital fingerprints are the same. This is a harmless ­example, but it has serious implications for digital forensics.

A. Two Documents
Digital fingerprints are sometimes used to filter out known files among the thousands on a suspected criminal's computer, helping investigators to focus on files that might contain evidence or contraband. But Marc Stevens can use the broken MD5 encryption algorithm to give two files the same fingerprint--as, for example, with the two images shown here. If a harmless manipulated file gets its fingerprint listed in a commonly used library, malicious files sharing its fingerprint could fly under the radar.

 

To read the entire article you must log in:

Most of our content — all daily news, blogs, and videos — is free. Magazine stories are paid. To read this story, you must have a subscription or you must use a reading credit. Registration to Technology Review is free and entitles registrants to three free reading credits.

Username or REGISTER
Password  
   
 
Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Sponsored Content

Technologies from National Instruments

Adding Data Logging
Log measured data to a file and open it in Microsoft Excel

> Click here for more National Instruments Videos <
Whitepaper

Temperature Measurements with Thermocouples: How-To Guide

This document is part of the “How-To Guide for Most Common Measurements” centralized resource portal. This tutorial provides a detailed guide for measurement and device considerations to take temperature measurements using thermocouples. Get an introduction to thermocouples, which are inexpensive sensing devices widely used with PC-based data acquisition systems. Also review some specific thermocouple examples and learn how thermocouples work and ways to integrate them into a data acquisition measurement system.

View full PDF > Listen to story >
Find us on Youtube

Videos

Meet 2011 TR35 Winner Jesse Robbins

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Toyota

Amyris

HTC

BrightSource Energy

More

Advertisement

Facebook

Advertisement