Cryptography is having a bad week as a new type of attack called SLOTH has weakened trust in encryption even further.
It was presented at the Real World Cryptography Conference in Stanford, USA. The SLOTH attack has the potential to weaken the strength of encryption in various protocols such as TLS, SSH, and IPsec.
The issue lies with our old friends MD5 and SHA-1, two algorithms that have both seen better days. MD5 was first cracked in 2004, while SHA-1 was, at least theoretically, cracked last fall. While higher-level security protocols like TLS (on which HTTPS is based), SSH, and IPsec are considered secure alternatives to HTTP, Telnet, and IP, two security researchers from INRIA (the French Institute for Research in Computer Science and Automation) have discovered that these protocols rely heavily on MD5 and SHA-1 for some of their components. It's called SLOTH, or Security Losses from Obsolete and Truncated Transcript Hashes. The name of this attack is a slap in the face to all those “smart” INFOSEC people who have allowed the weaker MD5 and SHA-1 algorithms to support some of the world’s leading security protocols over the years. In their research paper, the two researchers, Karthikeyan Bhargavan and Gaetan Leurent, present a new transcript collision attack that targets the parts of these security protocols where MD5 is used . In their tests, the two researchers were able to break down a server’s security signature from 128-bit to 64-bit. All of this was done in three hours on a 48-core computing unit, but in a second attempt, after optimizing their calculations, the researchers managed to reduce this time to one hour. “The security losses for other mechanisms, such as TLS client authentication , are even more dramatic, leading to practical attacks on real clients and servers,” the researchers explain in a blog post. As with many other cases in the past, a secure product is only as secure as the technology and people behind it allow it to be!
