#035 · Security ProfessionalsRareLocked in

Alex Sotirov

The Rogue CA Demonstration

MD5 collisions against a real certificate authority

Rating

83Impact score
Technical depth96
Defensive craft84
Research94
Influence84
FromBulgaria / USA
Era2007–present

Domains

PKIExploit mitigationBrowser security

Scouting report

Co-authored “Bypassing Browser Memory Protections”, the 2008 paper that showed how attackers were routing around DEP and ASLR, then at 25C3 the same year demonstrated a working rogue certificate authority built on MD5 collisions — which pushed the CA industry off MD5 for good. Co-founded Trail of Bits.

Curator’s note

Demonstrated the theoretical break against a live CA, which is the only kind that moves anyone.

Portrait

Painted from a photograph of Alex Sotirov by Alexander Klink, licensed CC BY 3.0.