Comodo SSL Certificates Safe from Black Hat Briefings Vulnerabilities

Published 18th August 2009

Certificates issued by Comodo are prey neither to the "Null Character attack" nor to the "MD2 vulnerability" recently revealed at the Black Hat Briefings in Las Vegas.

Moxie Marlinspike's "Null Character attack" tricks a vulnerable certificate authority (CA) into issuing a certificate that includes a \0 character (NULL) within the domain name. This allows the attacker to fool a vulnerable web browser into trusting the certificate for a domain name that the CA did not validate. Comodo's CA systems have never been vulnerable to this attack.

Dan Kaminsky's "MD2 vulnerability" warns that pre-image attacks against the MD2 hash algorithm are likely to become possible within months. This would allow an attacker to construct trusted certificates that appear to have been issued by a trusted CA certificate that has an MD2-based digital signature. Comodo have never used the MD2 algorithm, so our CA systems and our customers' certificates will not be affected.

The Black Hat Briefings is a regular industry gathering of computer security and government professionals, as well as respected hackers. http://www.blackhat.com/

"Comodo is proud to announce that none of its certificates is vulnerable to either threat," said Melih Abdulhayoglu, CEO and Chief Security Architect of Comodo, the largest issuer of high-assurance digital certificates. "The study is interesting, but, fortunately, it does not apply to Comodo's certificates."