Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your math suggests that you can break a certificate with 2^61 hash operations, but this page says 2^61 operations will only give you a collision:

https://code.google.com/p/hashclash/

With the ability to generate collisions, it becomes easier to trick a CA into signing an evil certificate, but collisions don't help if you want to break someone else's certificate.



By "break", ctz meant "create 2^10 certificates". Creating arbitrary intermediate CAs would indeed compromise the safety of HTTPS.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: