Full Name
Christopher Byrd
LinkedIn Profile
http://www.linkedin.com/in/cbyrd01
Twitter
http://twitter.com/cbyrd01
Researchers at the Chaos Computer Club in Moscow just published results of their research into MD5 collisions for x.509 Certificate Authorities. By exploiting weaknesses in RapidSSL's certificate request implementation, they were able to successfully create a valid Intermediate CA certificate trusted by 99+% of browsers. Combined with a man in the middle (MitM) attack such as the Kaminski DNS finding, this would truly break some of the fundamental trust models on the Internet.

Research paper here: http://www.win.tue.nl/hashclash/rogue-ca/
Demo site here: https://i.broke.the.internet.and.all.i.got.was.this.t-shirt.phreedom.org/
There are a couple of interesting related findings from this presentation: