The researchers are keeping the precise details of their solution secret to avoid giving hackers too much information. However, the main problem they exploited is that some certification agencies use an outdated encryption system known as MD5.
This system uses what is effectively a password of 32 letters or numbers. When the system was created in 1991, it seemed complex enough that hackers couldn’t efficiently figure out each password. However, with today’s increased computing power, that has proven possible: the researchers used a bank of 300 Playstation 3s to, put simply, try out every possible password until they found one that worked.