Iranian state-sponsored cyberwarfare is indistinguishable from script kiddies
Pretty much every news report I've seen so far that mentions any kind of Iranian connection is claiming that it's Iranian state-sponsored hacking. If what's happened with the certs so far (someone grabbed a few sample certs for high-profile domains, and there was a report of one of them briefly appearing on a test server in Iran) is an indication of their competence then we really have nothing to fear from them. Let's look at what would have happened if *I'd* figured out a way to compromise a CA. First, I'd get a few test certs issued for high-profile domains, Microsoft, Google, Yahoo, and perhaps a CA cert just for giggles. Then I'd set up a server somewhere and install one of the sample certs to see whether any web browser noticed a problem. Gosh, this sounds awfully like what actually happened. New Zealand must have a state-sponsored cyberwar program! The only difference in my case is that after a day or so of inviting security people to have a giggle at the test server with my "genuine" cert, I'd notify the CA about the problem. If I was an Iranian script kiddie I probably wouldn't have much motivation to do that. So what we have here is either (a) the world's most incompetent state- sponsored cyberwar program, who get the keys to the kingdom and then have no idea what to do with them, or (b) a bunch of script kiddies having fun. What do you reckon the odds are? (And in all this I haven't seen any mention of the Al Kai-yee-da angle. What happened, is everyone asleep?). Peter.
On Fri, Mar 25, 2011 at 9:34 PM, Peter Gutmann <pgut001@cs.auckland.ac.nz> wrote:
Pretty much every news report I've seen so far that mentions any kind of Iranian connection is claiming that it's Iranian state-sponsored hacking.
pretty amusing, to be sure. (years ago i quit being frustrated by lazy, inaccurate, attention porn news programming and decided to be amused instead. i am often amused! there are worse things...)
If ... [this] ... is an indication of their competence then we really have nothing to fear from them.
nothing in the "cyber domain", certainly. they're quite adept at old skewl though...
So what we have here is either (a) the world's most incompetent state- sponsored cyberwar program, who get the keys to the kingdom and then have no idea what to do with them, or (b) a bunch of script kiddies having fun. What do you reckon the odds are?
considering the poorly deployed, poorly managed, poorly maintained iranian networking and computing systems in question, Occam says someone having fun through iranian pwn hops... (not to mention, who better to place blame upon? what a great diversion! :)
On Sat, Mar 26, 2011 at 11:11 PM, coderman <coderman@gmail.com> wrote:
..
Pretty much every news report I've seen so far that mentions any kind of Iranian connection is claiming that it's Iranian state-sponsored hacking.
now you can point them at: http://pastebin.com/74KXCaEZ comodo ceo a fucking dunce and tool. send your csr anywhere else!
considering the poorly deployed, poorly managed, poorly maintained iranian networking and computing systems in question, Occam says someone having fun through iranian pwn hops...
even if that someone is themselves persian... , a few choice quotes in the correspondence. c.f.: """ 'I heard that some stupids tried to ask about it from Iran's ambassador in UN, really? How smartass you are? Where were you when Stuxnet created by Israel and USA with millions of dollar budget, with access to SCADA systems and Nuclear softwares? Why no one asked a question from Israel and USA ambassador to UN?' ""
participants (2)
-
coderman
-
Peter Gutmann