Iranian state-sponsored cyberwarfare is indistinguishable from script kiddies

Peter Gutmann pgut001 at cs.auckland.ac.nz
Mon Mar 28 19:50:38 PDT 2011


For people who aren't following this via pastebin, to paraphrase Crocodile
Dundee, "you call that a successful CA attack?  *This*
http://pastebin.com/CvGXyfiJ is a successful CA attack":

  "Here is another proof: http://www.multiupload.com/TGDP99CJLH.  I uploaded
  JUST 1 table of their ENTIRE database which I own."

Looks like every Comodo account should now be regarded as compromised.  I
wonder if we'll finally see a CA cert pulled from a browser?  Or does the CA
have to behead someone live on Youtube before the browser vendors will act?

Peter.





More information about the cypherpunks-legacy mailing list