Not really even saying this in a mean way. Almost all top CS programs in the US have assignments on writing buffer overflow attacks and reverse engineering in their mandatory intro to systems course. But I don't seem to see them going off on their own to learn more sophisticated attacks and acutally using it in the real world.
Why does russia seem to foster so many blackhats? Or is it just the proxies that are hosted there?
It seems like Yahoo's PR wants to switch focus to state-sponsored hacking and form a narrative around what's been in the news lately as opposed to Yahoo's incompetence.
Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.
State attack = a state steals the access and keep the breach secret for as long as they can [or until they get hacked themselves]. They use it for espionage and similar purposes
Evil bad guy = all accounts and passwords are already available on blackmarket.com since Day+1 after the breach. They'll probably end up in a torrent within the next month.
Evil bad guy sponsored by a state = Well, somewhere between the two. Hopefully the state ensures they get exclusive access and non disclosure.
> Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.
Seems like you understand just fine.
Like showing up on the doorstep of a CA and asking them to issue forged SSL certificates.
This was relevant for the pinning bug that was just fixed in Firefox 49: normal users shouldn't care about it, but it's very dangerous for Tor users.