>This is a significant exaggeration, but I'm not going to dox you.
It really isn't. The big number in that charge is referring to coldfusion shells the local CERT was supposedly able to "validate".
At best you could blame the prosecutor for exaggeration, which I entirely agree with, the court however accepted the prosecutors claims.
>Good luck with that visa.
Haven't actually had visa issues anywhere since then :) Good passport I guess.
>Then name it. I have it memorized, and they've changed it, so it's a no-op.
No clue, people within the group disagreed on carding so the person who got it didn't post it on the channel, only dropping the cards of "interesting" individuals. I guess I'll go looking for the logs though.
>It's not brute forceable even by nation states, so you'd have had to extract it by means your entry vector did not give you. Hash it in your reply if you want.
As far as I know someone wrote a quick coldfusion script to extract the decrypted key from memory.
>I've always suspected you had former employee help, and I'm pretty sure I know not only exactly who, but also their motive for assisting you and "HTP".
This was certainly not the case.
>If you do have the passphrase to that key, I can almost promise it was from your assistance. I eagerly await your reply, since the passphrase is a sentence, and once you know it the gist of it is easily communicable without consulting logs.
Don't know, and I'd assume getting coldfusion to spit out the decrypted key is much easier than the decryption passphrase that's only needed once.
And in any case your approach seems fundamentally flawed. Even in some parallel universe where we failed to extract the key, we'd still have been able to use your existing decryption code and the in-memory key to decrypt all the cards in the database.