Iranian hackers obtain fraudulent HTTPS certificates
eff.org
eff.org
I mean, another country in the neighborhood went for strategic ambiguity for many years. It worked very well right until it didn't.
Otoh, Israel hardly needs more trouble.
It is also possible that after Stuxnet, the Iranian government and military have had to consider their options and that this would be an option (bearing in mind that CINIC-signed certificates have been accepted in Firefox for a while and that CINIC have been involved in surveillance ops on people in China).
As for what's actually happening, the people that know are probably unwilling to discuss it on Hacker News or the EFF website.
How many Iranians use Yahoo Mail? How many people of interest outside of Iran use Yahoo Mail?
There's also Perspectives.
There's more information: https://blog.torproject.org/blog/detecting-certificate-autho...
I'd like HTTP SSL encryption and I'll worry abut certification as another problem.
The article's title should sound the same regardless of the hacker's nationality but if it doesn't (there may be a more menacing feel to it) then that's probably thanks to the media's propaganda which would like to put the words "Iranian", "nazi" and "pedophile" on the same level.
Are we going to fall back to the same silly "we're the good guys, they're the bad guys" cold war rhetoric? Come on.