A message from Comodo Hacker
pastebin.com
pastebin.com
After the third remote exploit that I found, my recommendation was that they throw it out and start again, it was a huge jumble of PHP. This hurt their feelings, and a 6 month long argument ensued where they defended their competency.
When I heard 'Italian certificate provider' last week, I thought it could be them, because they went on to launch a certificate project. I am more surprised that Comodo didn't do any due diligence on their resellers. All they had to do was to email my client to ask how their project went, and they would have found out about the clusterfuck.
Huh. He kind of lost all credibility at that point. Breaking RSA isn't something you just decide to do. I'll wait for the day when he announces he's broken it.
However, that does not reflect on whether or not he is the one that is behind the attack on Comodo, which has no real indications of being difficult.
Comodo claims that it must have been an organized, planned out attack because they knew which domains to get certificates for. That does not explain why 3 were generated for one domain and one for 'global trustee'. Nor does it take a genius to figure out a set of domains you would want certificates for depending on what you are planning to do (in this case, it seems like attacking large webmail providers).
After reading him state how astonishing his skills are and how he'll tackle the integer factorization problem, I thought to myself, "he must be a 20 years old university student." Then he states his age.
And so will a massive part of the Computer Science/Mathematics/Physics community. Answering the P vs NP question is kind of a big deal. :D
This is wrong in two ways.
First, a polynomial-time algorithm could still be too slow to be practical, either because the degree of the polynomial were high or because the constant factor or asymptotically disappearing overhead were high.
Second, discrete-logarithm-based cryptography does not depend on the difficulty of integer factorization. That includes Diffie-Hellman, ElGamal, DSA, SRP, and elliptic-curve methods.
You're right that integer factorization is not known to be NP-hard, and so a polynomial-time integer factorization algorithm wouldn't show P=NP.
The most stuff is just lame, but I still appreciate the way how he infiltrated the system.
My Rules as I rule to internet, you should know it already...
Although, I do have to agree with his points about Echelon.
EDIT: His command of the English language is irrelevant -- I stand by my comment above, which is the fact that we are even reading stuff like this makes the 16-year-old-cyberpunk-playing self from the '80s quite happy.