Diginotar and Comodo hacker the same guy and claims to have owned 4 other CAs
f-secure.com
f-secure.com
https://pastebin.com/u/ComodoHacker
And to his latest post:
He claims some injustice about 10,000 Muslim soldiers being killed. How many Muslims in Iran are going to be killed for writing something against the clerics in Gmail?
The harm is already there and possible, he's just forcing the issue. An "Anonymous" with a different agenda. It doesn't help "humanity" to believe that the CA system works when it's been totally subverted.
If this guy has done it, so have many others in all likelihood.
this is what humans do. At least have been doing from the times when humans started to be able to have an idea and right up to now, and no indications so far what things are going to change in any foreseeable future. And you're right - that ability and appetite for doing intentional harm makes humans a very disgusting species.
What can make scientists with a literary gift so interesting is that their formal position helps them sit on the cusp, looking forward, while their literary skills help them articulate what they see coming.
1. Have a proper & independent security audit of all root CAs. 2. Have a long, hard think about the SSL policies of some major websites. Facebook and GitHub, for instance, use certs issued by two different CAs. This makes it that much harder for me to make an informed judgement about their validity. 3. Rethink the whole trust model. It hinges on the policies of some companies out to make money, rather than out to secure the internet. These money-grabbing folks seem a lot more interested in the money-grabbing part than in the securing part.
Yes, the way he/she is bragging about '1337 hacker' skills is pretty 'lulzy'. I am not a security geek, but I find it amusing to see someone bragging about skills I consider to be something not worth mentioning.
This person certainly has patience when it comes to Googling.
The most embarrassing thing that can happen to a security company is getting owned by someone like this.
I'd put money on all of them involving basic social engineering and spear phishing with PDFs.
1. Not all the hacks require ninja skills, there's plenty of big targets with really low security that you can hack just by using publicly available automated tools. Also you need to consider that lots of crackers don't carry out targeted attacks. They need to hack a CA, there's plenty CAs in the world, all you need to find is one with bad security. You don't need to go after a big one, you don't need to go after the most protected application/infrastructure of them.
2. A person can have great skills and publicly brag about his hacks (Kevin Mitnick is a good example)
3. Another version of this, someone can have ninja skills and can be an ass at the same time (quite common in security industry)
At the moment, I'm reading Kevin Mitnick's Ghost in the Wires (awesome book, by the way). He pretty much owned the entire phone system in California. In some cases, he was able to do things even phone company techs were not able to do. About halfway through the book he describes how he was able to tap the people tapping his own phone lines. What he pulled off was absolutely massive. The phone companies didn't even want to report some of it because of how ridiculous they would look for letting it happen. And as good as he was, no employer wanted to touch him with a 10 foot pole.
My point is that unbelievably huge breaches can be and have been pulled off before. As for him announcing it publicly, I can only speculate on his motives. Maybe he wants to see them squirm. Maybe he's feeling a bit invincible right now. I don't know. But I sure wouldn't dismiss him as full of shit because the claims are so audacious or for the fact that he's bragging about it. We do know that a breach occurred and the victims sure as hell aren't going to reveal the full extent.
firefox plugin - http://www.networknotary.org/firefox.html background - http://perspectives-project.org/
....but that's a... less.... oh nevermind