What exactly wasn't believable about it before? Linode confirmed that someone cracked into their system on their blog, which I consider as being confirmation enough for everything.
FBI moles, compromise of a fairly large registrar, etc.
I guess I just didn't see a reason for HTP to lie about it, especially with several smaller pieces out there confirming large portions of it.
I suppose I don't understand why it's necessary to know if HTP was being 100% honest when the big details have been confirmed.
This is the first confirmation I've seen of Name.com being hacked. That's a fairly significant sticking point, particularly as the known attack vector on Linode was a ColdFusion exploit, not a complete takeover of their registrar...
The name.com sample data HTP showed in their log by querying the database was real. Source: I work for one of the companies they used as sample rows when querying the name.com DB. Our head of ops confirmed that the hash in the HTP log was indeed the MySQL 4.1 PASSWORD() unsalted hash of our password at the time. name.com is kind of generous with the term "encrypted" in their email.