Tuesday, 5 April 2011

Google Reader (1000+)

"That was enough to convince the skeptics. Robert Graham of Errata Security described how he verified the digital certificate, meaning that ComodoHacker did have information that only Comodo, or the perpetrator of the intrusion, would be able to obtain. Even Melih Abdulhayoglu, Comodo's founder and chief executive, now says he's convinced of ComodoHacker's identity: 'They've proven themselves,' he said.

Of course, that doesn't mean that anything ComodoHacker says about his age, motivation, nationality, and so on is true. And it's also possible that the original perpetrator shared the private half of the digital certificate with third parties, or that it was a group effort in the first place. On the other hand, ComodoHacker has published still more details, including a decompiled file called TrustDLL, about GlobalTrust's systems.

In a series of e-mail messages over the last week, ComodoHacker said that he took over two more Comodo resellers (which the company partially verified).

He said that he compromised 'one more' certificate authority besides Comodo, and 'if I need I could do more,' but declined to identify which one. When asked whether he obtained fraudulent certificates from it, he replied: 'Sure.'"


Source : Google Reader

No comments: