6 ms·
This is proof that nations are hacking and spoofing SSL keys in order to spy on its citizens.
by randomstring 16y ago
This is proof that nations are hacking and spoofing SSL keys in order to spy on its citizens.
- gloob 16y agoNo it's not. Even if "most of the IPs involved in the attack came from Iran" constituted proof that the attacker was Iranian, it would not be proof that (1) the attacker was the Iranian government, or that (2) they intended to use the stolen SSL keys to spy on the citizenry of Iran. It is, at best, evidence, not proof. Reasonably strong evidence, mind you.
- biafra 16y agoNot that strong if you consider this: "The attacker was well prepared and knew in advance what he was to try to achieve. He seemed to have a list of targets that he knew he wanted to obtain certificates for, was able quickly to generate the CSRs for these certificates and submit the orders to our system so that the certificates would be produced and made available to him." This makes me think that this could've been prepared anywhere in the world and was made from an Iranian IP address to make it look like it originated in Iran. If they were that prepared why not use a host in a different country?
- trotsky 16y agoIt is the classic "China IP" issue, in that China has become such a famous source for penetrations that other actors appear to prefer Chinese IPs as effective cutouts. But the other side of the coin is that a substantial number of attacks from china IPs do actually get tracked back to individuals or organizations inside China. That would lead one to conclude that if it quacks like a duck, it is, often, a duck.