Tuesday, March 29, 2011

Lone Iranian hacker claims credit for Comodo digital certificate hack

infosecurity.com - Reports are coming in that an independent Iranian hacktivist – portraying himself as a patriot – is claiming credit for the hack of a range of major site certificates from Comodo.

As reported previously, a number of digital certificates were obtained by deception from Comodo that could have resulted in the hijacking of a number of major websites such as lgin.skype.com, mail.google.com, login.live.com and other popular websites.

It now appears that the hacker – who calls him/herself Comodohacker – has posted a series of messages on the Pastebin.com portal, both describing how the hack was carried out and several details that experts are saying appear genuine.

Infosecurity understands that Comodohacker has claimed that GlobalTrust.it and InstantSSL.it, the Italian registration authorities, as potential weak links in the authentication process. This is in keeping with Comodo's claims in the last week that it was a southern European company that was central to the hack.     Read More