Live data from Hacker News

A message from Comodo Hacker

pastebin.com

31–40 of 44 posts

Re: A message from Comodo Hacker

#33
I come off with the feeling it is actually composed by an Iranian (possibly a team but could be an individual) who is clearly motivated to make "politically correct" (from the POV of the Iranian govt.) speeches. He goes to great lengths to praise his government, ambassador and president while denouncing all dissidents, separatists, Israel and the US. I cannot help feeling he/they have some connection with the government. Possibly the whole teenage cyberpunk rhetoric was deliberate (see repeated "hard for you easy for me" and "I was so fast" and the absurd "I will factor large integers") and little more than a poorly executed smoke screen to divert attention.

Re: A message from Comodo Hacker

#34
post #20
post #7

> At first I decided to hack RSA algorithm, I did too much investigation on SSL protocol, tried to find an algorithm for factoring integer, analyzed existing algorithms, for now I was not able to do so, at least not yet, but I know it's not impossible and I'll prove it Huh. He kind of lost all credibility at that point. Breaking RSA isn't something you just decide to do. I'll wait for the day when he announces he's b…

I came here to post exactly that. After reading him state how astonishing his skills are and how he'll tackle the integer factorization problem, I thought to myself, "he must be a 20 years old university student." Then he states his age.

Yes, the posturing did not lend credibility to his statements. Besides that, it seems vaguely plausible.

Re: A message from Comodo Hacker

#35
post #29

Earlier quoted context omitted.

> I'll wait for the day when he announces he's broken it. And so will a massive part of the Computer Science/Mathematics/Physics community. Answering the P vs NP question is kind of a big deal. :D

No. Integer factorization is not NP-hard (so not NP-complete). (This isn't proven, but it's generally thought to be the case.) So, while doing a polynomial-time integer factorization would be hugely significant (and make all asymmetric encryption in the world useless), it would not prove P=NP.

> So, while doing a polynomial-time integer factorization would be hugely significant (and make all asymmetric encryption in the world useless)

This is wrong in two ways.

First, a polynomial-time algorithm could still be too slow to be practical, either because the degree of the polynomial were high or because the constant factor or asymptotically disappearing overhead were high.

Second, discrete-logarithm-based cryptography does not depend on the difficulty of integer factorization. That includes Diffie-Hellman, ElGamal, DSA, SRP, and elliptic-curve methods.

You're right that integer factorization is not known to be NP-hard, and so a polynomial-time integer factorization algorithm wouldn't show P=NP.

Re: A message from Comodo Hacker

#36

That's some serious Miyamoto Musashi rhetoric there. The guy's either a grade A rationalist or a massive douchebag. I put odds at 5/95.

Can you elaborate on the "grade A rationalist" remark? Does attempting to compensate for one's cognitive biases generally blind one to how one sounds to others?

Re: A message from Comodo Hacker

#37
post #30

I think I kind of know, but for the uninitiated, can someone tell us what the potential practical consequences of this hack could have been?

If you combined these evil SSL certs with the right BGP hijack, you could read a lot of people's email and such. And since reading mail lets you reset passwords on everything else, he could have basically owned millions of people.

BGP, or DNS, or your DSL modem or cable modem, or an open access point, or the router in an internet cafe, or...

Re: A message from Comodo Hacker

#39
post #12
post #7

> At first I decided to hack RSA algorithm, I did too much investigation on SSL protocol, tried to find an algorithm for factoring integer, analyzed existing algorithms, for now I was not able to do so, at least not yet, but I know it's not impossible and I'll prove it Huh. He kind of lost all credibility at that point. Breaking RSA isn't something you just decide to do. I'll wait for the day when he announces he's b…

Hasn't everyone woken up some day and said "hey, I'm gonna break RSA today"? I guess that only happens when you have the experience of 1000 hackers...

LOL. Does this guy think he's really going to scare us with lines that could've come from a Michael Bay movie??

Re: A message from Comodo Hacker

#40

So it takes the "skill of 1000 programmers" to write a program to send POST requests to an HTTP API? He must have been writing his client in Java...

I wonder whether that hyperbole of '1000 ...' is due to mistranslating some Iranian idiom. Not that it would make the assertion any better.
Post reply on HN