<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: An unauthorized certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. This issue affects all supported releases of Microsoft Windows.</title>
	<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows/</link>
	<description>Comments on MetaFilter post An unauthorized certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. This issue affects all supported releases of Microsoft Windows.</description>
	<pubDate>Fri, 08 Jun 2012 11:19:16 -0800</pubDate>
	<lastBuildDate>Fri, 08 Jun 2012 11:19:16 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>An unauthorized certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. This issue affects all supported releases of Microsoft Windows.</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows</link>	
		<description>&lt;a href="http://en.wikipedia.org/wiki/Flame_(malware)"&gt;&quot;Flame&quot;&lt;/a&gt; is the name of a &lt;a href=&quot;http://venturebeat.com/2012/06/05/security-researchers-flame-malware-is-a-nightmare-scenario/&quot;&gt;newly-identified malware program&lt;/a&gt; which utilizes a previously unknown &lt;a href=&quot;http://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-cryptographic-attack-variant-in-flame-spy-malware&quot;&gt;MD5 collision attack&lt;/a&gt; to successfully spoof Microsoft Terminal Services, and install itself as a trusted program using Windows Update, &lt;a href=&quot;http://blogs.technet.com/b/srd/archive/2012/06/06/more-information-about-the-digital-certificates-used-to-sign-the-flame-malware.aspx&quot;&gt;Microsoft has confirmed. &lt;/a&gt;The program appears to have targeted computers in the Middle East, &lt;a href=&quot;http://www.guardian.co.uk/commentisfree/2012/jun/08/obama-virus-wars-mutually-assurred-cyberdestruction&quot;&gt;and specifically Iran&lt;/a&gt;; analysts have alleged it is&lt;a href=&quot;http://www.informationweek.com/news/security/attacks/240001271&quot;&gt; likely created by the same entity&lt;/a&gt; that designed Stuxnet.  Flame has been &lt;a href=&quot;http://arstechnica.com/security/2012/06/flame-espionage-malware-used-huge-network-to-steal-blueprints/&quot;&gt;live and actively spying since 2010&lt;/a&gt;, but went undetected until recently, due to &lt;a href=&quot;http://www.redorbit.com/news/technology/1112551027/flame-malware-attempts-to-thwart-detection-with-suicide-code/&quot;&gt;sophisticated anti-detection measures.&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;While &lt;a href=&quot;http://openchannel.msnbc.msn.com/_news/2012/05/29/11945479-was-flame-virus-that-invaded-irans-computer-networks-made-in-usa?lite&quot;&gt;anonymous US officials have claimed responsibility &lt;/a&gt;for the program, officially both the  &lt;a href=&quot;http://livewire.talkingpointsmemo.com/entries/un-telecom-chief-us-not-behind-flame&quot;&gt;USA&lt;/a&gt; and &lt;a href=&quot;http://www.bbc.co.uk/news/technology-18277555&quot;&gt;Israel&lt;/a&gt; have denied any involvement.</description>
		<guid isPermaLink="false">post:www.metafilter.com,2012:site.116762</guid>
		<pubDate>Fri, 08 Jun 2012 11:13:00 -0800</pubDate>
		<dc:creator>mek</dc:creator>		<category>flame</category>		<category>cybersecurity</category>		<category>malware</category>		<category>worm</category>		<category>trojan</category>		<category>virus</category>		<category>USA</category>		<category>israel</category>		<category>iran</category>		<category>politics</category>		<category>security</category>		<category>computers</category>		<category>internet</category>		<category>espionage</category>
	</item>	<item>
		<title>By: Bathtub Bobsled</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387131</link>	
		<description>What&apos;s the likelihood the entity that created this had direct consultation with some salaried folks in Redmond, Washington?

P.S. &quot;Flame&quot; is one letter above lame. Next time you guys are naming these things, PM me and I&apos;ll come up with some awesome names... if Weedlord Bonerhitler isn&apos;t already in use...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387131</guid>
		<pubDate>Fri, 08 Jun 2012 11:19:16 -0800</pubDate>
		<dc:creator>Bathtub Bobsled</dc:creator>
	</item>	<item>
		<title>By: The Lamplighter</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387136</link>	
		<description>If they had Microsoft&apos;s help I don&apos;t think they would need to use an unknown MD5 collision.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387136</guid>
		<pubDate>Fri, 08 Jun 2012 11:21:06 -0800</pubDate>
		<dc:creator>The Lamplighter</dc:creator>
	</item>	<item>
		<title>By: Bathtub Bobsled</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387139</link>	
		<description>Actually, that&apos;s a very good point Lamplighter.

Disregard.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387139</guid>
		<pubDate>Fri, 08 Jun 2012 11:23:35 -0800</pubDate>
		<dc:creator>Bathtub Bobsled</dc:creator>
	</item>	<item>
		<title>By: mullingitover</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387147</link>	
		<description>A collision attack!? &lt;a href=&quot;http://www.kb.cert.org/vuls/id/836068&quot;&gt;Who could&apos;ve seen that one coming&lt;/a&gt;?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387147</guid>
		<pubDate>Fri, 08 Jun 2012 11:27:13 -0800</pubDate>
		<dc:creator>mullingitover</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387154</link>	
		<description>I&apos;ve been following this the past couple days and I&apos;ve been particularly interested in how they used the terminal services cert to sign bogus updates. From what I hear, signing bogus updates with a terminal services cert just worked in for older versions of windows but newer versions had additional checks in place. The MD5 collision attack was used to bypass the checks in newer versions. 

An additional wrinkle is that Flame has started uninstalling itself after a command was sent out by whoever created it.

It is kind of awe inspiring to think whoever created it used an entirely new collision attack for malware instead of say publishing it and becoming famous.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387154</guid>
		<pubDate>Fri, 08 Jun 2012 11:29:58 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: mr_roboto</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387157</link>	
		<description>I cannot wait for the blowback from this one.  The best consequences are always the unintended ones!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387157</guid>
		<pubDate>Fri, 08 Jun 2012 11:31:18 -0800</pubDate>
		<dc:creator>mr_roboto</dc:creator>
	</item>	<item>
		<title>By: aspo</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387159</link>	
		<description>&lt;i&gt;It is kind of awe inspiring to think whoever created it used an entirely new collision attack for malware instead of say publishing it and becoming famous.&lt;/i&gt;

That&apos;s the downside of working for the NSA...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387159</guid>
		<pubDate>Fri, 08 Jun 2012 11:31:59 -0800</pubDate>
		<dc:creator>aspo</dc:creator>
	</item>	<item>
		<title>By: rh</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387166</link>	
		<description>&lt;em&gt;That&apos;s the downside of working for the NSA...&lt;/em&gt;

The upside? &lt;a href=&quot;http://www.nsa.gov/public_info/press_room/2012/a4_hawaii_final.shtml&quot;&gt;Hawaii and rainbows&lt;/a&gt;!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387166</guid>
		<pubDate>Fri, 08 Jun 2012 11:35:53 -0800</pubDate>
		<dc:creator>rh</dc:creator>
	</item>	<item>
		<title>By: mmrtnt</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387172</link>	
		<description>&lt;i&gt;The best consequences are always the unintended ones!&lt;/i&gt;

Because the US government and Microsoft can work hand-in-hand to backdoor &quot;enemies&quot;, it won&apos;t be long before all the bad guys just use Linux instead.

Unintended Consequence: Anyone using Linux is possibly a terrorist.

Also, &lt;a href=&quot;http://botaday.com/node/999&quot;&gt;this&lt;/a&gt; seems appropriate.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387172</guid>
		<pubDate>Fri, 08 Jun 2012 11:38:36 -0800</pubDate>
		<dc:creator>mmrtnt</dc:creator>
	</item>	<item>
		<title>By: Talez</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387187</link>	
		<description>&lt;blockquote&gt;A collision attack!? Who could&apos;ve seen that one coming?&lt;/blockquote&gt;

From the link:

&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;
&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;
&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;
&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;
&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;
&lt;b&gt;&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;&lt;/b&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387187</guid>
		<pubDate>Fri, 08 Jun 2012 11:41:49 -0800</pubDate>
		<dc:creator>Talez</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387190</link>	
		<description>I don&apos;t think Microsoft worked hand-in-hand on this. Windows update is now completely untrustworthy for millions of machines.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387190</guid>
		<pubDate>Fri, 08 Jun 2012 11:42:44 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: pwnguin</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387195</link>	
		<description>&lt;a href=&quot;http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387172&quot;&gt;mmrtnt&lt;/a&gt;: &quot;&lt;i&gt;Unintended Consequence: Anyone using Linux is possibly a terrorist.&lt;/i&gt;&quot;

More like &quot;Unintended Consequence: Linux is found to be just as buggy and insecure as Windows&quot;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387195</guid>
		<pubDate>Fri, 08 Jun 2012 11:44:58 -0800</pubDate>
		<dc:creator>pwnguin</dc:creator>
	</item>	<item>
		<title>By: BrashTech</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387234</link>	
		<description>I, for one, welcome the made-for-TV movie about a team of top-secret virus-writing hacker-spies and their thrilling and sexy adventures.  Within 3 years.  Mark my words.  &apos;Cause this stuff is gold.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387234</guid>
		<pubDate>Fri, 08 Jun 2012 12:00:15 -0800</pubDate>
		<dc:creator>BrashTech</dc:creator>
	</item>	<item>
		<title>By: charred husk</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387240</link>	
		<description>&lt;blockquote&gt;&lt;a href=&quot;http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387154&quot;&gt;Ad hominem&lt;/a&gt;:&lt;br&gt;&quot;It is kind of awe inspiring to think whoever created it used an entirely new collision attack for malware instead of say publishing it and becoming famous.&quot;&lt;/blockquote&gt;

Why publish any more when you can &lt;a href=&quot;http://www.schneier.com/blog/archives/2012/06/the_vulnerabili.html&quot;&gt;make a bunch of money?&lt;/a&gt;
BTW, that article really worries me.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387240</guid>
		<pubDate>Fri, 08 Jun 2012 12:02:34 -0800</pubDate>
		<dc:creator>charred husk</dc:creator>
	</item>	<item>
		<title>By: JHarris</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387244</link>	
		<description>&lt;i&gt;It is kind of awe inspiring to think whoever created it used an entirely new collision attack for malware instead of say publishing it and becoming famous.&lt;/i&gt;

Try infuriating.  This is basically math kept secret for reasons of national security.

&lt;i&gt;More like &quot;Unintended Consequence: Linux is found to be just as buggy and insecure as Windows&quot;.&lt;/i&gt;

Yeah they all the same amirite</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387244</guid>
		<pubDate>Fri, 08 Jun 2012 12:03:08 -0800</pubDate>
		<dc:creator>JHarris</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387271</link>	
		<description>Really it isn&apos;t an issue if Linux or OS X or Openbsd is more secure if your attacker is a federal agency with a near unlimited budget and also full of good will hunting type super-geniuses.
They probably have 0-day exploits ready to go for every OS ever written the same way the DOD just had two hubbles laying around taking up space.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387271</guid>
		<pubDate>Fri, 08 Jun 2012 12:21:54 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: Stonestock Relentless</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387272</link>	
		<description>If the authors of Flame had received help from microsoft, it would never have installed properly.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387272</guid>
		<pubDate>Fri, 08 Jun 2012 12:21:59 -0800</pubDate>
		<dc:creator>Stonestock Relentless</dc:creator>
	</item>	<item>
		<title>By: sparkletone</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387276</link>	
		<description>Flame is apparently in the process of &lt;a href=&quot;http://arstechnica.com/security/2012/06/flame-espionage-malware-issues-self-destruct-command/&quot;&gt;self-destructing&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387276</guid>
		<pubDate>Fri, 08 Jun 2012 12:25:25 -0800</pubDate>
		<dc:creator>sparkletone</dc:creator>
	</item>	<item>
		<title>By: Flunkie</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387283</link>	
		<description>&lt;blockquote&gt;&lt;i&gt;If the authors of Flame had received help from microsoft, it would never have installed properly.&lt;/i&gt;&lt;/blockquote&gt;It looks like you&apos;re trying to subvert a nation state!

Would you like help?

o Get help with subverting the nation state
o Just subvert the nation state without help

&#9633; Don&apos;t show me this tip again</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387283</guid>
		<pubDate>Fri, 08 Jun 2012 12:28:52 -0800</pubDate>
		<dc:creator>Flunkie</dc:creator>
	</item>	<item>
		<title>By: gilrain</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387299</link>	
		<description>&lt;small&gt;&lt;em&gt;&lt;a href=&quot;http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387272&quot;&gt;Stonestock Relentless&lt;/a&gt;:&lt;/em&gt; If the authors of Flame had received help from microsoft, it would never have installed properly.&lt;/small&gt;

Oh, &lt;em&gt;snap!&lt;/em&gt; I&apos;m surprised you restrained yourself from using a dollar sign for the S. Oh, well played indeed.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387299</guid>
		<pubDate>Fri, 08 Jun 2012 12:35:33 -0800</pubDate>
		<dc:creator>gilrain</dc:creator>
	</item>	<item>
		<title>By: CBrachyrhynchos</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387300</link>	
		<description>Bad news: &lt;a href=&quot;http://arstechnica.com/science/2012/06/faster-than-light-neutrino-findings-really-thoroughly-dead/&quot;&gt;We probably don&apos;t live in a Star Trek future.&lt;/a&gt;
Worse news: We definitely live in a William Gibson future.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387300</guid>
		<pubDate>Fri, 08 Jun 2012 12:36:47 -0800</pubDate>
		<dc:creator>CBrachyrhynchos</dc:creator>
	</item>	<item>
		<title>By: -harlequin-</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387304</link>	
		<description>&lt;i&gt;a federal agency with a near unlimited budget and also full of good will hunting type super-geniuses.&lt;/i&gt;

I&apos;d suggest that the federal agency enjoys one of those two things.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387304</guid>
		<pubDate>Fri, 08 Jun 2012 12:38:41 -0800</pubDate>
		<dc:creator>-harlequin-</dc:creator>
	</item>	<item>
		<title>By: cjorgensen</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387326</link>	
		<description>&lt;em&gt;It is kind of awe inspiring to think whoever created it used an entirely new collision attack for malware instead of say publishing it and becoming famous.&lt;/em&gt;

Unlike all the other household names that published previously.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387326</guid>
		<pubDate>Fri, 08 Jun 2012 12:50:39 -0800</pubDate>
		<dc:creator>cjorgensen</dc:creator>
	</item>	<item>
		<title>By: k5.user</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387334</link>	
		<description>cjorgensen, where&apos;s your Free Kevin! t-shirt ?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387334</guid>
		<pubDate>Fri, 08 Jun 2012 12:54:33 -0800</pubDate>
		<dc:creator>k5.user</dc:creator>
	</item>	<item>
		<title>By: quonsar II: smock fishpants and the temple of foon</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387343</link>	
		<description>&lt;i&gt;Oh, snap! I&apos;m surprised you restrained yourself from using a dollar sign for the S. Oh, well played indeed.
posted by gilrain at 3:35 PM on June 8&lt;/i&gt;

ignorance is bli$$.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387343</guid>
		<pubDate>Fri, 08 Jun 2012 13:01:51 -0800</pubDate>
		<dc:creator>quonsar II: smock fishpants and the temple of foon</dc:creator>
	</item>	<item>
		<title>By: nTeleKy</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387351</link>	
		<description>&lt;i&gt;Do not use the MD5 algorithm&lt;/i&gt;

Just wanted to add that wikipedia mentions SHA-2 as a currently acceptable alternative.

I was interested in finding out more about the command and control servers and found &lt;a href=&quot;http://www.securelist.com/en/blog/208193540/The_Roof_Is_on_Fire_Tackling_Flames_C_C_Servers&quot;&gt;this excellent analysis&lt;/a&gt;.  It&apos;s from an analyst at Kaspersky and details the process by which they identified the servers, talks about the malware and compares it to duqu.

&lt;i&gt;Summary and conclusions:
*The Flame command-and-control infrastructure, which had been operating for years, went offline immediately after our disclosure of the malware&apos;s existence last week.
*We identified about 80 total domains which appear to belong to the Flame C&amp;amp;C infrastructure.
*The Flame C&amp;amp;C domains were registered with an impressive list of fake identities and with a variety of registrars, going back as far as 2008.
*The attackers seem to have a high interest in PDF documents, Office and AutoCad drawings.
*The data uploaded to the C&amp;amp;C is encrypted using relatively simple algorithms. Stolen documents are compressed using open source Zlib and modified PPDM compression.
*Flame is using SSH connections (in addition to SSL) to exfiltrate data. The SSH connection is established by a fully integrated Putty-based library.
*Windows 7 64 bit, which we previously recommended as a good solution against infections with other malware, seems to be effective against Flame
&lt;/i&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387351</guid>
		<pubDate>Fri, 08 Jun 2012 13:07:37 -0800</pubDate>
		<dc:creator>nTeleKy</dc:creator>
	</item>	<item>
		<title>By: Slothrup</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387387</link>	
		<description>There are a lot of operating systems and applications that auto-update themselves these days. Each individual update mechanism is basically an attack vector, and every public access point is an opportunity for man-in-the-middle attacks.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387387</guid>
		<pubDate>Fri, 08 Jun 2012 13:30:00 -0800</pubDate>
		<dc:creator>Slothrup</dc:creator>
	</item>	<item>
		<title>By: maiamaia</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387407</link>	
		<description>I doubt Microsoft would have wanted to do this, or that Siemens would have wanted to co-operate on Stuxnet, but whilst these multinationals have more money than lots of economies, the USA isn&apos;t one of those...plus they might want to sell stuff there...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387407</guid>
		<pubDate>Fri, 08 Jun 2012 13:47:29 -0800</pubDate>
		<dc:creator>maiamaia</dc:creator>
	</item>	<item>
		<title>By: Postroad</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387435</link>	
		<description>A problem with the new chyber warfare, is that &lt;a href=&quot;http://www.spacedaily.com/reports/Cyber_experts_warn_of_intelligent_weapons_999.html&quot;&gt;&lt;b&gt;can unleash weapons that become uncontrolled&lt;/b&gt;&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387435</guid>
		<pubDate>Fri, 08 Jun 2012 14:05:07 -0800</pubDate>
		<dc:creator>Postroad</dc:creator>
	</item>	<item>
		<title>By: -harlequin-</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387439</link>	
		<description>It was probably done with Microsoft&apos;s help, but not collaboration. Eg, when the agency asks for documentation, or to talk to an engineer, they usually get it, but they don&apos;t reveal what they&apos;re doing with that information. Oh hey, we&apos;re using it to trash your product! Sucks to be you!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387439</guid>
		<pubDate>Fri, 08 Jun 2012 14:09:16 -0800</pubDate>
		<dc:creator>-harlequin-</dc:creator>
	</item>	<item>
		<title>By: Mental Wimp</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387456</link>	
		<description>&lt;em&gt;Flame is apparently in the process of self-destructing.&lt;/em&gt;

Pretty much spook SOP, eh?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387456</guid>
		<pubDate>Fri, 08 Jun 2012 14:18:10 -0800</pubDate>
		<dc:creator>Mental Wimp</dc:creator>
	</item>	<item>
		<title>By: phearlez</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387460</link>	
		<description>&lt;em&gt;A problem with the new chyber warfare, is that can unleash weapons that become uncontrolled&lt;/em&gt;

Is that really so unlike all other warfare?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387460</guid>
		<pubDate>Fri, 08 Jun 2012 14:20:18 -0800</pubDate>
		<dc:creator>phearlez</dc:creator>
	</item>	<item>
		<title>By: stbalbach</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387463</link>	
		<description>&lt;i&gt;..&quot;the most powerful weapon today in cyber space is still the propaganda, the chance to use the Internet to spread your message&quot;&lt;/i&gt;

This (from Postroad&apos;s link). Not to Godwin, but Hitler&apos;s success was because he used new technology, radio, film, loud speakers and other forms of modern propaganda, to spread his message. Note the Arab Spring. The &quot;flash mob&quot; is more than a curiosity, the ability to instantly organize many people for a single purpose is like a DOS attack, except with live people as the packets. That&apos;s power. Look at what Anonymous has done, hacking to be sure, but it&apos;s organized around a single short term goal. There&apos;s all sorts of potential for this kind of thing to take off in the near future. The quiet violence of the computer can easily become the violence in the street.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387463</guid>
		<pubDate>Fri, 08 Jun 2012 14:21:27 -0800</pubDate>
		<dc:creator>stbalbach</dc:creator>
	</item>	<item>
		<title>By: MattMangels</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387470</link>	
		<description>Can someone page flapjax at midnite and tell him that we need him in this thread to produce a parody of David Bowie&apos;s &quot;Fame&quot; called &quot;Flame&quot;?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387470</guid>
		<pubDate>Fri, 08 Jun 2012 14:26:18 -0800</pubDate>
		<dc:creator>MattMangels</dc:creator>
	</item>	<item>
		<title>By: bafflegab</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387474</link>	
		<description>&lt;em&gt;If they had Microsoft&apos;s help I don&apos;t think they would need to use an unknown MD5 collision.&lt;/em&gt;

If an entity wanted to maintain plausible deniability of its collusion with Microsoft, I would think it would naturally tend to move away from exploiting flaws in Microsoft&apos;s core proprietary codebase -- that would draw attention to the possibility of that collusion -- and instead look for flaws in the more mundane components, like hashes, etc.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387474</guid>
		<pubDate>Fri, 08 Jun 2012 14:28:49 -0800</pubDate>
		<dc:creator>bafflegab</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387503</link>	
		<description>Well there was the infamous NSAKEY in previous versions of Windows. I think it first appeared in an NT 4 service pack. No doubt the NSA has the source code to Windows, I&apos;m not sure if it is true of the most recent versions but you used to be able to license it, that is what allowed things like sysinternals to exist. I might be the naive one but I don&apos;t think Microsoft would subvert their own update infrastructure for any reason. The cat is out of the bag now, every malware author out there is probably looking into it right now.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387503</guid>
		<pubDate>Fri, 08 Jun 2012 14:50:54 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387514</link>	
		<description>Unless this is some Obama style jedi 7 dimension chess and they are trying to destroy all existing versions of Windows to force people onto trusted computing platforms.

My god, it all makes sense. We are through the looking glass here people.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387514</guid>
		<pubDate>Fri, 08 Jun 2012 14:54:07 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: Slothrup</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387523</link>	
		<description>&lt;i&gt;it would naturally tend to move away from exploiting flaws in Microsoft&apos;s core proprietary codebase -- that would draw attention to the possibility of that collusion&lt;/i&gt;

As I understand it, there are a surprisingly large number of entities -- including foreign governments like Russia&apos;s -- which have access to Windows source code. It is, perhaps, their assurance that there is no US-government trap door in the OS.

But I also think that some people overvalue source code when it comes to finding security problems. I suspect that it&apos;s actually easier to work with the binary artifacts directly -- and in fact, security bugs can be &lt;a href=&quot;http://isc.sans.edu/diary.html?storyid=6820&quot;&gt;introduced during compilation&lt;/a&gt;; for instance, by overly aggressive optimization.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387523</guid>
		<pubDate>Fri, 08 Jun 2012 14:59:17 -0800</pubDate>
		<dc:creator>Slothrup</dc:creator>
	</item>	<item>
		<title>By: three blind mice</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387530</link>	
		<description>&lt;i&gt;Obama&apos;s virus wars: mutually assured cyber-destruction&lt;/i&gt;

Mutually assured? Doesn&apos;t that mean both sides have the same capability? 

There you have it: IRAN IS DEVELOPING CYBER WEAPONS OF MASS DESTRUCTION.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387530</guid>
		<pubDate>Fri, 08 Jun 2012 15:01:31 -0800</pubDate>
		<dc:creator>three blind mice</dc:creator>
	</item>	<item>
		<title>By: feloniousmonk</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387551</link>	
		<description>I&apos;m sure this will result in some kind of spike on attempts at subverting Windows Update, but I don&apos;t think that&apos;s unusual. Several years ago I interviewed with a group that provides not WU but a service it relies on to verify OS installs, and I got the distinct impression that they had a significant number of staff dedicated to full time firefighting as people constantly were trying to break the APIs.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387551</guid>
		<pubDate>Fri, 08 Jun 2012 15:25:41 -0800</pubDate>
		<dc:creator>feloniousmonk</dc:creator>
	</item>	<item>
		<title>By: Nelson</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387586</link>	
		<description>I think what&apos;s most interesting about Flame is that it&apos;s actually older than Stuxnet/Duqu. Also the analyses I&apos;ve read are coming to the conclusion it&apos;s a whole separate codebase, albeit with some shared design characteristics. There&apos;s more than one espionage malware stack being developed by the US government, that&apos;s fascinating. How many more are there?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387586</guid>
		<pubDate>Fri, 08 Jun 2012 16:01:47 -0800</pubDate>
		<dc:creator>Nelson</dc:creator>
	</item>	<item>
		<title>By: kjh</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387609</link>	
		<description>&lt;i&gt;As I understand it, there are a surprisingly large number of entities -- including foreign governments like Russia&apos;s -- which have access to Windows source code. It is, perhaps, their assurance that there is no US-government trap door in the OS.
 
But I also think that some people overvalue source code when it comes to finding security problems. I suspect that it&apos;s actually easier to work with the binary artifacts directly -- and in fact, security bugs can be introduced during compilation; for instance, by overly aggressive optimization.&lt;/i&gt;

Though it&apos;s implied in your comment, I&apos;ll state it outright: having the source means nothing if you don&apos;t have the ability to build it. That is, Russia can examine the Windows source code all day long, but if the binary build they&apos;re deploying is provided by Microsoft, there isn&apos;t any assurance that the binary exactly matches the source. (I&apos;ll add as a caveat that I don&apos;t believe for a second that Microsoft is directly involved in this or any other such skullduggery.)

You can even go a step further and say that even if they have Microsoft&apos;s build environment--and even if they have the &lt;i&gt;source code&lt;/i&gt; for Microsoft&apos;s build environment--they &lt;i&gt;still&lt;/i&gt; can&apos;t be sure that what ends up being built is semantically identical to the source code. &lt;a href=&quot;http://cm.bell-labs.com/who/ken/trust.html&quot;&gt;Ken Thompson: Reflections on Trusting Trust&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387609</guid>
		<pubDate>Fri, 08 Jun 2012 16:22:34 -0800</pubDate>
		<dc:creator>kjh</dc:creator>
	</item>	<item>
		<title>By: Samizdata</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387829</link>	
		<description>&lt;a href=&quot;http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387172&quot;&gt;mmrtnt&lt;/a&gt;: &quot;&lt;i&gt;&lt;i&gt;The best consequences are always the unintended ones!&lt;/i&gt;

Because the US government and Microsoft can work hand-in-hand to backdoor &quot;enemies&quot;, it won&apos;t be long before all the bad guys just use Linux instead.

Unintended Consequence: Anyone using Linux is possibly a terrorist.

Also, &lt;a href=&quot;http://botaday.com/node/999&quot;&gt;this&lt;/a&gt; seems appropriate.&lt;/i&gt;&quot;

Cool, I&apos;m a terrorist now?  Add that to my international arms dealer status (crypto export violation as protest) and I am that much closer to a real Bond villian!  Even have a &lt;a href=&quot;https://secure.flickr.com/photos/samizdatadotorg/5358605228/&quot;&gt;fuzzy cat&lt;/a&gt; AND a giant monitor!  Rest of the lair kinda sucks though.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387829</guid>
		<pubDate>Fri, 08 Jun 2012 21:33:03 -0800</pubDate>
		<dc:creator>Samizdata</dc:creator>
	</item>	<item>
		<title>By: Samizdata</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4387830</link>	
		<description>Villain, even.  Evil does not preclude typos, unfortunately.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4387830</guid>
		<pubDate>Fri, 08 Jun 2012 21:37:38 -0800</pubDate>
		<dc:creator>Samizdata</dc:creator>
	</item>	<item>
		<title>By: yoink</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4388025</link>	
		<description>&lt;i&gt;I, for one, welcome the made-for-TV movie about a team of top-secret virus-writing hacker-spies and their thrilling and sexy adventures. Within 3 years. Mark my words. &apos;Cause this stuff is gold.&lt;/i&gt;

&quot;Quick, you need to hack the mainframe!&quot;

&quot;I&apos;m almost in! See all those spinning balls? If I can just navigate my hacker-craft past them, you&apos;ll see them turn green--that will mean I have control of their mainframe!&quot;

&quot;Oh no! You&apos;ll have to hack faster! The spinning balls are beginning to turn yellow!&quot;

&quot;Quick--you&apos;d better help me hack by typing on the keyboard at the same time as me! Man, this is the toughest mainframe I&apos;ve ever tried to hack into! I think I might need to undo another button on my blouse so my boobs can cool down from all the hacking they&apos;re helping me do.&quot;

Or has Hollywood gotten better at writing movies about anything related to computers?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4388025</guid>
		<pubDate>Sat, 09 Jun 2012 08:26:54 -0800</pubDate>
		<dc:creator>yoink</dc:creator>
	</item>	<item>
		<title>By: newdaddy</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4388368</link>	
		<description>&lt;em&gt;A former senior Israeli government minister has told us that, just as Sanger confirmed Stuxnet was created in partnership with the IDF&apos;s Unit 8200 cyber warfare unit, Flame was created by similar figures in Israel. &lt;/em&gt;.  The Guardian article seems fairly confident and specific that Flame is both written and used by Israeli entit(ies) but most comments in this thread seem preoccupied with the notion that NSA is somehow responsible.   Why is that?  Is it reflective of some deeper knowledge or due to conflicting news reporting? Or just cloak-and-dagger fantasies?  Am I misunderstanding something?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4388368</guid>
		<pubDate>Sat, 09 Jun 2012 14:21:50 -0800</pubDate>
		<dc:creator>newdaddy</dc:creator>
	</item>	<item>
		<title>By: Thistledown</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4388897</link>	
		<description>It&apos;s an easy thought experiment. Big and Mysterious NSA doing something Big and Mysterious, as opposed to Tiny Israel, y&apos;know?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4388897</guid>
		<pubDate>Sun, 10 Jun 2012 05:33:08 -0800</pubDate>
		<dc:creator>Thistledown</dc:creator>
	</item>	<item>
		<title>By: Nelson</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4390134</link>	
		<description>&lt;a href=&quot;http://www.securelist.com/en/blog/208193568/Back_to_Stuxnet_the_missing_link&quot;&gt;Back to Stuxnet: the missing link&lt;/a&gt;. Kaspersky looks deep into older versions of Stuxnet and finds evidence of shared source code with Flame.&lt;blockquote&gt;The above conclusions point to the existence of two independent developer teams, which can be referred to as &quot;Team F&quot; (Flame) and &quot;Team D&quot; (Tilded). Each of these teams has been developing its own platform since 2007-2008 at the latest.

In 2009, part of the code from the Flame platform was used in Stuxnet. We believe that source code was used, rather than complete binary modules. Since 2010, the platforms have been developing independently from each other, although there has been interaction at least at the level of exploiting the same vulnerabilities.&lt;/blockquote&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4390134</guid>
		<pubDate>Mon, 11 Jun 2012 08:23:08 -0800</pubDate>
		<dc:creator>Nelson</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4390812</link>	
		<description>&lt;a href=&quot;http://www.emptywheel.net/2012/06/11/stuxnet-covert-op-exposing-code-in-covert-op-exposing-code-out/&quot;&gt;StuxNet: Covert Op-Exposing Code In, Covert Op-Exposing Code Out&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4390812</guid>
		<pubDate>Mon, 11 Jun 2012 12:45:57 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: ericb</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4392293</link>	
		<description>&lt;a href=&quot;http://redtape.msnbc.msn.com/_news/2012/06/12/12172042-is-flame-virus-fallout-a-chinese-russian-plot-to-control-the-internet?lite&quot;&gt;Is Flame virus fallout a Chinese, Russian plot to control the Internet?&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4392293</guid>
		<pubDate>Tue, 12 Jun 2012 09:31:12 -0800</pubDate>
		<dc:creator>ericb</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4394899</link>	
		<description>&lt;a href=&quot;https://speakerdeck.com/u/asotirov/p/analyzing-the-md5-collision-in-flame&quot;&gt;Analyzing the MD5 collision&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4394899</guid>
		<pubDate>Wed, 13 Jun 2012 11:28:08 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4400005</link>	
		<description>&lt;a href=&quot;http://www.pcpro.co.uk/news/security/375169/could-us-cyberspies-have-moles-inside-microsoft&quot;&gt;Could US cyberspies have moles inside Microsoft?&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4400005</guid>
		<pubDate>Fri, 15 Jun 2012 14:52:43 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/116762/An-unauthorized-certificate-could-be-used-to-spoof-content-perform-phishing-attacks-or-perform-maninthemiddle-attacks-This-issue-affects-all-supported-releases-of-Microsoft-Windows#4407973</link>	
		<description>&lt;a href=&quot;http://www.washingtonpost.com/world/national-security/us-israel-developed-computer-virus-to-slow-iranian-nuclear-efforts-officials-say/2012/06/19/gJQA6xBPoV_story.html&quot;&gt;U.S., Israel developed Flame computer virus to slow Iranian nuclear efforts, officials say&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.116762-4407973</guid>
		<pubDate>Wed, 20 Jun 2012 10:20:22 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>
	</channel>
</rss>
