Clearly posters aren't getting the sarcasm, so I'll spell it out: the NSA is clearly suspect number one.
What's more interesting to me, though, isn't that they had this technique, it's that they let it out for ... what? It seems like this is a garden variety public worm. One would think that if the NSA had the ability to forge windows code signatures like this, they would have used it more selectively. Some spook is in deep trouble about this.
The NSA is not suspect number one. The Russians have had superb cryptographers for decades, heck GCHQ invented public key cryptography years before Diffie Helmann and denied it's very existence within for decades.
Attribution is a bitch. It's not a slam dunk to suggest that a particular agency is at fault without supporting evidence.
> the GCHQ beat DH by three years and RSA by four, not decades.
Correct. But they kept the fact that they did secret for decades. That's what I meant, apologies if it was ambiguous (I can't actually edit the comment now to fix it).
The Russians have far more of an economic risk to set something like this off in the middle east. Their huge investments in oil infrastructure could go up in flames if this was traced back to them. And this is just the stuff that's somewhat above the table.
It's easy to pin it on a nation state or intelligence agency, but it's worth considering the possibility that it was rogue elements in one (or both worlds) that exploited this (and various people) for purely financial gain.
Hell, the people I know who don't work for the government scare me with the kind of advanced research they do. And if it was government funding they might farm out to the private sector if there was more advanced research there with this kind of attack vector in mind.
What's more interesting to me, though, isn't that they had this technique, it's that they let it out for ... what? It seems like this is a garden variety public worm. One would think that if the NSA had the ability to forge windows code signatures like this, they would have used it more selectively. Some spook is in deep trouble about this.