7 ms·
South Korea military cyber command was hacked
- faragon 10y agoIn South Korea only old people get hacked...
- lifthrasiir 10y agoSo 2011 data breach of SK Communications [1] has only affected 35M old people, right? [1] http://www.koreaherald.com/view.php?ud=20110728000881 http://www.koreaherald.com/view.php?ud=20110728000881
- slyrus 10y agoCyber is tough.
- redsummer 10y agoIoT: what could go wrong: https://en.wikipedia.org/wiki/Samsung_SGR-A1 https://en.wikipedia.org/wiki/Samsung_SGR-A1
- sverige 10y agoI wonder what kinds of fail-safes these sentries have if they're hacked? It says that there's a human operator. Do they have a kill switch to shut it down if it turns the wrong way so it can't be used against them?
- ComodoHacker 10y ago>speculation that North Korea might be behind the latest cyber attack Does North have hackers skilled enough to perform such (or any) attacks? How did they acquire their skills given the internet is forbidden there?
- norswap 10y agoI seem to recall that the Sony hack was attributed to North Korean hackers and while many people laughed it off, serious investigations pointed that it was really the case. (Just on top of my head, I'll let you dig for sources.)
- nyolfen 10y agoserious analysis pointed to iran (malware shared traits with that used in saudi aramco hack a year or two prior), probably because nk and iran have some kind of offensive sharing arrangement on cyber, but the nuclear deal was in the works and the last thing the obama admin wanted to deal with was a perceived provocation.
- SRSposter 10y agoThe same way they got ahold of nuclear weapons knowledge.
- ComodoHacker 10y agoPhysics was never forbidden. And they got much from Soviets.
- SRSposter 10y agoYou dont need hacker culture for electronic warfare
- noobermin 10y agoIf after decades, they are only now developing nukes barely as powerful as the earliest nuclear weapons (although still dangerous), one would wonder if their decades delayed IT know-how really can pull off such an attack.
- Eridrus 10y agoSounds like someone running around with the Cisco IOS exploit from the ShadowBrokers dump. Best Korea has obvious motive, but it could also be random hackers running around hacking everything on shodan.
- jimpix1 10y agoI suppose it is random hackers
- lifeisstillgood 10y agoI wonder if it is time for a reboot. If the castles we have built so far turn out to be made of gauze instead of stone, maybe we need to rethink it all, in the same way we need to rethink energy policy Every Intel motherboard since 2008 has had a "spy" on board, almost every home router is working for someone's botnet and will never be patched, medical devices and factory automation systems ship with default passwords because no one assumed they would ever connect to the Internet and don't get me started on browsers and JavaScript. It was a multi-decade long fight to get the seat belt adopted, so I suspect that we aren't going to fix this the old way - surely at some point we stop?
- tmzt 10y agoRiscV, TCP+crypto offload, hardware switchports with luajit or nf rules. Reactive UI with hardware rendering and compositing. Hardware keystore with physical switch to generate and enroll keys, user/owner controlled secrets, one-time programmable as an option, hardwired SAK and OS personality switching key. Real-time security isolation kernel, hardware-enforced containerization with MMU-protected GPU passthrough.
- lifeisstillgood 10y agoIt will take a while to google-walk through all that, but thank you. Do you feel this is a comprehensive recipie to move to a (enterprise wide) computing platform where the attacker has the paying field tipped against them (it seems the other way round today)
- Jach 10y agoIt doesn't sound comprehensive enough to me, though better than what's around. My own comprehensive recipe is simply "put nickpsecurity in charge". :)
- tmzt 10y agoI was thinking the same thing. What I was describing is about using the disadvantages of a platform like RiscV yo our advantage. Rather than running network stacks, compositing and other things on the main processor which will likely trail intel processors in performance for a time, we design the hardware to do what hardware does best.
- electic 10y agoNo one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.
- thematt 10y agoI'm not sure how splitting up the NSA fixes anything. Wouldn't the new offensive organization still be compelled to seek out zero-day exploits as well for their mission? What happens when they find one that the defensive organization hasn't found yet?
- electic 10y agoBetter than the current setup. The defensive side sole responsibility is to find critical flaws and report them. This would also include investigating breaches in US infra and making sure things get patched. Right now, you don't even have the defensive side.
- deleted 10y ago[deleted]
- tptacek 10y agoSplitting IAD off from SIGINT wouldn't reduce the number of zero-days the government collected, but it would: * Ensure that the advice IAD was generating was untainted by SIGINT influence * Enable IAD to independently collect vulnerability intelligence and disseminate it (most importantly, to vendors) without having to endure a bogus equities process to ensure they weren't blowing a SIGINT operation. Of course, this only works if IAD is stripped completely out of the NSA, and perhaps out of the DoD entirely. IAD probably belongs under DHS.
- deleted 10y ago[deleted]
- 10y ago
- scurvy 10y ago"vaccine routing server" = next-gen firewall running UTM?
- jlgaddis 10y agoFrom the context, my first thought was something like a centralized server providing anti-virus software and/or updates hosts on the internal portion of the network. Considering the timeline (within the last month or two) and the recently discovered issues in antivirus products from multiple vendors, I think that this scenario (or something similar) is, at the least, plausible. A compromised UTM firewall would not be unheard of either.
- yongjik 10y ago1. Government website gets hacked 2. Government blames North Korea 3. ??? 4. Profit! Err, I mean, government support goes up. Well, maybe North Korea did it, maybe it didn't, but the current state of South Korean politics created a perverse incentive structure. The more severely the government is hacked (or otherwise attacked by North Korea), the more it is politically rewarded. So, expect nothing to change any time soon.
- aburan28 10y agoThis is most likely retaliation for North Korea's latest nuclear test
- secult 10y agoSo they have internet after all!