5 ms·
What evidence do they have that suggests these threats are coming from North Korea?
by buzzert 5y ago
What evidence do they have that suggests these threats are coming from North Korea?
- trashcan01 5y agoA statement from Google.
- martyvis 5y agoI'm actually surprised Google would say this is from the DPRK government without also saying it had has been verified by US federal government authorities. Usually they leave it for others to deal with statements at that level.
- huntsman 5y agoI think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years. (Disclaimer: I am head of TAG)
- dna_polymerase 5y ago
- thematrixturtle 5y agoHere's the report which associated Clear Sky with NK, and it's not from Google: https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...
- dna_polymerase 5y agoYeah, still waiting for something to substantiate the headline. This report isn't it. A lot of hand-waving about other people's hand-waving.
- thematrixturtle 5y agoAPT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?
- harry8 5y agoThink of all the big, serious and sensible news organisations that independently reported WMD in Iraq while not being connected to the US government. Are you alleging they're all wrong and this is some vast conspiracy to frame an innocent Iraq and protect.. who, exactly? Evidence is evidence. After WMD (which totally took me in, btw, you too?) Claims that evidence is "just over there" and "here are multiple different people reporting they've spoken to someone who saw it." Count for zero. Maybe they always should have but there's not doubt this stuff happens anymore. We watched it. (Hopefully) in horror as it unfolded without us objecting.
- nl 5y agoI thought the WMD "evidence" was BS, and actually there was only one piece that was presented publicly (the UN presentation by Colin Powell), and that was based on CIA secret intelligence. And the UN Weapon Inspectors were saying the opposite. OTOH, the evidence linking APT38 to North Korea is pretty compelling. For example, there is a bunch of evidence collected independently identifying individuals associated with APT38, and these people worked for the North Korean company Chosun Expo. See https://www.justice.gov/opa/press-release/file/1092091/download https://www.justice.gov/opa/press-release/file/1092091/downl... for the evidence in depth.
- thematrixturtle 5y agoThere's a huge difference between news organizations reporting on US govt claims, and investigators on the ground actually digging into the evidence on their own. Your assertion is basically the same as claiming that Iraq did have WMDs, but UNMOVIC etc were covering up and hiding the evidence. For what it's worth, quite a few people were skeptical about the WMD "evidence" at the time, and even more cynics like myself figured that true or false, it was mostly an excuse for George W to Do Something(tm) after 9/11 and at the same time finish off the war his dad started.
- actuator 5y agoRather than attacking him, you are free to discuss on how it would be hard to attribute or reach to a source. Just because you might not know what techniques the researchers here used to reach to that conclusion, doesn't mean they would have used dubious methods. It is better to ask than attack a person.
- dna_polymerase 5y agoThe United States reserves the right to react to cyber attacks with force [0]. Instead of asking people to be nice on the internet you should hold those accountable that are in a position to manufacture a narrative. The linked report in the sibling comment here has no valid proof of North Korean involvement but the headline is chosen in a way to paint a picture of an impoverished nation as an aggressor. If you just accept that Google can make up facts to pave the way for physical warfare you are complicit in the eventual deaths of thousands of innocent people. To be precise. After the CIA made up reports of WMDs in Irak people should ask for receipts earlier. [0]: https://www.reuters.com/article/us-usa-defense-cybersecurity-idUSTRE7AF02Y20111116 https://www.reuters.com/article/us-usa-defense-cybersecurity...
- saagarjha 5y ago> Instead of asking people to be nice on the internet you should hold those accountable that are in a position to manufacture a narrative. Nope, Hacker News is the place where you be nice to each other on the internet rather than assuming they’re trying to manufacture consent. This is quite literally spelled out in the site guidelines.
- azinman2 5y agoHow do you know what country is actually behind any of this? I’d imagine that would be very difficult given nation states can host content anywhere in the world and will want to make it look like it’s coming from elsewhere.
- saagarjha 5y agoI don’t work in this field, but my impression has been that groups tend to share techniques and code patterns that can help tie them back to where they came from.
- azinman2 5y agoBut how do you know the origin?
- jasonwatkinspdx 5y agoBy connecting multiple details such as ip addresses, connection/flow logs, known CnC servers, etc. You seem to be expecting some magic simple answer but the reality is the same as other investigative work: doing the work in the details as a professional. Just because this work is difficult and inherently has some ambiguity doesn't mean you can just dismiss every attribution from your armchair.
- rtpg 5y agoStaring hard at a all the details and figuring it out? The thing with trying to hide yourself is you have to do everything right to guarantee some false flag operation will work but if you make enough mistakes in this process there will be reasonably high-confidence links between some action and some person. An example that I _have_ seen in some write up: some snippet of malware code showing up in a stack overflow question (with the shape and user variables being the same). At one point it's like... probably that person. Of course maybe there are other indicators to the contrary but that's data for you. Gotta use your noggin a bit.
- xtian 5y agoHere’s a question I expect you’ll never answer: is it within the capabilities of any groups within the West (state-sponsored or otherwise) to fabricate the information you’re using to make those assessments? And if so, how have you decisively eliminated this possibility? I ask because it’s broadly accepted that there are extremely powerful and wealthy entities in the West who benefit from an aggressive US foreign policy and heightened geopolitical tensions.
- jamesmishra 5y agoWhy do you have to prefix your question with, "Here’s a question I expect you’ll never answer"?
- xtian 5y agoI don’t have to, it just makes me look good when he never answers.
- jasonwatkinspdx 5y agoNo, it does not.
- xtian 5y agoAgree to disagree
- throwawaylinux 5y agoProbably, but even more simply they have the capabilities to just direct intelligence agencies, politicians, and news corporations, and big internet and social media companies to put the blame wherever they like. There is no need for a perfect technological solution. Hack something shoddy together, go to war/regime change/etc, and worst case if it does come to light that the "intel" was wrong, a well-placed "whoopsie-daisy" is enough to wash hands of all responsibility or scrutiny.
- 5y ago
- fit2rule 5y ago
- vmception 5y agoAnd even when knowing how a country or particular state-backing is identified, there is nothing preventing other hackers from adding the same markers to their own software
- agilob 5y agoNK hackers are kwnon for adding false flags
- deleted 5y ago[deleted]
- bberrry 5y ago> These groups' activity has been publicly tracked as Operation Dream Job and Operation AppleJeus. Following those links yield these two documents, which both have "Attribution" sections. Presumably some of these tell-tale signs were identified in the ongoing exploitation. https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf https://www.clearskysec.com/wp-content/uploads/2020/08/Dream... https://securelist.com/operation-applejeus/87553/#attribution https://securelist.com/operation-applejeus/87553/#attributio...
- ncann 5y agoI'm very curious how we can attribute a threat to a particular nation state, given pretty much anything in code/IP/modus operandi/etc. can be faked by one party to look like another. I went through both links and all I found was a lot of hand-wavings like > One of the top identifiers of Lazarus is their dual attack mission – money theft and espionage. This modus operandi is unique to North Korea, as other state actors usually focus on espionage only. North Korean money theft operations are carried out in service of the government, as a way of funding the nuclear program Like, seriously? "You not only do espionage but also steal money, therefore you're NK"?
- nl 5y agoI've posted this elsewhere, but https://www.justice.gov/opa/press-release/file/1092091/download https://www.justice.gov/opa/press-release/file/1092091/downl... This is about WannaCry, but it shows how multi-source attribution is done.
- ncann 5y agoThanks, this seems much more detailed. I'll give this a good read.
- youarethebest 5y agoIts hilarious that neckbeards think that NK hackers are top class. Yeah maybe they can hack here and there but anything complex is developed by TAO/the Equation Group/ Israelis Lol