5 ms·
My work brings me into regular contact with DPRK IT professionals, for example by [teaching open source sotware](https://izbicki.me/blog/teaching-open-source-in
by jackpirate 4y ago
My work brings me into regular contact with DPRK IT professionals, for example by [teaching open source sotware](https://izbicki.me/blog/teaching-open-source-in-north-korea.html https://izbicki.me/blog/teaching-open-source-in-north-korea....) or [teaching proper web design](https://izbicki.me/blog/fixing-north-korea-kcna-webpage.html https://izbicki.me/blog/fixing-north-korea-kcna-webpage.html). I make a lot of effort to respect sanctions, but documents like this are incredibly unhelpful. I've read through the document, and it seems completely devoid of actionable, DPRK-specific information that can help IT professionals avoid sanctions violations. For example, the document encourages websites to monitor for the following activity as "indications of DPRK IT workers who may be using their platforms":
• Multiple logins into one account from various IP addresses in a relatively short period of time,
especially if the IP addresses are associated with different countries;
• Developers are logging into multiple accounts on the same platform from one IP address;
• Developers are logged into their accounts continuously for one or more days at a time;
• Router port or other technical configurations associated with use of remote desktop sharing
software, such as port 3389 in the router used to access the account, particularly if usage of
remote desktop sharing software is not standard company practice;
• Developer accounts use a fraudulent client account to increase developer account ratings, but
both the client and developer accounts use the same PayPal account to transfer/withdraw
money (paying themselves with their own money);
• Frequent use of document templates for things such as bidding documents and project
communication methods, especially the same templates being used across different developer
accounts;
• Multiple developer accounts receiving high ratings from one client account in a short period,
with similar or identical documentation used to establish the developer accounts and/or the
client account;
• Extensive bidding on projects, and a low number of accepted project bids compared to the
number of projects bids on by a developer; and
• Frequent transfers of money through payment platforms, especially to PRC-based bank
accounts, and sometimes routed through one or more companies to disguise the ultimate
destination of the funds.
This list is so generic that I'm not sure what the point of it is. I think it would make sense to ban some of these practices from a general security perspective. But these practices would give way too many false positives if you were trying to use them to identify DPRK developers.
I'm honestly really confused about who the target audience is for publications like this. It can't be actual IT professionals due to the lack of actionable information. Is it journalists? Do we publish these things just to remind them that we don't like the DPRK?
- 8organicbits 4y ago> I make a lot of effort to respect sanctions Are there certain things you aren't able to teach when you travel, or is that fairly unrestricted? I had no idea people were doing work like this.
- A4ET8a8uTh0 4y agoIt does not take much to run afoul of sanctions on a country that has total embargo status. Even normally legal counsel advice may be prohibited to US persons to provide ( sorry for odd syntax ). In other words, OP does not have to deal with anything beyond normal IT work and still could be restricted on what information he can provide. Not to search too far, although that is a more exotic example, recently crypto guy got smacked for providing crypto speech ( classified as technical advice ) to DPRK(1). (1)https://www.justice.gov/opa/pr/us-citizen-who-conspired-assist-north-korea-evading-sanctions-sentenced-over-five-years-and https://www.justice.gov/opa/pr/us-citizen-who-conspired-assi...
- drc500free 4y agoDo you have an example where the defendant didn't specifically and purposefully provide guidance on how to use tech to circumvent sanctions? It's not like he was generically talking about crypto.
- newguynewphone 4y agoI mean, we would have to see all sides of information, but this is not normal IT work. On another note, would this case be directly related to the 400 million hack north korea did?
- mcculley 4y agoThe simplest first thing that U.S. companies should do is implement E-Verify and require that all subcontractors do the same. This publication does not even mention E-Verify.
- cschmid 4y ago