5 ms·
"SoUrCe?" This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles. This is coming from someone (me) who personally sa
by w0z_ 3y ago
"SoUrCe?"
This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles.
This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.
- whimsicalism 3y agoThis seems like a disproportionately mocking tone for the original comment made.
- pphysch 3y agoAttributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that. Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal. WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chinese, Iranian, etc. It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution.
- deleted 3y ago[deleted]
- paganel 3y ago> It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution. I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to (I guess that's how the OP got to see those NK-related IP blocks) Western government agencies that handle this sort of stuff.
- w0z_ 3y agoGiven it's an official Google blog post related to a nation-state threat actor, somebody asking for valid attribution could be a way attackers try to: 1) Derail the conversation 2) Find out ways to further cloak their footprint IMO if you've worked in the field, you know it's a dumb question meant to invoke something. "Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!" Sadly, I am a nobody who happened to see DPRK not tunnel to a VPN.
- rightbyte 3y ago> somebody asking for valid attribution could be a way attackers try to: 1) Derail the conversation 2) Find out ways to further cloak their footprint Really? What does it take to sprinkle North Korea over my code? Is having the North Korean equivalent of JIS in strings enough? I mean, how could there possibly there be any footprint of anything. Does gcc leak info into the binary that my Debian system does not have in the first place? You need to get these guys when they are bragging to their friends. You can't look on the trails they leave behind ... A lot of cyber security smells like bullet forensics.
- paganel 3y agoIf it matters I didn't mean to direct my comment at you personally (obviously, as I don't know you), but instead it was meant to target the generic security person who says that he/she has gotten in the "vicinity" of such state-sponsored attacks. Back to the subject at hand, and taking a more general view, trusting a big Pentagon-contractor [1] (and not only) such as Alphabet on the subject of other countries' cyber-attacks against the US (and its Western allies) is just futile. [1] https://www.reuters.com/technology/pentagon-awards-9-bln-cloud-contracts-each-google-amazon-oracle-microsoft-2022-12-07/ https://www.reuters.com/technology/pentagon-awards-9-bln-clo...
- jryle70 3y agoAre you really that naive? Google don't even reveal how their search engine scores the web pages they index, and you want them to tell you the evidences of NK being behind this or how they figured that out? You are free not to trust them if you choose. It's particularly ironic because in this case social media was used to gain access to the researcher's computer: In one case, they carried on a months-long conversation [on X], attempting to collaborate with a security researcher on topics of mutual interest HN is another perfect place for that to happen. How do we know that pphysch (or me jryle70) isn't a NK's agent trying to get more information about the technique employed in this case?