4 ms·
Given it's an official Google blog post related to a nation-state threat actor, somebody asking for valid attribution could be a way attackers try to: 1) Derai
by w0z_ 3y ago
Given it's an official Google blog post related to a nation-state threat actor, somebody asking for valid attribution could be a way attackers try to:
1) Derail the conversation
2) Find out ways to further cloak their footprint
IMO if you've worked in the field, you know it's a dumb question meant to invoke something.
"Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!"
Sadly, I am a nobody who happened to see DPRK not tunnel to a VPN.
- rightbyte 3y ago> somebody asking for valid attribution could be a way attackers try to: 1) Derail the conversation 2) Find out ways to further cloak their footprint Really? What does it take to sprinkle North Korea over my code? Is having the North Korean equivalent of JIS in strings enough? I mean, how could there possibly there be any footprint of anything. Does gcc leak info into the binary that my Debian system does not have in the first place? You need to get these guys when they are bragging to their friends. You can't look on the trails they leave behind ... A lot of cyber security smells like bullet forensics.
- paganel 3y agoIf it matters I didn't mean to direct my comment at you personally (obviously, as I don't know you), but instead it was meant to target the generic security person who says that he/she has gotten in the "vicinity" of such state-sponsored attacks. Back to the subject at hand, and taking a more general view, trusting a big Pentagon-contractor [1] (and not only) such as Alphabet on the subject of other countries' cyber-attacks against the US (and its Western allies) is just futile. [1] https://www.reuters.com/technology/pentagon-awards-9-bln-cloud-contracts-each-google-amazon-oracle-microsoft-2022-12-07/ https://www.reuters.com/technology/pentagon-awards-9-bln-clo...