8 ms·
Did North Korea Really Attack Sony?
- SG- 12y agoThis piece pretty much echoes what I've felt since I first read about all the speculation and FBI report. I'm just glad someone with credibility was able to come out and say it, I just hope (but doubt) that mainstream media will follow up on it and ask the right questions going forward.
- happyscrappy 12y agoYou are glad he said what? He rules out a Sony insider and says NK must be involved in some way unless someone did it for the Lulz.
- yourad_io 12y agoHe didn't rule out a Sony insider. > It's possible, but that employee or ex-employee would have also had to possess the requisite hacking skills, which seems unlikely. Considering the number of laid off techies, I think it is somewhat "more than unlikely". I don't know where you got the second part.
- wpietri 12y agoI think he's also missing the case where a disgruntled insider gives a beachhead and/or money to outsiders.
- nkantar 12y agoI sincerely doubt the mainstream media will give Schneier any air time, as his view point isn't sensationalist enough to sell well. But I also think his skepticism is spot on. This "explanation" is too conveniently tidy for me to find it all that believable.
- dba7dba 12y agoBut that someone has zero credibility when it comes to distinguishing nuances in the Korean language. N Korea has the motive, means, and track record for this kind of thing. And please let's all agree such hacking is not some impossible rocket science. Any group of young teens/hackers with enough time could've pulled it off. Especially such a relatively easy target as sony. Oh by the way, N Korea did launch a mid range ballistic missile (albeit a crude one).
- at-fates-hands 12y agoSo he posits 5 possibilities, 3 of which directly involve NK? He basically says he doesn't know what to think, but maintains the evidence is weak, like every other tech journalist. I do agree its a good possibility the government has a lot more classified evidence it's not sharing with us, and we're trying to put together a puzzle with only half the pieces.
- jdawg77 12y agoWhat's funny to me is even with, "Freedom of information act," in the USA some Americans act like everything is public record. It's not. Sometimes, for international relations, things are classified, never released until much later. Having been party to a minor agreement, at least knowing about it, before the general media, gives you a ton of insight into how the USA operates. To me at least, I came to the, "Business," operating model. In other words, the economic engine takes priority and the agreements I know of that were signed pushed that particular agenda. Dollars, literally, make the world go round. The US dollar is the world, "Reserve," currency. There's a very good reason for that, and a very good reason the Secret Service is in charge of the US money supply. Then again, perhaps I'm as much as insider as the author of the blog post. Eg, out of the loop.
- JonnieCache 12y agoLiterally? Wow.
- dasil003 12y agoYou're supposed to infer the figurative usage from the dramatic commas.
- thirsteh 12y agoYou mean the literal usage? http://www.merriam-webster.com/dictionary/literally http://www.merriam-webster.com/dictionary/literally (#2) * long sigh * Happy festivus!
- umanwizard 12y agoThere's no reason to be a pedant here.
- jcd748 12y agoDollars do not literally make the world go round. The world literally goes around because it was formed from a disc of swirling matter, and the lack of inertia and forces that would stop it.
- bjourne 12y agoIs there any information anywhere of how the intrusion was made? E.g was the admin server for Sony's intranet accessible via remote desktop from the whole internet with the user and password admin/admin? It's a completely different situation than if it consisted of exploiting an unknown vulnerability in SELinux to get remote root access.
- fitshipit 12y agoThis piece is in fact even more speculative than the FBI's announcement.
- brown9-2 12y agoTellingly, the FBI's press release says that the bureau's conclusion is only based "in part" on these clues. This leaves open the possibility that the government has classified evidence that North Korea is behind the attack. I am surprised that the article doesn't end here. Other press reports have highlighted that there is classified evidence that has not been disclosed, and it seems odd to me that Schneier would play this aspect down in a story involving cyberattacks, North Korea, the FBI and the US intelligence community.
- barrkel 12y agoSecret evidence can be used to justify whatever whims the gatekeepers of that evidence wish to pursue politically. If anything should be learned from the Iraq debacle, it's that.
- aragot 12y agoThat focus on Iraq is strange. I'm French and when Bush provided so-called "evidence" at the UN, people here were laughing and media were skeptic. From comments on HN, it seems Bush was taken seriously in other circles of the world, which may explain why some US citizen boycotted French products after we said we would create a worldwide axis against war.
- duaneb 12y ago> From comments on HN, it seems Bush was taken seriously in other circles of the world, Not sure if you heard the news, but Bush quickly invaded Iraq. I think it's safe to assume he was taken seriously. > which may explain why some US citizen boycotted French products after we said we would create a worldwide axis against war. Some US citizens just like to complain about foreigners to be more patriotic (as if that would help). I would doubt most people could explain anything about french foreign policy.
- arjie 12y agoExactly! It honestly beats me. The tone around the news in India was that the so-called "evidence" was total bullshit. I, too, was amazed to learn that there were people who believed it.
- Jongseong 12y agoI'm dismayed that this piece is repeating Marc Rogers's gross misportrayal of the linguistic situation of the Koreas, saying that "Korean language in the code also suggests a Korean origin, though not necessarily a North Korean one, since North Koreans use a unique dialect." First of all, North Korean doesn't have "a unique dialect" but a number of regional dialects, just like South Korea, and like the situation in many languages. But again as in many major languages, a supra-regional, standard Korean language came into being, based on the central dialect region around Seoul which was the capital for many centuries. Before that the capital was Kaesong, which is in the same central dialect region as Seoul though it is now in North Korea. This happened before the division of the peninsula. Even today, the standard Korean taught and spoken in North Korea is based on this common standard with the South. The differences between regional dialects within either North or South Korea are far greater than the difference between the standard Korean spoken in the North and the South. The difference is mainly in words (especially any technology-related vocabulary introduced after the end of WWII) and spelling, and it's a lot like the differences between British and American English. You're never going to say that something written in English can't have been written by Americans because they have a unique dialect. Also, as far as I know the codes didn't contain any Korean. Instead, what they found was that it seems to have used Korean text encoding, like EUC-KR. People have pointed out that this is a South Korean encoding, but North Koreans also use it since you hardly find any software that supports the official North Korean encoding. Again, if someone uses a British English locale, that isn't proof that it can't be an American. When it comes to text encoding and locale, you usually use whatever is available that lets you type in your own language.
- feraloink 12y agoSigh, sounds very familiar, like what people say about Mandarin and Cantonese, those who don't know. This is a different hack, but I think they more reliably differentiated between North Korea and South Korea, due to the IP addresses? "Korea seeks U.S. help in reactor hacking probe" http://m.koreaherald.com/view.php?ud=20141222001202&ntn=0 http://m.koreaherald.com/view.php?ud=20141222001202&ntn=0
- Jongseong 12y ago
- rab_oof 12y agoAnd guessing the tinfoil conspiracy about Sony hacking itself wouldn't stay secret long. :) My thought is we'll probably never know for certain unless perps reveal themselves, so saying NK definitely did it would be jumping to conclusions. The real story is: Best. Marketing. Ever. And an international incident, to boot! (Well played, Sony. Even Obama was part of the story.). Seriously, the canceling the release was the story-making move. And the subsequent nonrelease release monetizes the situation. Couldn't have planned it any better. ;)
- IndianAstronaut 12y agoIf it was marketing, Sony would not have revealed the private emails of their executives. Obama would also not have stepped in, there is plenty of vetting that goes on in the federal government.
- rab_oof 12y agoLet me explain the joke to you, since you seemed to have missed the cute emoticons. Satire - making fun of any alternative explanation that obviously isn't true. Maybe I should be more literal next time. Merry Xmasmukah and new year!
- rqebmm 12y agoIf it was all a marketing ploy they wouldn't have released private employee information that would open them up to lawsuits, or shut down their operations for several days. There's absolutely no way that Sony makes a profit on this adventure, and that would be the only reason to make it up. It's absolutely ridiculous to think otherwise.
- feraloink 12y agoWired had a good article yesterday too, that made clear that there is still a lot of uncertainty. http://www.wired.com/2014/12/sony-north-korea-hack-experts-disagree http://www.wired.com/2014/12/sony-north-korea-hack-experts-d...
- kailuowang 12y agoOut of the 5 possibilities Schneier listed, I found #1 (the one picked by FBI) mostly likely. > This is the work of independent North Korean nationals. Mr. Schneier doesn't clearly understand people who lived in a totalitarian country. If this national lives in North Korean, there is no way he will dare such an attack without being instructed by the government. This level of freedom doesn't exist in his mind. And it doesn't make sense for a North Korean still holding the same ideology to live outside North Korea, he would either completely abandoned that or go back to North Korea. > This is the work of hackers who had no idea that there was a North Korean connection to Sony until they read about it in the media. This doesn't explain the Korean language used in the code. It might be a South Korean, but from my knowledge, it's very hard to imagine a South Korean risking going to the jail either fighting for North Korean or even find it fun. (Hint - South Korean people don't like the people from north who are pointing Thousands of cannons and missiles to them). As for why this is not the same encoding as North Korean dialect, I know people from mainland China use encoding of Traditional Chinese from Taiwan. It is very easy for me the imagine that North Korean government offices use such settings so that they can access resources from South Korea (much more abundant and still without language barrier.) > It could have been an insider This hacker has been hurting regular Sony employees. From my understanding, only people with mental problems will direct their hatred towards a company to random regular employees (his own ex-coworkers). People with mental problems don't usually possess the hacking skills demonstrated in this case. > The initial attack was not a North Korean government operation, but was co-opted by the government. It is hard to imagine a hacker targeting Sony with the plan to profit from selling the information to North Korean government and then intentionally leave some trace towards North Korea (the Korean language in code). This attack must have originated from North Korea, and that's the conclusion FBI is suggesting.
- vezzy-fnord 12y agoPeople with mental problems don't usually possess the hacking skills demonstrated in this case. Depends on the mental problem. The category is far too broad to make a sweeping statement like that. Anything from being slightly narcissistic to being a paranoid schizophrenic can be considered a "mental problem" under one definition or another. Most of these do not involve any diminished technical skills. In addition, I could cynically retort that anyone who orchestrated such a reckless and damaging attack as this isn't exactly the most mentally stable.
- jobu 12y agoIf North Korea is involved I think it was after the initial attack (theory #4 in the article). As he says in the article: "the explicit North Korean connection -- threats about the movie The Interview -- were only made by the hackers after the media picked up on the possible links between the film release and the cyberattack". North Korea may not have even been aware of the movie until the hack. It seems like Sony is playing up the North Korea connection because it could only help them. They would lose more credibility (and potentially lawsuits [1]) if it's a 14yo hacker doing it for the lulz. State sponsored hacking is a Big Deal, and many would give leniency to Sony if that's a true story. [1] http://abcnews.go.com/Entertainment/wireStory/sony-faces-4th-employee-lawsuit-hack-27726230 http://abcnews.go.com/Entertainment/wireStory/sony-faces-4th...
- rqebmm 12y ago> North Korea may not have even been aware of the movie until the hack. North Korea was well aware of The Interview ahead of the hack. See this article from June: http://www.theguardian.com/film/2014/jul/10/north-korea-un-the-interview-seth-rogen-james-franco http://www.theguardian.com/film/2014/jul/10/north-korea-un-t...
- rudolf0 12y ago>the explicit North Korean connection -- threats about the movie The Interview -- were only made by the hackers after the media picked up on the possible links between the film release and the cyberattack I personally think this is a misinterpretation of what happened. Media began heavily speculating it was tied to The Interview about 1-2 days after the hack was initially reported, but the hackers waited until Dec. 15 before explicitly mentioning it. If they wanted to take advantage of the sensationalism, why continue releasing messages and threats that clearly acknowledge Sony and the media between Nov. 24 and Dec. 15 while not mentioning The Interview until the most likely motive essentially became obvious? Second, I think the group name "Guardians of Peace" is a fairly obvious allusion to "guarding international peace by preventing Sony from releasing The Interview", and is in line with just about everything they've been saying. And of course they were using that group name on day 1. I'm not saying North Korea necessarily did it, but I think the actors either intended to stop the movie from the beginning, or intentionally framed North Korea by using a pretext of trying to stop the movie. I don't think they're a group of hacktivists who only appropriated The Interview as a motive after media speculation.
- oijfpoiewf 12y agoSo, legitimate question: how is it possible to get North Korean comments out of a compiled binary? Somehow I doubt that any supposed North Korean hackers would have followed the tenets of free software and distributed the original source to Sony along with the malware.
- cgh 12y agoman strings "strings is mainly useful for determining the contents of non-text files."
- oijfpoiewf 12y agoDoesn't it stand to reason that the compiled version of the malware wouldn't contain the Korean, though?
- q2 12y agoJust like this article, several other entities may be skeptical on assertions that North Korea is involved given the past involving Iraq's imaginary WMD...etc. Also, cyber attacks may be common in future, for whatever may be the reasons involved. In future, if some Hollywood studio makes a movie on Russia's Putin or on China and if hackers claiming from the injured country do similar cyber-attack on that studio and If USA retaliates and if Russia/china counter-retaliates and if this spills into physical world, then we can have nightmarish situations/tensions and may be full blown war. Worse, another country may do that sort of attack from some other country to hide its trail. Hope proper sense and calm minds prevail to prevent such nightmare. But such possibility exists in theory. As solution, world needs an international, independent, competent panel/forum/group to investigate openly/transparently all cyber-attacks and find out culprits rather than doing mere guess work. Also, evidence of the crime need to be put in public domain to avoid conspiracy theories. This can be on the lines of international court of justice/United nations ...etc. Since parties involved are entities like Sony which are not connected to national defence directly, we need not fear national secrets leaking out ...etc i.e. it can be done without impacting the sovereignty of the nations involved. Without such arrangement, stability and peace of the world will always be in question for any cyber attack on any major country such as USA/Europe/China/Russia ...etc. TL,DR: Cyber-attacks on economic entities such as Sony or Google in the past involving several countries need to be investigated by international body rather than a single country and evidence of the crime need to be in public domain to avoid conspiracy theories.
- d0ugie 12y agoTheir bandwidth is estimated to be in the neighborhood of 6Gbit/s, and they allegedly grabbed 100TB of data. If my math is right that would take fifteen days for them to download. Unless of course they got a bargain on a VPS somewhere else..
- dba7dba 12y agoThey can use USB HDs. They can hack from China. The possibilities are endless. It's well known NK had been complaining about the movie for months. And I doubt NK started hacking only 2 weeks before scheduled opening day.
- discardorama 12y agoBut NK sure is a convenient bogeyman for the real agenda: to bring in CISPA: http://www.zdnet.com/article/white-house-wants-congress-to-revisit-controversial-cispa-style-cybersecurity-laws-after-sony-attack/ http://www.zdnet.com/article/white-house-wants-congress-to-r...
- tootie 12y agoCISPA was already vetoed due to inadequate privacy protections but the fundamental rationale of requiring private companies to share threat information with the government is pretty reasonable. CISPA just needs to be fixed and reintroduced which has been Obama's stance for a while.
- encoderer 12y agoEverybody is a critic. Everybody has an opinion. Everybody is just writing rank speculation. The gov't filed charges, so to speak, so lets see them play out their case.
- encoderer 12y agoEverybody is a critic. Everybody has an opinion. Everybody is just writing rank speculation. The gov't filed charges, so to speak, so lets see them play out their case.