5 ms·
Sony just had a major layoff,pointing to a possible insider.[1] Many Koreans work for Sony and they may have had a personal gripe with NK.“Guardians of Peace” c
by lbenes 12y ago
Sony just had a major layoff,pointing to a possible insider.[1] Many Koreans work for Sony and they may have had a personal gripe with NK.“Guardians of Peace” comes from a quote used by former President Richard Nixon describing South Korea.[2]
In this debate[3], the security expert on the side of the FBI keeps rehashing the old it's the same IP address debate. But I don't buy it. Those are open proxies.
Combine that with the fact that North Korea has a terrible education system and an entimated 1 in 10,000 people have access to the Internet in North Korea. This is not the kind of environment that fosters elite super hackers. I don't think NK did it.
[1] http://www.polygon.com/2014/9/18/6377971/sony-financial-results-mobile-2014 http://www.polygon.com/2014/9/18/6377971/sony-financial-resu...
[2] http://www.thedailybeast.com/articles/2014/12/20/sony-hackers-guardians-of-peace-troll-fbi-fbi-is-the-best-in-the-world.html http://www.thedailybeast.com/articles/2014/12/20/sony-hacker...
[3] https://www.youtube.com/watch?v=vNCpHM4BBJQ https://www.youtube.com/watch?v=vNCpHM4BBJQ
- spcoll 12y agoIf DPRK has the capacity to pull this sort of hacking feat on demand, it begs the question: why aren't they doing it around the clock, to hurt their enemies that they seem to hate so much? It's just not very realistic to think that DPRK has this super secret hacker army (but not so secret that we haven't heard of it in the media) that can hack any large corporation (but can't cover its own tracks). If they did, we would see it action all year long. This hack sounds like the work of a large, professional, well-funded organization that only uses its capabilities in a very targeted, parsimonious manner. But what would be the motive for the US govt to hack Sony and then accuse DPRK? Distract the public from the CIA torture report? Something else?
- TillE 12y ago> the capacity to pull this sort of hacking feat on demand > that can hack any large corporation That's not how hacking works. Even if you have a collection of zero-day exploits, it's entirely dependent on the software and configuration of a target's computer systems. Or your own luck with social engineering.
- meowface 12y agoThis is not a hacking feat at all. Perhaps if this was the DoD and not Sony. Extracting and exfiltrating many TB of data would take a bit of experience, but even some experienced script kiddies could likely get a foothold on Sony's network without much difficulty.
- ceejayoz 12y ago> Combine that with the fact that North Korea has a terrible education system and an entimated 1 in 10,000 people have access to the Internet in North Korea. This is not the kind of environment that fosters elite super hackers. I don't think NK did it. You could say the same for nuclear programs and rockets. People showing technical aptitude are likely singled out for special training and given perks unheard of by the general population. Plus, from what we've heard, the Sony hack didn't require remarkable levels of skill. They were doing things like storing major account passwords in text/Excel files on a shared drive.
- XorNot 12y agoThe only problem being that there's a much larger population of more skilled people who would do it "for the lulz" everywhere else in the world.
- ceejayoz 12y agoI'm dubious that North Korea did this particular attack. That said, acting as if North Korea can't pull off this sort of attack is dangerously complacent.
- deleted 12y ago[deleted]
- XorNot 12y agoThe thing is no one should care. It isn't unique NK capability. Hacking is the domain of non-state actors, and knows no real political boundaries - at least on this level. We're not talking about stuxnet, where it's likely wetwork teams planted it in the targets. We're talking about a run of the mill corporation with bad security getting owned - it was going to happen because the bar to clear for doing it just wasn't very high.
- GabrielF00 12y ago> Combine that with the fact that North Korea has a terrible education system and an entimated 1 in 10,000 people have access to the Internet in North Korea. This is not the kind of environment that fosters elite super hackers. I don't think NK did it. Business Insider spoke to a defector about the DPRK's cyberwarface program[1]. Even if they can't develop hackers organically, they can build a small cadre by selecting some people who might be talented, hiring outside experts to train them and giving their trainee hackers certain privileges. An analogy might be that in the US, we build our olympic teams organically - athletes choose what they want to do based on personal interest and it's a good environment in which to grow as an athlete. North Korea has a terrible environment to develop athletes organically, but they can hire outside experts to train a small cadre of their own people. They win a few gold medals every summer Olympics. http://www.businessinsider.com/north-korean-defector-jang-se-yul-trained-with-hackers-2014-12 http://www.businessinsider.com/north-korean-defector-jang-se...
- XorNot 12y agoThe only problem being that no outside expert with the right skillset would ever travel to North Korea, and them doing so would be highly suspect. Even if NK wanted to build such a team, the reality of nation-states is that you can't make up for the complete failure of your society with just money alone. The degree to which the Soviet Union turned out to be behind the US during the Cold War speaks to that - and NK is a lot worse off then the Soviet Union.
- dba7dba 12y agoYou can build the skillset without having anybody teach you in person. NK is a lot worse than the Soviet but NK still managed to develop nukes and cobble together a midrange ballistic missile, something no teenage hackers in a basement can manage. You shouldn't underestimate NK. Just the fact they have survived as long as it has shows it means something.
- kragen 12y agoThe Copenhagen Suborbitals are a group of "teenage hackers in a basement" who have cobbled together a midrange ballistic missile, although without any intention of using it as a weapon. The main thing preventing other teenage hackers from doing this is violence — either the police come and arrest you, or your neighbors steal your things, or your neighbors get pissed off about the amount of nitrogen oxides you're wafting over their house and coerce you to stop.
- HillRat 12y agoNorth Korea has a terrible education system and an entimated 1 in 10,000 people have access to the Internet in North Korea. This is not the kind of environment that fosters elite super hackers. It's also not the kind of environment that fosters high-energy physicists, but we're talking about a regime that has indigenously developed nuclear weapons. The NK government already has an "official" Linux distro, "Red Star OS," indicating at least some level of technical ... well, let's not say prowess, let's say comprehension. (Likewise, the proliferation of cheap high-tech goods smuggled over the Chinese border has forced the NK government to announce its own smartphone, though few people believe the factory to be anything other than a Potemkin fab, with the actual phones shipped over from China.) You have to assume that a nation state, even one as impoverished as NK, can mobilize the kind of cash necessary to train a few hundred (at most) hackers, using Chinese or Russian instructors. It's much cheaper than hiring Makeyev OKB to design another ballistic missile system, and, unlike nuclear and missile tests, the international community doesn't have a unified playbook for dealing with target hacks, particularly against non-governmental systems. No one's going to war for Sony, but if NK is behind (or believed to be behind) the attack, you can bet that the USG has found Sony's experience to be rather bracing. Having said that, I agree that the evidence favoring NK as the culprit is circumstantial and hazy at best. Even the best evidence they're provided is dependent on a chain of assumptions that I think haven't been properly validated. This isn't a "WMD in Iraq" situation, because the USG would have loved for the Sony hack to be a bunch of anons doing it for the lulz (though now that the government has committed to the NK story, it's hard to backtrack). After all, we couldn't do much over NK's nuclear program, which is a crisis many, many orders of magnitude more serious than the Sony hack; calling out NK for this just underscores the fact that we don't have many levers to move against Pyongyang.
- hasslein 12y agoIt's also not the kind of environment that fosters high-energy physicists, but we're talking about a regime that has indigenously developed nuclear weapons. A minor quibble, but North Korea did not indigenously develop nuclear weapons - they acquired most of their knowledge and capabilities from Pakistan via the Khan network. They most certainly spent a great deal of effort internally to convert said knowledge into functional nuclear devices, but by no means did they develop everything internally.
- sroerick 12y agoI challenge your source for [2]. I looked for the name Guardians of Peace prior to that meme starting, and after the George Clooney article came out, I looked again. While Nixon did use the phrase Guardians of Peace a number of times, I was unable to find it in conjunction with Korea. As far as I can tell, the only source saying Guardians of Peace is a SK reference is George Clooney. Frankly this backs up what you are saying. Given this fact: http://iowa.barstoolsports.com/random-thoughts/sony-paid-kevin-hart-two-million-dollars-for-two-tweets-because-the-world-isnt-fair/ http://iowa.barstoolsports.com/random-thoughts/sony-paid-kev... I'm not willing to trust George Clooney at his word.