6 ms·
Could someone explain how they would know that the IP "used exclusively" by NK wasn't a proxied IP but in fact the "real" source IP? Personally, I think just m
by ddod 12y ago
Could someone explain how they would know that the IP "used exclusively" by NK wasn't a proxied IP but in fact the "real" source IP?
Personally, I think just mentioning that part of the evidence came from the Behavioral Analysis Unit proves that NK's ties to this are definitely shaky.
- Alupis 12y agoNot to mention it's also easy to spoof your IP address if you are traversing out of a DC or node that does not do egress filtering (meaning you don't even have to proxy through the proper IP/country... you just make it up). Shaky evidence? You bet ya. (and it seems this is the only evidence offered as an explanation so far) Also, if N. Korea really was behind this "attack" of a private company with no US Gov't ties, why would they not claim responsibility and tout their "Cyber Attack" skills? They do for just about everything else (even failed missile launch attempts). Fear of retribution? No way, this is/was a private company... the US Gov't could not respond with any kinetic weaponry attack and look good on a geopolitical scale. N. Korea also offered to send personnel to help the FBI in the attack investigation, which is extremely uncharacteristic of N. Korea to say the least... normally they'd just praise the attack flatout.
- happyscrappy 12y agoIt is quite interesting how so many are hoping against hope that it was not North Korea. I don't really see why they are emotionally attached.
- Alupis 12y agoThere's no emotions involved -- just like there's no evidence involved. It's flat out wrong to blame some small and non-credible-threat country for something they likely had nothing to do with just to advance a political agenda. North Korea is not a great country... but that doesn't mean a "global leader" like the USA can just pin something on them with zero evidence.
- davidw 12y agoNon-credible-threat? North Korea? I'm not a fan of the US' foreign policy in some ways, and certainly place no blind faith in the declarations of the government, but, that doesn't exactly make North Korea the 'good guys'... http://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?NewsID=14255&LangID=E http://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?Ne... http://en.wikipedia.org/wiki/North_Korea_and_weapons_of_mass_destruction http://en.wikipedia.org/wiki/North_Korea_and_weapons_of_mass...
- Alupis 12y ago> Non-credible-threat? North Korea? Their nuclear program claims it has a range of 4,000KM, but to reach the USA it would take about 10,000KM. Not to mention their last missile launch test could not even escape their border. That's what I mean when I say non-credible threat; they are incapable of inflicting meaningful harm to the USA. They are really all bark and no bite... > oesn't exactly make North Korea the 'good guys'. Of course not. Nobody said they are -- they just simply aren't the "bad guys" we are looking for in this specific case.
- davidw 12y ago> they just simply aren't the "bad guys" we are looking for in this specific case. You seem to be awfully certain. Frankly, I have no idea and am quite skeptical of people who profess such certainty in the face of so few facts. Seems to be the kind of thinking where you have a conclusion and look around for facts to support it.
- Alupis 12y ago> You seem to be awfully certain Perhaps I overspoke a tad. I'm awfully skeptical is better put. We're largely a scientific community here at HN. Something is False until proven True. You may have a hypothesis, but it's just that, an educated guess as-to the result. To prove something True you must present overwhelming evidence. We have none of that here... What we do have is a hypothesis being perpetuated as fact in the face of almost zero concrete evidence. The FBI first says "there is zero evidence to suggest North Korea has anything to do with the hack". Then some "high level anonymous White House official" "leaks" to the NY Times that they believe it's North Korea, and it takes the FBI 3 full days to change their public announcement, yet present zero concrete evidence. This was a rudimentary hack against a private company, there's nothing that would be classified or kept top secret here. Sony should do a full disclosure. Until then, we can not be certain of anything.
- mijoharas 12y agoI wouldn't say it is being emotionally attached to be sceptical of something that is presented without solid evidence.
- billions 12y agoFully agree with your technical AND political analysis. I commented along the same lines when the attacks were first announced and got downvoted. When a way of thinking is too far ahead of the crowd, the HN algorithm fails.
- neilwillgettoit 12y agoIt could be as simple as they saw a bunch of UDP traffic with a spoofed src that was a dprk ip block.
- rgbrenner 12y agoN. Korea also offered to send personnel to help the FBI in the attack investigation, which is extremely uncharacteristic of N. Korea to say the least They offered to help investigate the Cheonan after they sunk it. So it's really not uncharacteristic. And why do you have attack in quotes? Do you believe Sony wasn't actually attacked?
- Alupis 12y ago> And why do you have attack in quotes? Do you believe Sony wasn't actually attacked? No, I think it's plenty clear that they were. It's just that "attack" has a certain stigma to it, and what happened to Sony was not some grand attack, but rather a run-of-the-mill hack against a company with extremely poor security.
- irq 12y agoIt is _not_ easy, or even possible, to "make up" an IP address that works for receiving data across the public Internet. The responses to packets you send from such an address will not come back to you. This doesn't thwart all attacks (DNS query amplification, general flooding, etc), but their hack involved transmitting AND receiving data (ssh, http, etc). What is _easy_, however, is determining which country is using a given IP address. Particularly when the searching party is a superpower and the country they're investigating is known for having very few links to the Internet. And what connections they do have are severely restricted. I imagine it would be very difficult to find a reliable, exploitable proxy server inside North Korea that is accessible across the public Internet.
- emn13 12y agoYou may not need the responses to come to you, particularly if (as is suggested) this is a tiny minority of traffic. Sending something to some /dev/null address in NK? Why not?
- drzaiusapelord 12y agoFunny, when the IP addresses weren't NKorea, as earlier highly voted HN articles have told us, it was proof that it wasn't NKorea. Now that they do, its somehow further proof that it wasn't N Korea. I understand knee-jerk anti-US comments are karma gold here, but I don't think you guys realize how ridiculous you sound to the rest of us. I think its pretty difficult to arm-chair analyze this stuff and come out with a definitive answer, especially considering a lot of this stuff will never be declassified, but the Alex Jones-like conspiracy thinking here really brings the discourse down to a reddit-like level. Purely from an Occam's razor perspective, the country that attacked this film and warned of consequences if released-- consequences that actually happened, is probably at fault here. This analysis of how it must have been anyone but NKorea, especially considering NKorea's reputation, is highly questionable to the unbiased observer.
- davidw 12y ago> the Alex Jones-like conspiracy thinking here really brings the discourse down to a reddit-like level. That's where political discussions inevitably and invariably end up. Probably best to just flag these articles.
- indlebe 12y agoI would disagree on your point that "knee-jerk anti-US comments are karma gold here" on 2 notes, 1 that being anti-US-administration is not being anti-US, and 2 that most unsubstantiated comments that are critical of government actions almost always get down voted to oblivion. Everyone knew that North Korea had it out for Sony, what's to stop a network security enthusiast from stirring the pot by performing the attack and planting "evidence" that it was coming from North Korea. I don't think it's far fetched to think that many young security enthusiasts would get excited to think about causing such a stir.
- deleted 12y ago[deleted]
- siegecraft 12y agoWho is saying this is proof that it wasn't NKorea? Straw man. People on HN are just more likely to believe Schneier or other respectable security people, and not government agencies who by their very nature are going to have their own agenda and not be 100% honest. As far as consequences that actually happened -- Do you mean to say that theaters that showed the film were bombed? Or are you referring to embarassing email leaks which would have no doubt been released anyway?
- philip1209 12y agoIf somebody were to want to frame the North Koreans, what would stop a motivated attacker (perhaps a nationstate) from just abusing BGP to spoof source IPs? How hard would that be to detect, particularly if you controlled direct peers?
- SwellJoe 12y agoAs I understand it, China would be able to do so easily and convincingly, since most (all?) of NK's traffic passes through China. That may even be a good theory. China might not want to directly attack US industry in this way, but might "assist" North Korea in doing so.
- dpeck 12y agoall, or at least all that anyone knows about. NK has a single path/peer.
- mox1 12y agoIF someone "route flapped" the entire North Korean IP space for any amount of time, one of the 10+ organizations who monitor BGP would have noticed and commented on that already....... If Russia et al had the ability to covertly do that...why attack Sony....why not big financial institutions or other such high profile targets....
- emn13 12y agoNo need to route flap if the route's already going through you.
- roywiggins 12y agoIf the NSA has taps sitting on all the routers that are a hop away from NK, they can probably nail it down just from timing, right? If the packets were being proxied through an NK IP, I would think it would be easy to tell the difference (if you're the NSA, anyway).
- Alupis 12y agoWould be a hugely missed opportunity for the NSA to tout their currently controversial programs if true.
- deleted 12y ago[deleted]
- rilita 12y agoTiming correlation. If you are monitoring traffic in/out of NK, you can correlate traffic by similar sequence of sized packets going into one IP and then coming out of another. This is the "secret sauce" that the FBI says they cannot tell anyone imo. Doing this is nothing new and I am sure they've been doing it for ages though. The problem is that if you assume the FBI is doing this ( which any skilled hacker would assume ) then you can easily get around it by sending a sequence of instructions ahead of time, and then having them playback at what seems like a reasonable rate at a later time. ( making it seems as if you are on site and didn't set it up ahead of time )