Live data from Hacker News

The NSA has linked the WannaCry computer worm to North Korea

washingtonpost.com

111–120 of 253 posts

Re: The NSA has linked the WannaCry computer worm to North Korea

#111
post #86

Earlier quoted context omitted.

There was lots of skepticism but in the end because of lack of good humint a lot of weight was placed on his behavior (his continued pretense/bluffing for the purpose of not disclosing weakness to Iran), the international community with the US at the lead reached a faulty conclusion. With regard to DPRK S Korea has great humint and we have multiple defectors corroborating each other (whereas Iraq there was basically…

"the international community with the US at the lead reached a faulty conclusion" Mistakes can happen and be forgiven but deception is seldom forgotten. It didn't go down quite so innocently as you portray. It appears painfully obvious that there were/are many parties with economic and other interests who were behind what turned into a giant expensive catastrophe and killed hundreds of thousands. No one has even been…

There is lots of blame to go around with re Iraq. Our intelligence, Saddam himself (calling a bluff he could not possibly win, the cat-mouse game, in addition to just being a tyrant), opposition, Shiites, many western countries (but curiously Russia opposed) etc.

It may not seem like it from the way I write, but I was utterly devastated when the congress approved the plans. But I take one incident at a time. I try not to color unrelated things.

Re: The NSA has linked the WannaCry computer worm to North Korea

#112

Earlier quoted context omitted.

To be fair, the NSA was never given the mission to take on that defensive role you state. Their mission includes the defense of classified systems. Defense of any other systems is not their responsibility. The offensive capability you state is part of their mission and is what NSA was created for.

> The NSA was never given the mission to take on that defensive role you state. It's both. James Clapper ( https://en.wikipedia.org/wiki/James_Clapper ), former director of national intelligence, says the NSA has a review process to decide whether or not to disclose vulnerabilities to software vendors. Nothing in their mission prevents them from doing it. They're choosing not to do it. Look at the slogan on the NSA's…

Strategically there is sometimes advantage in not letting the enemy know what you know (how you define enemy is another question, but it's reasonable to observe that we have antagonistic relationships with some countries). The alternative is a siege mentality. If you systematically throw up defences ASAP every time you discover a vulnerability, and an enemy discovers a vulnerability but does observe any defensive preparations, the enemy now knows that they have an operational advantage over you and is incentivized to deploy it for maximum effect.

Obviously this is only a thumbnail sketch rather than an exhaustive exploration of strategy. But it's a subject I read and think about a good deal. Pretty much every military thinker through history has emphasized the value of surprise and the ability to set the tempo of battle.

Re: The NSA has linked the WannaCry computer worm to North Korea

#113
post #95

Earlier quoted context omitted.

> The NSA is not credible. - Somewhat technical internet user

well the NSA chief lied to US congress. http://www.slate.com/articles/news_and_politics/war_stories/...

Well that's it then, one lie ends everything. I had a program crash on me once, never used it again.

I'm being flippant but while I wouldn't advise you to trust the NSA it's equally foolish to assume an antagonistic posture towards it forever more in everything. Military forces sometimes kill innocent people which is terrible, and even worse than lying, but you don't see any country deciding not to have one, for reasons that I hope are obvious.

We live in a very imperfect world and it's not obvious how to rid ourselves of war, militarism, greed and so on because of the perverse economic incentives that prevail at this time in history. So I feel we should be very skeptical of our institutions, but not to the point of perversity or reflexive rejection thereof, which would make us as easy to manipulate as reflexive approval.

Re: The NSA has linked the WannaCry computer worm to North Korea

#114
post #95

Earlier quoted context omitted.

> The NSA is not credible. - Somewhat technical internet user

well the NSA chief lied to US congress. http://www.slate.com/articles/news_and_politics/war_stories/...

Which says to the American people...

'''You aren't in control at any level of your government. You can elect representation, but fuck them, and fuck you. We run the show around here and we do as we please.'''

The long term cost of this implication, to the organization, to the government, to society in general is more than if he just presented power points of the secret plans on YouTube.

Re: The NSA has linked the WannaCry computer worm to North Korea

#116

It's ~impossible to prove who's behind any attack these days given code-reuse, false flags & TOR. Anyone who claims to be able to do it reliably, is bullshitting you and likely has an agenda.

Not really. Very few attacks dedicate enough effort to evasion or anti-forensics to be completely untraceable. There are plenty of things that get reused such as public keys that can be reliably tied to a group. There are also many private indicators that are not released to the general public Discovering who funds that group or where they operate from can be tougher, but APT groups are trackable.

Re-using a public key seems like an incredibly basic mistake.

How is the chain of custody for digital evidence handled by intelligence agencies and 3rd party researchers? Are there higher standards with regard to digital evidence? It seems to me that with digital evidence, ultimately you at least have to trust the investigatory agency at hand. But we're past that, because a huge number of Americans like myself will never trust any information from the US government.

Re: The NSA has linked the WannaCry computer worm to North Korea

#117
post #64

Earlier quoted context omitted.

Supposing North Korea has Bitcoins... how could they sell them in a way that grants them usable currency?

It's trivial to exchange Bitcoins anonymously to cash almost anywhere in the world.

Not in volumes that count

Re: The NSA has linked the WannaCry computer worm to North Korea

#118

Earlier quoted context omitted.

So we are unsure.

Out of curiosity, what evidence would convince you?

Collin Powell got quite a lot of tonnage I mean mileage out of a cartoon drawing. Just draw him a picture.

Re: The NSA has linked the WannaCry computer worm to North Korea

#119
post #66

Though the hackers raised $140,000 in bitcoin, a form of digital currency, so far they have not cashed it in, the analysts said. That is likely because an operational error has made the transactions easy to track, including by law enforcement. As a result, no online currency exchange will touch it, said Jake Williams, founder of Rendition Infosec, a cybersecurity firm. “This is like knowingly taking tainted bills fro…

Mixing $140,000 in Bitcoin would be trivial. For example, bitmixer.io holds ~1000 BTC reserve for mixing, which is currently worth ~$2.5 million. So ~60 BTC could be safely mixed over a few days. Decent mixers: bitmixer.io (bitmixer2whesjgj.onion) Bitcoin Fog (foggedddxlunnaaa.onion) Helix (grams7enufi7jmdl.onion/helix/light) I'm not aware that exchanges have blacklisted any mixers. There has been talk of blacklistin…

Just a warning to anyone new to the BTC scene.

DO NOT USE BitcoinFog

Re: The NSA has linked the WannaCry computer worm to North Korea

#120
post #57
post #38

Earlier quoted context omitted.

It's not been fully confirmed/established that Lazarus group == DPRK: see "false flag" from Kaspersky researchers https://www.wired.com/2017/05/wannacry-ransomware-link-suspe...

Yeah, I don't know. People tend to believe the narrative story they want to believe. When someone claims "the Russians" hacked the DNC and other operatives, there is very little "false flag" ("how do you know it really was the Russians?") claims (and for good reason), but when something does not fit their belief systems then it's "oh, false flag" despite reputable researchers putting their reputation on the line.

It's about broader context, or a lack thereof.

The DNC hack is self-consistent and aligned with known motives of suspected actors, so the public sees a false flag as possible but improbable. WannaCry came seemingly out of nowhere using a mixed bag of tricks from unfamiliar actors... absent context, the public will entertain any explanation.

Post reply on HN