Live data from Hacker News

The NSA has linked the WannaCry computer worm to North Korea

washingtonpost.com

191–200 of 253 posts

Re: The NSA has linked the WannaCry computer worm to North Korea

#191

OK, so I know this is going to come up in the comments, but this is not remotely a baseless allegation. The Lazarus group (one of the names for the DPRK-associated APT group) is somewhat well known and is quite sophisticated. This is the same group that hacked Sony a few years back. And to preempt people who are going to chime in with "Sony was just some insider leaking data" there is extensive evidence showing it wa…

> DISCLAIMER: I worked with the people who wrote that report In other words trust us we are sooo much smarter than you mere plebs...

The op made a bunch of assertions provided a reference which refuted one of her assertions and then appealed to authority...

Re: The NSA has linked the WannaCry computer worm to North Korea

#192
post #129

The only rational response to this is deep, deep skepticism. In the old days of the USSR, while very difficult, it was at least conceivable that you could just fly to moscow and see if they were eating their children there or burning priests or god knows whatever else. There was a natural limit to the deception that could occur and further a normal person could make conclusions about the things they saw with their ow…

So, very cut down, you're saying that the US are implicating North Korea because they know they can, because they think that "normal civilian joes" don't know anything about NK? I'de say it's highly likely too, but what we need to find out is why would the US deep-state do this? Is there a specific motive for the US deep-state haphazardly implicating NK, other than, just maybe, the NSA got their hands on some evidenc…

I can think of some motivations:

- NK is developing longer-range ICBMs, and relations with the US have been deteriorating; recently, in response to a Trump tweet, NK threatened to drop a nuke on NYC [1]. Nobody in the administration is going to complain if NK takes a propaganda hit.

- The NSA has been taking a lot of blame for WannaCry, and pointing fingers at NK diverts some of that blame.

[1] http://www.newsweek.com/north-korea-attack-new-york-nuclear-...

Re: The NSA has linked the WannaCry computer worm to North Korea

#193
post #144

Earlier quoted context omitted.

They clearly had a fluent Chinese speaker working with them. https://www.flashpoint-intel.com/blog/linguistic-analysis-wa... Of course I'm sure the NSA has a number of fluent Chinese speakers.

> A number of unique characteristics in the note indicate it was written by a fluent Chinese speaker. A typo in the note, “帮组” (bang zu) instead of “帮助” (bang zhu) meaning “help,” strongly indicates the note was written using a Chinese-language input system rather than being translated from a different version. More generally, the note makes use of proper grammar, punctuation, syntax, and character choice, indicating…

Not every IME has fuzzy pinyin and I don't think the Microsoft one has it enabled by default.

Re: The NSA has linked the WannaCry computer worm to North Korea

#194

Earlier quoted context omitted.

So, very cut down, you're saying that the US are implicating North Korea because they know they can, because they think that "normal civilian joes" don't know anything about NK? I'de say it's highly likely too, but what we need to find out is why would the US deep-state do this? Is there a specific motive for the US deep-state haphazardly implicating NK, other than, just maybe, the NSA got their hands on some evidenc…

I can think of some motivations: - NK is developing longer-range ICBMs, and relations with the US have been deteriorating; recently, in response to a Trump tweet, NK threatened to drop a nuke on NYC [1]. Nobody in the administration is going to complain if NK takes a propaganda hit. - The NSA has been taking a lot of blame for WannaCry, and pointing fingers at NK diverts some of that blame. [1] http://www.newsweek.co…

> The NSA has been taking a lot of blame for WannaCry, and pointing fingers at NK diverts some of that blame.

Which is the exact reason I wouldn't trust any NSA-provided news about the origins of WannaCry more than I trust an average warez-site.

Re: The NSA has linked the WannaCry computer worm to North Korea

#195
post #144

Earlier quoted context omitted.

They clearly had a fluent Chinese speaker working with them. https://www.flashpoint-intel.com/blog/linguistic-analysis-wa... Of course I'm sure the NSA has a number of fluent Chinese speakers.

> A number of unique characteristics in the note indicate it was written by a fluent Chinese speaker. A typo in the note, “帮组” (bang zu) instead of “帮助” (bang zhu) meaning “help,” strongly indicates the note was written using a Chinese-language input system rather than being translated from a different version. More generally, the note makes use of proper grammar, punctuation, syntax, and character choice, indicating…

It's this lack of follow through which burns me in regard to these investigations.

> The two Chinese ransom notes differ substantially from other notes in content, format, and tone. Google Translate fails in both Chinese-English and English-Chinese tests, producing inaccurate results that suggests the Chinese text was likely not have been similarly generated by the English text.

Really? Did Flashpoint even compare English to Chinese samples from the many professional human-based translation services online or was Google Translate their sole source of testing?

> Perhaps most compelling, the Chinese note contains substantial content not present in any other version of the note, is lengthier, and differs slightly in format.

Hmm. That again suggests it may have been interpreted by a human. Although why immediately assume it's one of the authors? A human-based translation service could yield the same results...

Re: The NSA has linked the WannaCry computer worm to North Korea

#196

Earlier quoted context omitted.

> A number of unique characteristics in the note indicate it was written by a fluent Chinese speaker. A typo in the note, “帮组” (bang zu) instead of “帮助” (bang zhu) meaning “help,” strongly indicates the note was written using a Chinese-language input system rather than being translated from a different version. More generally, the note makes use of proper grammar, punctuation, syntax, and character choice, indicating…

Not every IME has fuzzy pinyin and I don't think the Microsoft one has it enabled by default.

Yeah. You are right about that. So I am not ruling out the possibility that someone who mispronounces the word was the author.

Still the odds are low, considering this is a common phrase and he/she has likely made similar mistakes before (zh -> z) and taken some corrective actions to prevent future typos.

Re: The NSA has linked the WannaCry computer worm to North Korea

#197
post #142
post #28

lol...at some point there will have to be some type of specifc discussion on null-routing that shit-hole of a country...

And then they use a Chinese VPN. You can't stop a nation state with by geoblocking.

heh, of course you are correct. i was using "null-routing" in a more borad methaphorical sense, in a weak attempt at humor.

Norks are China's useful idiots so nothing going to change in near term...

Re: The NSA has linked the WannaCry computer worm to North Korea

#198
While any sort of attribution claim should be taken with a lot of skepticism I wouldn't at all be surprised if it was NK. They routinely engage in behavior that keeps the region from getting too stable. The asymmetric nature of cyber-warfare is a perfect fit for them.

Re: The NSA has linked the WannaCry computer worm to North Korea

#199
post #129

The only rational response to this is deep, deep skepticism. In the old days of the USSR, while very difficult, it was at least conceivable that you could just fly to moscow and see if they were eating their children there or burning priests or god knows whatever else. There was a natural limit to the deception that could occur and further a normal person could make conclusions about the things they saw with their ow…

> Now, the enemy that "we have always been at war with" ... is attacking us with secret cyber weapons that only a domain expert with highly specialized experience could even recognize, much less qualify. WannaCry is a wormable implementation of a leaked NSA exploit. Maybe not "trivial", but this wasn't exactly Stuxnet. I frankly don't share the knee-jerk skepticism of many in this comment section, and certainly not b…

>this attack is well within their capability

And the asymmetric nature of cyber warfare is a perfect fit for a small, marginalized state looking to destabilize everyone else.

Post reply on HN