Live data from Hacker News

North Korean Spy to Be Charged in Sony Pictures Hacking

nytimes.com

41–50 of 50 posts

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#41

Earlier quoted context omitted.

I disagree with the idea that the DPRK is not capable of such attacks. They've demonstrated they are capable of creating nuclear weapons and ICBMs, I don't think it's such a stretch to say they are capable of APT attacks. Especially when you consider that the DPRK gets a lot of support from China, which also engages in cyber attacks. It wouldn't be difficult to send DPRK citizens to China to be educated and instructe…

Can we get an estimate of how much money was stolen/earned/misplaced/whatever in this hack?

In the Sony hack? None. But many of the Lazarus group's other attacks have resulted in getting significant amounts of money. There was the theft with the Bangladesh bank a few years ago, where they got away with around $100M US. There were some other, smaller incidents involving banks in Vietnam and Taiwan. And the Lazarus group is believed to be behind the WannaCry randsomware, idk how much they got from that.

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#42

Earlier quoted context omitted.

There's some fairly extensive information publicly available in support of the NK connection. I'll point to https://www.operationblockbuster.com/wp-content/uploads/2016... (disclaimer: I worked with the team that wrote that report, though not on Operation Blockbuster itself). That information shows that the group behind the Sony Hack were a previously unknown APT group. Analysis of malware used, C&C servers, and even…

As someone else that's spent a large amount of time looking into this, I'd like to offer a dissenting opinion. I agree with the analysis linking the groups.. however, the final conclusion is because the other attacks were attributed to NK, then we must also attribute these attacks to NK. I think these assumptions need to be questioned. The sophistication of the attacks is so out of proportion with North Koreas abilit…

What's harder, building nukes or hacking Windows? Why should I expect that an entity capable of the first is not capable of the second?

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#43
post #6

What I really want to know is how did they learn the skills to do this? And more importantly, if they had that kind of access to outside information, how do they not know about the atrocities they are involved in? Or is it a catch 22 where if they don’t help then they become a victim?

Some insight into how they learn the skills ... https://www.businessinsider.com/north-korean-defector-jang-s... "Mirim University produces most of the hackers that get placed in Bureau 121. It's a highly competitive program, with each class accepting only about 100 students out of 5,000 applicants. They take six 90-minute classes every day, learning different coding languages and operating systems, from C to Linux. J…

Since my other post is being downvoted into oblivion, I thought I'd add this presentation by a North Korean CS teacher.

https://www.youtube.com/watch?v=Orcmmra9oLQ

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#44

Earlier quoted context omitted.

There's some fairly extensive information publicly available in support of the NK connection. I'll point to https://www.operationblockbuster.com/wp-content/uploads/2016... (disclaimer: I worked with the team that wrote that report, though not on Operation Blockbuster itself). That information shows that the group behind the Sony Hack were a previously unknown APT group. Analysis of malware used, C&C servers, and even…

I've never understood the knee-jerk skepticism to the IC consensus despite no countervailing evidence to these foreign hacks. I'm really concerned we're going to be caught flat-footed to significantly more severe attacks from foreign powers if 40-50% of the population denies that they happened.

It's because institutions everywhere have been caught lieing repeatedly and maliciously. Public trust in institutions has been seriously eroded because those institutions have not been acting in a trustworthy manner.

People are being trained to not believe data from any organized group

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#45

Earlier quoted context omitted.

Can we get an estimate of how much money was stolen/earned/misplaced/whatever in this hack?

In the Sony hack? None. But many of the Lazarus group's other attacks have resulted in getting significant amounts of money. There was the theft with the Bangladesh bank a few years ago, where they got away with around $100M US. There were some other, smaller incidents involving banks in Vietnam and Taiwan. And the Lazarus group is believed to be behind the WannaCry randsomware, idk how much they got from that.

This undercuts either the APT classification or the identification of the APT with DPRK. It's not as though Sony doesn't have any money; a group that steals money would have stolen some. In that case there would have been some sort of credible trail to follow.

Actually the whole "we don't like movies about Dear Leader" supposed motivation is only superficially reasonable. From the leaked email it's clear that this was a chaotic capricious organization that wouldn't have hesitated to fire embittered IT (or simply IT-aware) staff, who would then have been well-placed to do everything that was done to Sony. (I especially liked the unencrypted Word docs they had of nothing but hundreds of passwords. Passwords don't belong in Word docs!) "Guardians of Peace" had a special hatred for Sony execs, while e.g. Rogen and Franco were afterthoughts.

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#47

Earlier quoted context omitted.

In the Sony hack? None. But many of the Lazarus group's other attacks have resulted in getting significant amounts of money. There was the theft with the Bangladesh bank a few years ago, where they got away with around $100M US. There were some other, smaller incidents involving banks in Vietnam and Taiwan. And the Lazarus group is believed to be behind the WannaCry randsomware, idk how much they got from that.

This undercuts either the APT classification or the identification of the APT with DPRK. It's not as though Sony doesn't have any money; a group that steals money would have stolen some. In that case there would have been some sort of credible trail to follow. Actually the whole "we don't like movies about Dear Leader" supposed motivation is only superficially reasonable. From the leaked email it's clear that this wa…

Some of their attacks involve stealing money, but not all of them. Regardless, that argument is circumstantial at best. Look at the report https://www.operationblockbuster.com/wp-content/uploads/2016... . There was re-use of malware, C&C infrastructure, and RSA certificates, that is hard evidence.

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#48
post #36

Earlier quoted context omitted.

It substantially limits their movement, as it increases the caution needed to enter any country with which the US has an extradition treaty. As to explaining password security, the Justice Department is a law enforcement agency, not a security agency.

North Koreans aren't known for their international travel.

North Korean hackers actually travel abroad to their target country for 2 years according to the business insider article someone liked to in this thread. Seems possible they may travel again.

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#49

Earlier quoted context omitted.

Remarkably low level citizens (basically grad students) have access to public (monitored) internet. https://www.youtube.com/watch?v=Orcmmra9oLQ My guess is that, like the incubator baby thing in Iraq, the more heinous crimes are just made up. It's easy to make up stories when there's no way to refute them. The defector stories are already internally inconsistent. https://www.theguardian.com/world/2015/oct/13/why-do-n…

We have large amounts of testimony and evidence for DPRK concentration camps, dating back decades. It's not like we are relying on a single person's testimony. For instance, we have satellite imagery of the prison camps. Also, the guardian article that you linked to literally states that just because there are inconsistencies doesn't mean that there aren't serious human rights abuses, including the existence of priso…

there’s an industry of tabloids and publishers waiting with open arms for nork defectors to denounce their former government. these defectors are basically the dregs of society in south korea; impoverished, unskilled, widely despised and easily identifiable. many of them effectively live in the projects together, working low wage jobs and facing discrimination from the public. if you can make some bank telling a particularly lurid versions of stories you’ve heard back home, and there’s little other opportunity...

none of this is to say that the NK regime doesn’t commit atrocities. i’m certain some of the stories are true. i only mean to point out that there are perverse incentives that point exclusively in one direction.

Re: North Korean Spy to Be Charged in Sony Pictures Hacking

#50
>>Mr. Park, who also went by the alias Pak Jin Hek, is unlikely to see the inside of an American courtroom. The United States has no direct, formal relations with North Korea and did not communicate with its reclusive government ahead of the charges.

And if he did find himself in a court, a couple of professors and escapees can testify that unless he did what he did, he'd be in jail, along with all his extended family. Not guilty. Now maybe he didn't have to be that successful, but we don't know all details beyond reasonable doubt.

Post reply on HN