Live data from Hacker News

Countering threats from North Korea

blog.google

71–80 of 172 posts

Re: Countering threats from North Korea

#71

Earlier quoted context omitted.

I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years. (Disclaimer: I am head of TAG)

Quoted post unavailable.

Here's the report which associated Clear Sky with NK, and it's not from Google:

https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...

Re: Countering threats from North Korea

#72

Earlier quoted context omitted.

I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years. (Disclaimer: I am head of TAG)

Quoted post unavailable.

Rather than attacking him, you are free to discuss on how it would be hard to attribute or reach to a source.

Just because you might not know what techniques the researchers here used to reach to that conclusion, doesn't mean they would have used dubious methods.

It is better to ask than attack a person.

Re: Countering threats from North Korea

#73

Earlier quoted context omitted.

Quoted post unavailable.

Rather than attacking him, you are free to discuss on how it would be hard to attribute or reach to a source. Just because you might not know what techniques the researchers here used to reach to that conclusion, doesn't mean they would have used dubious methods. It is better to ask than attack a person.

The United States reserves the right to react to cyber attacks with force [0]. Instead of asking people to be nice on the internet you should hold those accountable that are in a position to manufacture a narrative. The linked report in the sibling comment here has no valid proof of North Korean involvement but the headline is chosen in a way to paint a picture of an impoverished nation as an aggressor. If you just accept that Google can make up facts to pave the way for physical warfare you are complicit in the eventual deaths of thousands of innocent people.

To be precise. After the CIA made up reports of WMDs in Irak people should ask for receipts earlier.

[0]: https://www.reuters.com/article/us-usa-defense-cybersecurity...

Re: Countering threats from North Korea

#74

Earlier quoted context omitted.

Quoted post unavailable.

Here's the report which associated Clear Sky with NK, and it's not from Google: https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...

Yeah, still waiting for something to substantiate the headline. This report isn't it. A lot of hand-waving about other people's hand-waving.

Re: Countering threats from North Korea

#75

Earlier quoted context omitted.

> (Insert obligatory "wiki it's not always accurate etc etc"). Overall I'd take either one and personally don't care. Just trying to match what you're saying with what I'm reading and make sense of where the truth is. Diving in (even if the parent doesn't care :) ): The last sentence is the real challenge: Meanings depend 100% on writer and reader understandings. If two agree that 'homograph' means 'chicken poop', as…

> Some dictionaries influence meaning by being prescriptive (e.g., American Heritage, IIRC); others report what has been understood by being descriptive (e.g., Oxford). The problem is, Wikipedia is neither: It represents the understandings of a few editors of unknown knowledge; it is neither descriptive nor prescriptive and we quickly get into chicken poop scenarios. To be clear: reporting what has been understood st…

> reporting what has been understood still influences meaning. Choice of inclusion moderates spread; definitions are inherently lossy and cannot capture the whole range of nuance; the compiler's understanding can be inaccurate.

I agree and actually had a sentence in the GP that said it, but removed it because it was getting too long. An important point. Also, the Oxford English Dictionary intends to be descriptive and says so, but many readers won't understand that and take it as prescriptive.

> OED no less "represents the understandings of a few editors of unknown knowledge" than Wikipedia does.

The knowledge of OED editors is not unknown but well known and exceptional - the world's leading lexicographers, with the best training and decades of experience. The resources are exceptional: top-notch professional lexicographers, domain experts, databases, teams of volunteers reading and contributing, etc. The definitions are not based on the contemporary understanding of a few people but on over a century of accumulated research, back to the beginning of English, and the understandings of those people, plus it depends on the input of domain experts, editors, etc.

I'm not knocking Wikipedia, which has its value, and the OED is, like every human institution, limited. But beyond that general statement, the quoted sentence doesn't describe the OED at all.

Re: Countering threats from North Korea

#76
post #63

Been looking in that article to find how they concluded it's from North Korea, but I can't find it. Can anyone point it out for me?

https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...

> Analysis of the files shows, that they cannot run on computers that have the Korean, Japanese, or Chinese language preferences

Interesting seeing Japanese here but might just be a language thing.

> LinkedIn profile Protection – we believe that LinkedIn has yet to develop sufficient security mechanisms and protect its users against impostor accounts. We find it alarming that a fictitious profile, copycat an existing account, can be open and use without alerting to source profile from which the information was stolen, as well as profiles contacted by the new imposter profile.

Sounds like some low hanging fruit

Re: Countering threats from North Korea

#77

Earlier quoted context omitted.

That's fair I'm not really one for jargon and whatnot (I think it can actually become less useful if the goal is just to communicate something to a person), but the first line in wiki says: > a homoglyph is one of two or more graphemes, characters, or glyphs with shapes that appear identical or very similar. "Very similar" and "two or more" being the key words. As for homograph I found homoglyph by reading the wiki a…

> (Insert obligatory "wiki it's not always accurate etc etc"). Overall I'd take either one and personally don't care. Just trying to match what you're saying with what I'm reading and make sense of where the truth is. Diving in (even if the parent doesn't care :) ): The last sentence is the real challenge: Meanings depend 100% on writer and reader understandings. If two agree that 'homograph' means 'chicken poop', as…

Awesome response. Thanks for taking the time to write it.

Re: Countering threats from North Korea

#78

Earlier quoted context omitted.

Here's the report which associated Clear Sky with NK, and it's not from Google: https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...

Yeah, still waiting for something to substantiate the headline. This report isn't it. A lot of hand-waving about other people's hand-waving.

APT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?

Re: Countering threats from North Korea

#79
post #63

Been looking in that article to find how they concluded it's from North Korea, but I can't find it. Can anyone point it out for me?

https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...

That's a report from 2020, how would it show this exploit found in 2022 was from North Korea?

Re: Countering threats from North Korea

#80
post #32

Earlier quoted context omitted.

Or potentially there were exploits but they weren't able to encounter them due to the various protection measures the attackers used.

Either way, I find it very hard to believe that they haven’t coordinated with Apple and Mozilla on this CVE.

There's nothing to coordinate with on this cve. There's almost assuredly coordination happening between the various security orgs, but this cve is about a chrome bug, and the Google teams weren't able to isolate ff or safari zero days to report.

"We expect this group has zero days that they're exploiting in your software but we don't know what specifically they are" isn't a cve.

Post reply on HN