Live data from Hacker News

Countering threats from North Korea

blog.google

91–100 of 172 posts

Re: Countering threats from North Korea

#92

Earlier quoted context omitted.

Yeah, still waiting for something to substantiate the headline. This report isn't it. A lot of hand-waving about other people's hand-waving.

APT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?

Think of all the big, serious and sensible news organisations that independently reported WMD in Iraq while not being connected to the US government. Are you alleging they're all wrong and this is some vast conspiracy to frame an innocent Iraq and protect.. who, exactly?

Evidence is evidence. After WMD (which totally took me in, btw, you too?) Claims that evidence is "just over there" and "here are multiple different people reporting they've spoken to someone who saw it." Count for zero. Maybe they always should have but there's not doubt this stuff happens anymore. We watched it. (Hopefully) in horror as it unfolded without us objecting.

Re: Countering threats from North Korea

#95
post #83

Earlier quoted context omitted.

Don’t reply to those SMS. Your geolocation can be derived from your reply, even a STOP or UNSUBSCRIBE reply.

Can you explain how this works if you don't click any links?

I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.

Re: Countering threats from North Korea

#96

Earlier quoted context omitted.

Don’t reply to those SMS. Your geolocation can be derived from your reply, even a STOP or UNSUBSCRIBE reply.

Yes, would like to learn more as well.

I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.

Re: Countering threats from North Korea

#97
post #2

> Careful to protect their exploits, the attackers deployed multiple safeguards to make it difficult for security teams to recover any of the stages. These safeguards included: * Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site. * In some email campaigns the targets received links with unique IDs. This was potentially used to enforcea one-time-click po…

For CVEs? No. CVEs are awarded for things as (relatively) little as static keys being packaged with APKs.

What is unusual is that NK used a sophisticated attack chain to successfully pwn a hardened industry (notably, fintech).

At this point I think it’s safe to say that NK is a significant competitor to FVEY in terms of cyber warfare capabilities.

Re: Countering threats from North Korea

#98

Earlier quoted context omitted.

I too saw one of these. Very odd since I was expecting a note about a job.

Don’t reply to those SMS. Your geolocation can be derived from your reply, even a STOP or UNSUBSCRIBE reply.

Can you provide a pointer showing how this is supposed to work?

Re: Countering threats from North Korea

#99
post #83

Earlier quoted context omitted.

Can you explain how this works if you don't click any links?

I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.

Presumably if they have the number to text to, they already roughly know the geolocation for most people, through the area code.

Re: Countering threats from North Korea

#100
post #99

Earlier quoted context omitted.

I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.

Presumably if they have the number to text to, they already roughly know the geolocation for most people, through the area code.

Only in the US (or whole NANP?)

Mobile numbers are non-geographic everywhere else that I know of.

Post reply on HN