Earlier quoted context omitted.
I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.
Presumably if they have the number to text to, they already roughly know the geolocation for most people, through the area code.
Countering threats from North Korea
101–110 of 172 posts
Re: Countering threats from North Korea
#102Earlier quoted context omitted.
But why ask? Why not ask why we can't use forests or jquery to prevent these attacks? What is the logic here, how do you think it might work, even just vaguely if you don't have a worked-out solution? Edit: from another comment in a sibling thread, you indicate thinking that WASM has a "security model / sandbox". That would have been (part of) the answer to the grandparent comment I suppose.
My logic was here that WASM was created/designed by companies that do maintain browsers - Mozilla Microsoft Google Apple and it is marketed as "WebAssembly describes a memory-safe, sandboxed execution environment that may even be implemented inside existing JavaScript virtual machines. When embedded in the web, WebAssembly will enforce the same-origin and permissions security policies of the browser." Basically I fel…
Re: Countering threats from North Korea
#103Earlier quoted context omitted.
Yes, would like to learn more as well.
I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.
https://stackoverflow.com/questions/18523417/can-i-retrieve-...
(Twilio is awesome by the way)
Re: Countering threats from North Korea
#104Earlier quoted context omitted.
Can you explain how this works if you don't click any links?
I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.
https://stackoverflow.com/questions/18523417/can-i-retrieve-...
(Twilio is awesome by the way)
Re: Countering threats from North Korea
#105Earlier quoted context omitted.
Presumably if they have the number to text to, they already roughly know the geolocation for most people, through the area code.
That’s not what I’m talking about. And since number portability and mobile devices became possible, area codes are mostly irrelevant. For example, I’ve lived 2000 miles from the area code of my phone number for probably 10 years now.
Re: Countering threats from North Korea
#106Earlier quoted context omitted.
Here's the report which associated Clear Sky with NK, and it's not from Google: https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...
Yeah, still waiting for something to substantiate the headline. This report isn't it. A lot of hand-waving about other people's hand-waving.
https://www.justice.gov/opa/press-release/file/1092091/downl... has a bunch of evidence that the Justice Department collected when charging some people associated with ATP38 around the Sony Pictures and WannaCry hacks (and other campaigns)
I'd note that things like shared encryption keys and shared TLS passive tables are very indicative of shared resources.
The use of North Korean IP addresses is indicative, but never enough on its own. However, the use of domains controlled by North Korean IP addresses is interesting as well.
Combine that with passwords largely shared with another North Korean attack, devices signed into from NK IP addresses under multiple accounts setup from N Korean IP addresses you start seeing a pattern of behaviour.
And then you find that the person who controlled accounts used by these attacks was a North Korean national (pg 134) who worked for a well known North Korean front company (paragraph 269, pg 136) and the evidence becomes pretty good.
Re: Countering threats from North Korea
#107Earlier quoted context omitted.
APT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?
Think of all the big, serious and sensible news organisations that independently reported WMD in Iraq while not being connected to the US government. Are you alleging they're all wrong and this is some vast conspiracy to frame an innocent Iraq and protect.. who, exactly? Evidence is evidence. After WMD (which totally took me in, btw, you too?) Claims that evidence is "just over there" and "here are multiple different…
OTOH, the evidence linking APT38 to North Korea is pretty compelling. For example, there is a bunch of evidence collected independently identifying individuals associated with APT38, and these people worked for the North Korean company Chosun Expo.
See https://www.justice.gov/opa/press-release/file/1092091/downl... for the evidence in depth.
Re: Countering threats from North Korea
#108Earlier quoted context omitted.
> These groups' activity has been publicly tracked as Operation Dream Job and Operation AppleJeus. Following those links yield these two documents, which both have "Attribution" sections. Presumably some of these tell-tale signs were identified in the ongoing exploitation. https://www.clearskysec.com/wp-content/uploads/2020/08/Dream... https://securelist.com/operation-applejeus/87553/#attributio...
I'm very curious how we can attribute a threat to a particular nation state, given pretty much anything in code/IP/modus operandi/etc. can be faked by one party to look like another. I went through both links and all I found was a lot of hand-wavings like > One of the top identifiers of Lazarus is their dual attack mission – money theft and espionage. This modus operandi is unique to North Korea, as other state actor…
This is about WannaCry, but it shows how multi-source attribution is done.
Re: Countering threats from North Korea
#109Earlier quoted context omitted.
We see some of this with just normal spear phishing against companies. The "single click" thing is reasonably common, it makes things a bit harder to catch as often the clickthrough will change to whatever is being spoofed in the first place. A homophone ycornbinator.com would serve the malware first time, then next time it would send a permanent redirect. Unique IDs you'll see in things like spam SMS, both to work a…
I am receiving increased SMS spam past week. Is connected to this exploit? Msgs are all different domains with unique ID appended.
Back in the 90s and early 2000s the worst that could happen was, say, texting a commercial number to get a polyphone ringtone, and that actually being a subscription. But obviously that is something you have to initiate first, not something passive.
Re: Countering threats from North Korea
#110Earlier quoted context omitted.
APT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?
Think of all the big, serious and sensible news organisations that independently reported WMD in Iraq while not being connected to the US government. Are you alleging they're all wrong and this is some vast conspiracy to frame an innocent Iraq and protect.. who, exactly? Evidence is evidence. After WMD (which totally took me in, btw, you too?) Claims that evidence is "just over there" and "here are multiple different…
For what it's worth, quite a few people were skeptical about the WMD "evidence" at the time, and even more cynics like myself figured that true or false, it was mostly an excuse for George W to Do Something(tm) after 9/11 and at the same time finish off the war his dad started.