Earlier quoted context omitted.
Don't we have these exact types of sanctions already in place i. NK for exactly the reasons you mention?
Sure, they're not working well enough by the look of it... The people are severely repressed, it's hard to imagine how much North Koreans suffer, look up Yeonmi Park's story. What we seem to do is ignore these maniacs, until it's too late or it's absolutely critical, then they hold us hostage, like Putin.
Countering threats from North Korea
131–140 of 172 posts
Re: Countering threats from North Korea
#132Earlier quoted context omitted.
I read about it on HN some months ago. I don’t recall if it was in comments or an article. But I read the info and sources and was convinced enough at the time. I’m sorry I didn’t save the original info. I’ll try some googling “geolocation from SMS” and see what I can find.
Here’s the best I could find: https://stackoverflow.com/questions/18523417/can-i-retrieve-... (Twilio is awesome by the way)
Re: Countering threats from North Korea
#133Earlier quoted context omitted.
I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years. (Disclaimer: I am head of TAG)
How do you know what country is actually behind any of this? I’d imagine that would be very difficult given nation states can host content anywhere in the world and will want to make it look like it’s coming from elsewhere.
The thing with trying to hide yourself is you have to do everything right to guarantee some false flag operation will work but if you make enough mistakes in this process there will be reasonably high-confidence links between some action and some person.
An example that I _have_ seen in some write up: some snippet of malware code showing up in a stack overflow question (with the shape and user variables being the same).
At one point it's like... probably that person. Of course maybe there are other indicators to the contrary but that's data for you. Gotta use your noggin a bit.
Re: Countering threats from North Korea
#134Earlier quoted context omitted.
I am receiving increased SMS spam past week. Is connected to this exploit? Msgs are all different domains with unique ID appended.
Hearing Americans regularly complain about SMS and robocall spam still blows my European mind. I haven't received a single spam call or SMS in my life, ever. Back in the 90s and early 2000s the worst that could happen was, say, texting a commercial number to get a polyphone ringtone, and that actually being a subscription. But obviously that is something you have to initiate first, not something passive.
My number was leaked in a particular data breach that actually had nothing to do with me, but a different family member who had all of their contacts vacuumed up before the breach. So from my perspective it was passive.
Re: Countering threats from North Korea
#135it is interesting that most of the CVEs are "use after free". instead of being stuck in an endless cycle of detection and patching, maybe, it's time we consider better ways...
Ah, yes, I’m sure the Chrome team is entirely unfamiliar with ways to improve memory safety. Snark aside, every browser vendor is working on this, it’s just that migrating is nontrivial.
Re: Countering threats from North Korea
#136Earlier quoted context omitted.
APT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?
Think of all the big, serious and sensible news organisations that independently reported WMD in Iraq while not being connected to the US government. Are you alleging they're all wrong and this is some vast conspiracy to frame an innocent Iraq and protect.. who, exactly? Evidence is evidence. After WMD (which totally took me in, btw, you too?) Claims that evidence is "just over there" and "here are multiple different…
Re: Countering threats from North Korea
#137Earlier quoted context omitted.
Don't we have these exact types of sanctions already in place i. NK for exactly the reasons you mention?
Sure, they're not working well enough by the look of it... The people are severely repressed, it's hard to imagine how much North Koreans suffer, look up Yeonmi Park's story. What we seem to do is ignore these maniacs, until it's too late or it's absolutely critical, then they hold us hostage, like Putin.
(edit: another old article that points out inconsistencies in Yeonmi Park statements: https://thediplomat.com/2014/12/the-strange-tale-of-yeonmi-p... ... The JRE interview wasn't a fluke)
I don't think that you can reasonably treat Yeonmi Park as a reliable witness.
North Korea's train network is 4700km long, though it is not perfect... If you want to travel from Pyongyang to Chongjin for example, you're better off flying there
Re: Countering threats from North Korea
#138Earlier quoted context omitted.
Ah, yes, I’m sure the Chrome team is entirely unfamiliar with ways to improve memory safety. Snark aside, every browser vendor is working on this, it’s just that migrating is nontrivial.
What approaches are being considered here out of interest? I’m only familiar with Firefox’s use of Rust, but haven’t heard anything about other browsers trying to use that particular approach.
https://microsoftedge.github.io/edgevr/posts/Super-Duper-Sec...
https://microsoftedge.github.io/edgevr/posts/Introducing-Enh...
Re: Countering threats from North Korea
#139Earlier quoted context omitted.
I am receiving increased SMS spam past week. Is connected to this exploit? Msgs are all different domains with unique ID appended.
Hearing Americans regularly complain about SMS and robocall spam still blows my European mind. I haven't received a single spam call or SMS in my life, ever. Back in the 90s and early 2000s the worst that could happen was, say, texting a commercial number to get a polyphone ringtone, and that actually being a subscription. But obviously that is something you have to initiate first, not something passive.
At the moment it's pretty bad with lots of calls from overseas. (People with hilariously un-local accents trying to tell you they are calling from the Ministry of Health of Ministry of Manpower...)
Those overseas callers are faking caller id to look like local numbers.
Re: Countering threats from North Korea
#140Earlier quoted context omitted.
Hearing Americans regularly complain about SMS and robocall spam still blows my European mind. I haven't received a single spam call or SMS in my life, ever. Back in the 90s and early 2000s the worst that could happen was, say, texting a commercial number to get a polyphone ringtone, and that actually being a subscription. But obviously that is something you have to initiate first, not something passive.
I live in Germany and I get a lot of spam calls and spam SMS. It's always in waves. Some days I stop answering calls if I don't recognise the number, because its one of these days where Interpol has informwd me already three times that my identity was stolen and I have to give them all my details to fix this ..... They're very patient at Interpol, I keep hanging up on them and they never give up.