Live data from Hacker News

Countering threats from North Korea

blog.google

151–160 of 172 posts

Re: Countering threats from North Korea

#151

Earlier quoted context omitted.

Take care of how?

Probably doing similar things to what's been done with Russia, more sanctions, more sanctions against supporting nations etc. They're soon to test a nuclear weapon and already play fun games testing missiles and having them land just off the coast of Japan. Not going to be fun once those things are nuclear missiles and en route to Tokyo.

Their economy is already almost completely dependent on China. It's hard to sanction them more.

Sanctions against Russia aren't uniquely effective in a way that sanctions against NK aren't. It's just that the threat of having your economy look like North Korea's is pretty dire.

Re: Countering threats from North Korea

#152

Will WebAssembly save us from this kind of CVEs? assuming it has capabilities to support "modern" web

So far WebAssembly implementations look fairly secure, thanks to a small attack surface. AFAICT WebAssembly CVEs are mostly DoS.

And WebAssembly has been used by Mozilla for sandboxing: https://hacks.mozilla.org/2021/12/webassembly-and-back-again...

So it may help. But wasm is never going to be eg a substitute for JS, so it's not going to "save us" the way you imply.

Re: Countering threats from North Korea

#153
post #134
post #109

Earlier quoted context omitted.

Hearing Americans regularly complain about SMS and robocall spam still blows my European mind. I haven't received a single spam call or SMS in my life, ever. Back in the 90s and early 2000s the worst that could happen was, say, texting a commercial number to get a polyphone ringtone, and that actually being a subscription. But obviously that is something you have to initiate first, not something passive.

I, in Australia, had never received a spam call or SMS, until two years ago. I now receive several per day. All automatically blocked, but still. My number was leaked in a particular data breach that actually had nothing to do with me, but a different family member who had all of their contacts vacuumed up before the breach. So from my perspective it was passive.

in india its pretty common for businesses/ orgs to sell number data in bulk which is bought by advetisers.

you can be sure to be bombarded with calls and sms if a students applies for a notify thing or gives their number somewhere outside exam halls or on student help websites.

same for shops asking for mobile numbers.

then there are marketers who randomly call each number, send sms to see what sticks.

the situation is pretty bad i would say because for every careful person who sees through the ruse, there are hundreds who fall for million dollar prizes and kyc scams and all.

people call you and say "we are form bank. main branch. you need to verify your debit card or your account will close". no name of bank, no place of branch, just "from bank. main branch".

Re: Countering threats from North Korea

#154
post #140

Earlier quoted context omitted.

I live in Germany and I get a lot of spam calls and spam SMS. It's always in waves. Some days I stop answering calls if I don't recognise the number, because its one of these days where Interpol has informwd me already three times that my identity was stolen and I have to give them all my details to fix this ..... They're very patient at Interpol, I keep hanging up on them and they never give up.

When I have a spammer/scammer on the phone (and I actually picked up), I usually just put my phone on mute and stop talking to them. They waste a bit more time that way before they hang up (without more effort from me).

I try to help them out by letting them know that I have been trying to reach them about their car's extended warranty.

Re: Countering threats from North Korea

#155
post #146

Earlier quoted context omitted.

What approaches are being considered here out of interest? I’m only familiar with Firefox’s use of Rust, but haven’t heard anything about other browsers trying to use that particular approach.

The biggest coming change is raw_ptr wrapper to replace raw pointers stored in structs and classes. Presently in Chromium it is no-op, but soon will be replaced by a non-trivial implementation that will instantly crash on use-after-free.

The raw_ptr/BackupRefPtr/MiraclePtr [1] mitigation will change the security industry. It is quite a feat what Chromium is doing.

[1] https://chromium.googlesource.com/chromium/src/+/ddc017f9569...

Re: Countering threats from North Korea

#156
post #144

Why does Google even need to mention North Korea in the title? A vulnerability is a vulnerability. Why bring politics in, right in the title? It would feel much more OK if simply said in the text , that a NK hacker group is currently known for exploiting it. Imagine it was a vulnerability being exploited by a TLA of the US of A. What would Google say? Or would they have received a gag order to not talk about it at al…

Because of the close ties of US tech giants and the US "intelligence" community.

Re: Countering threats from North Korea

#157
post #144

Why does Google even need to mention North Korea in the title? A vulnerability is a vulnerability. Why bring politics in, right in the title? It would feel much more OK if simply said in the text , that a NK hacker group is currently known for exploiting it. Imagine it was a vulnerability being exploited by a TLA of the US of A. What would Google say? Or would they have received a gag order to not talk about it at al…

Because more people will click on it and read it. Call it "Countering CVE-0284-b" and 50 people will read it. Go with a political catalyst title and you get thousands if hits, even if they then close the tab immediately.

It means more random user-agent/referrer data for them and I'm guessing more domain authority or whatever that crap is.

It's marketing. The article concludes with how the Google Chrome safe browsing list was updated bla bla bla.

It's all just marketing. That's how Google operates. Everything is a shop window. Everything you say, do and make. Google is the market research company.

Except they've repeatedly created products that no one wanted and killed them.

But that's a form of market research when you have a lot of money.

I feel like Google collects so much information it probably doesn't get much sense out of it. Who knows

Re: Countering threats from North Korea

#158
post #114

Earlier quoted context omitted.

Here’s a question I expect you’ll never answer: is it within the capabilities of any groups within the West (state-sponsored or otherwise) to fabricate the information you’re using to make those assessments? And if so, how have you decisively eliminated this possibility? I ask because it’s broadly accepted that there are extremely powerful and wealthy entities in the West who benefit from an aggressive US foreign pol…

Why do you have to prefix your question with, "Here’s a question I expect you’ll never answer"?

I don’t have to, it just makes me look good when he never answers.

Re: Countering threats from North Korea

#159
post #114

Earlier quoted context omitted.

Here’s a question I expect you’ll never answer: is it within the capabilities of any groups within the West (state-sponsored or otherwise) to fabricate the information you’re using to make those assessments? And if so, how have you decisively eliminated this possibility? I ask because it’s broadly accepted that there are extremely powerful and wealthy entities in the West who benefit from an aggressive US foreign pol…

Probably, but even more simply they have the capabilities to just direct intelligence agencies, politicians, and news corporations, and big internet and social media companies to put the blame wherever they like. There is no need for a perfect technological solution. Hack something shoddy together, go to war/regime change/etc, and worst case if it does come to light that the "intel" was wrong, a well-placed "whoopsie…

Uh oh that’s starting to sound like Russian disinformation

Re: Countering threats from North Korea

#160
post #144

Why does Google even need to mention North Korea in the title? A vulnerability is a vulnerability. Why bring politics in, right in the title? It would feel much more OK if simply said in the text , that a NK hacker group is currently known for exploiting it. Imagine it was a vulnerability being exploited by a TLA of the US of A. What would Google say? Or would they have received a gag order to not talk about it at al…

Because they believe it is a state sponsored attack. It isn't politics, it is called attribution which is a threat intelligence product. Identifying and tracking specific threat actors is esentially the entire point of the post which is a threat intel post, means little without the threat part (threat actors not tools).
Post reply on HN