Live data from Hacker News

I'm the hacker that brought down North Korea's Internet for over a week. AMA

old.reddit.com

91–100 of 173 posts

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#91

Earlier quoted context omitted.

> western political philosophy, known as Westphalian sovereignty) is that there is no other authority inside a State’s borders except its own You’re citing centuries-old political philosophy, only remnants of which remain in our world [1]. The West that arose after WWII and through the Cold War is decidedly non-Westphalian. Concepts like human rights, non-proliferation and self determination are non-Westphalian. The…

These "proponents" seem less strict about applying this philosophy to states other than their own.

The Westphalian treaties gave France, Sweden and later Russia the explicit right to intercede to guarantee the Imperial constitution [1]. (Westphalia was concerned with the Holy Roman Empire.)

Westphalian sovereignty as a historical concern is a myth [2].

[1] https://en.m.wikipedia.org/wiki/Guarantor_of_the_imperial_co...

[2] https://www.cambridge.org/core/journals/international-organi...

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#93

Earlier quoted context omitted.

See OSINT. It's well established terminology. https://en.wikipedia.org/wiki/Open-source_intelligence

It's a weird term. My impression is that it mostly means "randos LARPing spies", though there's a commercial angle too, it being to intelligence what PMCs are to the military. May or may not be called after "Open Source Publishing, Incorporated", featured here: [0]. -- [0] - https://irp.fas.org/congress/2005_hr/062105jardines.pdf

it is not a weird term, and is absolutely a thing. a big deal in 2024, really.

back in the day it was just "reading the newspapers and talking to the local cab drivers", but on 2024 you're scanning forums and social media, on top of news sites.

go to a military-related subreddit and start asking questions about stuff, and you'll eventually get an expert to chime in. Make wrong & stupid claims and then have them slap you down and spill some details -- that's how they got dudes to release classified tank info in Warthunder.

dudes in Palestine and in Ukraine are getting killed because they post selfies and tweets that have GPS coordinates in the metadata. Not hidden behind any top secret firewall, easy to find if you're checking VK or Instagram, but very real implications for dropping bombs.

OSINT is also absolutely a thing in Cyber, where you can get a lot of details about a target by reading their press releases -- "Corp X signs big new deal with Oracle" -- which can give you a new attack surface. Phishing, on a long, broad timeline, has a very high success rate, so go onto Linkedin and start connecting to people. Figure out their tech stack, create a Sales Guy account, and start reaching out to Architects and Managers, and then map out the teams that might have elevated access...

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#94
post #70

Earlier quoted context omitted.

None. This was a middle finger to the NK State apparatus and that's about all.

I think this was a pretty stupid joke. Especially if the OP is an individual. Making a nation state your adversary as merely a sole individual is something you never ever want to even risk. Any rational human being (not just hacker) would know or recognize that. Very often it is ego that directly leads to doing irrational actions like this.

North Korea was already targeting him. The hack was in retaliation.

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#95
post #92

I'm shocked that he shows his face and identifies himself willingly

Big "lifelock" vibes...and if I understand it correctly, that lifelock character has had his identity successfully stolen and impacted multiple times.

Sometimes the person who says "I'm really smart, like mensa level", does some really ignorant and stupid things.

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#96
post #92

I'm shocked that he shows his face and identifies himself willingly

I worked with him briefly on another project and he was pretty comfy and open about the whole thing. In fact I think I remember him mentioning doing a talk at a conference about it. He's a genuinely nice guy and fairly laid back about things. NK regime maybe is annoyed with him, but there is an almost zero probability of them being able to do anything other than digital harrassment to him.

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#97

Earlier quoted context omitted.

No no no, ofc its morally justified to do such thing against impoverished nations! After all, if they are subjected to famine-inducing embargoes, they probably deserve it!

Self imposed poverty due to the authoritarianism. They’re the bad guys, we care less if bad things happen to them.

[flagged]

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#98
There are a couple good points in the linked Wired article, such as the fact that the Russians, Chinese, Iranians, and North Korea are already escalating attacks on civillian and commercial targets and our restraint isn't being matched.

I fully understand why the US and partner governments won't be able to respond in kind, but there is certainly a lot more that could be done in that domain.

Re: I'm the hacker that brought down North Korea's Internet for over a week. AMA

#99

Earlier quoted context omitted.

See OSINT. It's well established terminology. https://en.wikipedia.org/wiki/Open-source_intelligence

It's a weird term. My impression is that it mostly means "randos LARPing spies", though there's a commercial angle too, it being to intelligence what PMCs are to the military. May or may not be called after "Open Source Publishing, Incorporated", featured here: [0]. -- [0] - https://irp.fas.org/congress/2005_hr/062105jardines.pdf

Ye they are larpers that sell security consulting etc.

It is a scam. Especially attribution of hacks to states that are on the Washington shit list. There is just no way to know.

Post reply on HN