Live data from Hacker News

N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

nytimes.com

21–30 of 159 posts

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#21
This is the second NYTimes article I've seen that has suggested that the NSA was collecting information on a group while that group was planning an attack, but that the collection or the analysis was not sufficient to stop the attack. (The other article was on the Mumbai terrorist attack).

This is interesting and you could look at it a number of different ways:

- Collecting data is one thing, but understanding what it means is incredibly challenging and the NSA might not be doing a great job.

- Even when they can't prevent an attack, there is still value in having this data so that they can attribute the attack and understand something about the motives and methods of the attackers.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#22
post #11

Earlier quoted context omitted.

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying. - The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States. - The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communicat…

"To be fair," there are norms about how intelligence services behave. That we, the proletariat, aren't aware of them doesn't make them any less real. That they've either changed or that we've only just discovered what they are doesn't say anything about what they are or used to be.

"Norms" don't necessarily make things objectively or even subjectively better. They just make them standard. Asking for norms will get you absolutely nothing, even if you get what you ask for: They'll just establish what they're already doing as normal, and continue to not tell you about the new things they start doing. Because that's what intelligence is; if they told people what they were doing, for better or worse, people would make it harder for them to do.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#23

This is the second NYTimes article I've seen that has suggested that the NSA was collecting information on a group while that group was planning an attack, but that the collection or the analysis was not sufficient to stop the attack. (The other article was on the Mumbai terrorist attack). This is interesting and you could look at it a number of different ways: - Collecting data is one thing, but understanding what i…

Or:

- They supposedly were collecting all this info and didn't think to warn Sony about any potential issues.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#24
post #11

Earlier quoted context omitted.

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

Interesting. I had thought it was common knowledge at this point that the US regularly hacks and is hacked by other nations. I think the biggest splash this article may have is added narrative supporting the truthiness of USG attribution to NK - something that seems to be held in high doubt by a large percentage of the technical crowd (but that I think seems pretty reasonable).

People forget that before Snowden the story was how bad the US's cyber intelligence was compared to China, etc.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#25

This is the second NYTimes article I've seen that has suggested that the NSA was collecting information on a group while that group was planning an attack, but that the collection or the analysis was not sufficient to stop the attack. (The other article was on the Mumbai terrorist attack). This is interesting and you could look at it a number of different ways: - Collecting data is one thing, but understanding what i…

- Or "national security" doesn't mean what normal English-speaking humans think it means. The hack was no threat to the reigning industrial/government structure or the dollar.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#26

Earlier quoted context omitted.

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying. - The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States. - The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communicat…

"To be fair," there are norms about how intelligence services behave. That we, the proletariat, aren't aware of them doesn't make them any less real. That they've either changed or that we've only just discovered what they are doesn't say anything about what they are or used to be. "Norms" don't necessarily make things objectively or even subjectively better. They just make them standard. Asking for norms will get yo…

The norms in question are those of cyber attacks. This includes but is not limited to intelligence operations. The SONY attack, for example, was not an intelligence operation. The downing of the Syrian airforce was not an intelligence operation. Nor was Stuxnet or the the Georgia cyberattack.

Norms are important because they are precursors to law (in this case international law). Norms create ground upon which a country can accuse another, a ground upon which you can achieve consensus among many parties, and norms set expectations of behavior that if loosely followed every country can benefit from.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#27
> Mr. Jang said that as time went on, the North began diverting high school students with the best math skills into a handful of top universities, including a military school specializing in computer-based warfare called Mirim University, which he attended as a young army officer.

I realize I'm not engaging the core topic being discussed, but stories like this are why I'm surprised people like Will Scott haven't gotten in trouble. (I don't want to single him out, but he's the best example I have at hand.) For the past two years, he's gone to North Korea to volunteer teaching computer science.[1][2] At best, his students' skills will be wasted on some silly Android apps praising the supreme leader. More likely, these students will go on to make software for less-than-ethical purposes: wargame simulation, nuclear explosion modeling, missile guidance systems, or network/server subversion.

I'm not saying this software shouldn't exist, just that the world would be better-off if the DPRK had more difficulty writing it. And I'm surprised the State Department hasn't fined or revoked the passport of any American who has aided the DPRK in this manner.

1. https://news.ycombinator.com/item?id=8869265

2. https://news.ycombinator.com/item?id=6829558

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#28

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded. What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials. The document on Der Speigel speaks primarily about taking copies of intelligence from SK ha…

And another thing from Spiegel's article. NSA routinely attacks targets and then makes it look as if someone else did it:

> But the loot isn't delivered directly to ROC's IP address. Rather, it is routed to a so-called Scapegoat Target. That means that stolen information could end up on someone else's servers, making it look as though they were the perpetrators.

So how do we really know it was North Korea, and not just NSA planting that evidence that NK hacked Sony in those two months? I mean other than "trusting NSA"?

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#29
post #11

Earlier quoted context omitted.

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

It's perfectly fine to be OK with your government hacking other countries while also being mad when those other countries do the same thing (though it's foolish to be shocked when it happens).

It's perfectly fine to be OK with your government hacking other countries while also being mad when those other countries do the same thing (though it's foolish to be shocked when it happens).

I would disagree that this opinion is fine; this is only fine if one selfishly considers oneself more important than the 7000000000+ other people on the planet.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#30
post #3

Might be me, but I'd be surprised if they hadn't. They hacked so many countries including China[1], Mexico[1], Belgium[1], Syria[3], Iran[4], etc. (after saying that a digital attack is an act of war[2]). I don't remember each and every leak and I don't feel like looking up everything, but they seem to have targeted loads of people in various countries. I doubt North Korea (which is not even an ally) is the exception…

I don't believe that the US has ever said that "a digital attack is an act of war". The quote that you linked to says that the United States reserves the right to respond militarily to "hostile acts in cyberspace" if it exhausts all other options and judges the costs of action to be greater than the costs of inaction.

The statement is not saying that any cyberattack is an act of war, it is saying that the United States might treat certain attacks as the cost of doing business but that other attacks might require a military response, depending on the specifics of the incident.

Post reply on HN