Live data from Hacker News

N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

nytimes.com

11–20 of 159 posts

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#11

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded. What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials. The document on Der Speigel speaks primarily about taking copies of intelligence from SK ha…

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government).

The average US citizen was outraged that some other government would have the audacity to hack anything in the US. This article's goal seems to be to point out that the US Government is hacking all other nation's governments, including NK. (pot calling the kettle black)

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#12
post #9

Earlier quoted context omitted.

Certainly false flag operations are a tactic that has seen reliable and regular use, especially in counterintelligence. But what purpose exactly would a false flag operation against SONY serve? Definitely not as a pretext to take action against North Korea - the US could much more easily justify actions against NK than it has many other nations in its history.

They could use North Korea "attack" to justify more local measures, you know, banning encryption, tighter regulations, more penalties... more or less what has been happening last weeks.

I absolutely believe that attacks are used as conveniences to justify legislative wishlists, but question whether such things are planned in advance like you are suggesting or are opportunistic responses to actual events.

Regarding encryption bans I've mostly seen justification referencing the Charlie Hebdo attacks (which are assuredly not a false flag).

Personally I believe that North Korean sympathizers were behind the SONY attacks given a number of pieces of evidence, but most heavily the #GOP leaks of emails detailing SONY collaboration with the US State Department and RAND Corporation that point toward The Interview being a strategic diplomacy product.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#13

According to the article, NSA noticed the first spear-phishing attacks against Sony in September. Yet they didn't realize admin credentials had been stolen until much later. Nor did they seem to notice terabytes of data being exfiltrated out of Sony. Fishy story.

Fishy? It seems quite likely that such a thing could be overlooked. The NSA was (as the article says) concentrating their efforts on the DPRK's nuclear weapons program. Some spear phishing attacks aren't exactly a priority in comparison.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#14
post #11

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded. What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials. The document on Der Speigel speaks primarily about taking copies of intelligence from SK ha…

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

Interesting. I had thought it was common knowledge at this point that the US regularly hacks and is hacked by other nations.

I think the biggest splash this article may have is added narrative supporting the truthiness of USG attribution to NK - something that seems to be held in high doubt by a large percentage of the technical crowd (but that I think seems pretty reasonable).

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#15
Typical for the NYT to bury the strong countervailing evidence against the official war-mongering story in a couple of paragraphs 2/3rds of the way through the article.

  Still, the sophistication of the Sony hack was such that many experts
  say they are skeptical that North Korea was the culprit, or the lone
  culprit. They have suggested it was an insider, a disgruntled Sony
  ex-employee or an outside group cleverly mimicking North Korean
  hackers. Many remain unconvinced by the efforts of the
  F.B.I. director, James B. Comey, to answer critics by disclosing some
  of the American evidence.
  
  ... it would not be that difficult for hackers who wanted to appear to
  be North Korean to fake their whereabouts.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#16

Earlier quoted context omitted.

Certainly false flag operations are a tactic that has seen reliable and regular use, especially in counterintelligence. But what purpose exactly would a false flag operation against SONY serve? Definitely not as a pretext to take action against North Korea - the US could much more easily justify actions against NK than it has many other nations in its history.

Playing devils advocate here: The NSA is arguably having a credibility problem at home in the US. It needs to convince the tech industry that there are enemies abroad who threaten their security, and attacks by nation states (who aren't the US) is something that is real. North Korea is a great scape goat. They can deny it all they want, and we don't care about the diplomatic costs, because it can't get any worse. Peo…

I similarly don't see the risk (and collateral damage) v. reward pan out. Plus there are so many legitimate cyber attacks against the United States, it would seem like a waste of resources. And it doesn't seem to me like the NSA would so joyously release the Lynton/Bennett/State Department emails. If they wanted to paint NK in a bad light this would seem so counter to that goal.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#17

Typical for the NYT to bury the strong countervailing evidence against the official war-mongering story in a couple of paragraphs 2/3rds of the way through the article. Still, the sophistication of the Sony hack was such that many experts say they are skeptical that North Korea was the culprit, or the lone culprit. They have suggested it was an insider, a disgruntled Sony ex-employee or an outside group cleverly mimi…

The sophistication of the attack is pretty questionable IMO. The malware used can be purchased by anyone on the black market and had been used before by Iranian hackers in 2012. Furthermore, spearphishing emails were used to get inside the network. Furthermore, how would sophistication be evidence against a State actor with (a reported) 7,000 personnel?

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#18
post #11

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded. What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials. The document on Der Speigel speaks primarily about taking copies of intelligence from SK ha…

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying.

- The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States.

- The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communications).

It's entirely possible to take the position that countries are going to engage in espionage, but that there should be norms about how intelligence services behave. Right now we're all trying to figure out what those norms are.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#19
post #11

Earlier quoted context omitted.

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying. - The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States. - The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communicat…

Thank you for mentioning international cyber operation norms. This is the center of US international cyberpolicy efforts. Ontologies describing categories of cyber operations often place destructive attacks like the one against SONY into a category of its own and these are usually considered fair only in very particular scenarios of provocation.

An addendum here regarding 'free speech'. There is some question about The Interview being a propaganda effort on behalf of the US State Department (which was given a preview as early as July) since #GOP released emails where CEO Lynton discusses the effects of the ending with RAND Corporation strategist and nuclear deterrence specialist Bruce Bennett and Lynton confirmed analysis of its effectiveness with Senior State Department officials. (It also doesn't help that the script writer was asked specifically to consider changing his character from an anonymous leader of NK to Kim Jong-Un).

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#20
post #11

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded. What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials. The document on Der Speigel speaks primarily about taking copies of intelligence from SK ha…

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

It's perfectly fine to be OK with your government hacking other countries while also being mad when those other countries do the same thing (though it's foolish to be shocked when it happens).
Post reply on HN