Earlier quoted context omitted.
Attributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that. Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal. WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chines…
> It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution. I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to…
1) Derail the conversation 2) Find out ways to further cloak their footprint
IMO if you've worked in the field, you know it's a dumb question meant to invoke something.
"Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!"
Sadly, I am a nobody who happened to see DPRK not tunnel to a VPN.