Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

111–120 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#111

Earlier quoted context omitted.

The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.

You can’t separate colonialism and imperialism from Korea. As if any of us know what Korea would be doing if the west didn’t invade then sanction among other things.

North Korea invaded South Korea after US pressured South Korea to disarm. North Korea was the imperialist actor here.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#112
post #26

Earlier quoted context omitted.

[flagged]

> For starters, this propaganda often mischaracterizes the Monroe Doctrine as the US preying on its neighbors the way Russia and China are currently doing, when in fact it was a policy aimed at keeping wars between European colonial powers away from the newly independent countries in the Americas. ...so we can freely do as we please. Of course we've been preying on our neighbors. We've been invading and deposing all…

>Panama

92% of Panamans supported the invasion to despose Noreiga and actually would have preferred the US do it earlier back during his second coup.

Truth be speaking, I would where you are getting your history, if not just from skewed leftist internet Podcasters. Not mentioning the larger context of the Cold War and the opinions of the people on the ground does look more like lying by omission.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#113
post #25

I’ve heard that in North Korea it is difficult for ordinary people to learn or own a computer. It is assumed that a small number of elite operatives are selected and trained to carry out such tasks, and it is somewhat surprising that they possess the latest technology and conduct hacking.

I always understood that these hacks are one of the main ways for North Korea to actually earn money in other currencies, as they’ve been barred from trading with pretty much the entire world.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#114
> Attribution Scenarios: Option A: DPRK Operator Embedded in PRC

> Use of Korean language, OCR targeting of Korean documents, and focus on GPKI systems strongly suggest North Korean origin.

I'm don't follow how needing OCR to read Korean documents points to them being North Korean?

Could also point in the opposite direction of them needing to copy the text for translation.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#115
post #56
post #42

Earlier quoted context omitted.

one time i ran nmap against my dev box at facebook. i was definitely worried someone was going to give me a stern talking to.

I ran 'neoprint.php' on myself at Facebook in 2007 and immediately got a stern email about it... It was some script that collected info for responding to law enforcement requests. But after chastising me, the email said "I was gratified that you ran it on yourself". (as opposed to snooping on someone else!) It was just a summer internship and FB was like 'only' 80 engineers back then. But they still took it seriously…

I think that's a little different. It sounds like neoprint.php is an internal Facebook tool for looking up data on Facebook users. So improper usage of it is a privacy problem for users. It's something misbehaving employees might run against celbrities, exes, etc. (e.g. https://www.gawkerarchives.com/5637234/gcreep-google-enginee... )

Otoh nmap isn't a privacy problem for users of Facebook (or any other tech company).

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#116

> Attribution Scenarios: Option A: DPRK Operator Embedded in PRC > Use of Korean language, OCR targeting of Korean documents, and focus on GPKI systems strongly suggest North Korean origin. I'm don't follow how needing OCR to read Korean documents points to them being North Korean? Could also point in the opposite direction of them needing to copy the text for translation.

Their shell history shows them using OCR tools. AFAIK it doesn't show them using translation tools.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#117

Earlier quoted context omitted.

> For starters, this propaganda often mischaracterizes the Monroe Doctrine as the US preying on its neighbors the way Russia and China are currently doing, when in fact it was a policy aimed at keeping wars between European colonial powers away from the newly independent countries in the Americas. ...so we can freely do as we please. Of course we've been preying on our neighbors. We've been invading and deposing all…

>Panama 92% of Panamans supported the invasion to despose Noreiga and actually would have preferred the US do it earlier back during his second coup. Truth be speaking, I would where you are getting your history, if not just from skewed leftist internet Podcasters. Not mentioning the larger context of the Cold War and the opinions of the people on the ground does look more like lying by omission.

I read history books like anyone else, the cold war was just straight retarded, and we trained Noriega (at the very school I already linked to). Furthermore just because I want someone to invade and liberate us doesn't mean it's not a violation of international law and sovereignty.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#118
post #91

Earlier quoted context omitted.

ChatGPT decoded the ROT47 text immediately from a simple prompt: "Decode this string sent by some random pompous guy on Hacker News: [raw string]". If robots want in, they will get in eventually too, apparently.

It was a simple way to highlight impulsive behavior common in modern users, and the trivial encoding function should be obvious to those who are minimally empathetic. Ask the LLM handler if being lied to makes people feel worse than getting robbed... then consider if you would hire such individuals. If you are ever unsure of someones motives, than politely ask for context. Have a wonderful day =3 https://en.wikipedia…

What is the impulsive behavior? Do you have a zero day in some ROT-47 decoder? Or perhaps a zero day in the file command in case a user creates a file containing the string and runs the command on it? Or is the string both a valid ROT-47 string and a valid executable on some platform?

> If you are ever unsure of someones motives, than politely ask for context.

Asking for context.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#119
post #97
post #87

Earlier quoted context omitted.

> I am a Hacker and I am the opposite to all that you are. In my realm, we are all alike. We exist without skin color, without nationality, and without political agenda. We are slaves to nobody. Classic elitist take ignoring that this this space where "all are alike" can only work for certain kinds of people.

Your quote it is out of context, they are talking to North Korea's -sociopathic- government accomplice: > North Korean citizens are kidnapped by a dictatorship. They are talking to someone who supports crimes against humanity.

[dead]

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#120

> Attribution Scenarios: Option A: DPRK Operator Embedded in PRC > Use of Korean language, OCR targeting of Korean documents, and focus on GPKI systems strongly suggest North Korean origin. I'm don't follow how needing OCR to read Korean documents points to them being North Korean? Could also point in the opposite direction of them needing to copy the text for translation.

Their shell history shows them using OCR tools. AFAIK it doesn't show them using translation tools.

Actually KIM was also using Google Translate (discovered through his browsing history)
Post reply on HN