Live data from Hacker News

North Korean hackers stole a record $1.7B of crypto last year

economist.com

131–140 of 203 posts

Re: North Korean hackers stole a record $1.7B of crypto last year

#131

Earlier quoted context omitted.

I don't understand why technology that provides a modicum of privacy must be demonized. It must be for money laundering and criminals. It can't have a legitimate use case. Is it used for nefarious activities? Of course, but not exclusively so.

Can you provide a legitimate use case for mixers? (I'm not trolling, I'm genuinely curious)

Lots of good examples already mostly geared around minimizing bits leaked for the sake of alpha, but there are also instances where it is desirable to be "locally clandestine" even if you're a full throated supporter of the powers that be on the whole. Persecution does not just come by way of financial penalties or the legal system, these tools are useful for avoiding social consequences as well. A hypothetical I'd expect to play well here: paying for an abortion in a large state where it is legal, but in a small town where the local church wields an immense amount of influence.

Re: North Korean hackers stole a record $1.7B of crypto last year

#132
post #77

Earlier quoted context omitted.

How are these scenarios "use cases" for a mixer and not critical flaws in the underlying system? We're in a thread about a rogue state using the tech to steal money to fund their operations (Chemical attacks in airports, nuclear warheads, intercontinental ballistic missiles, etc.) How many nuclear detonations would you consider acceptable in exchange for the cryptobros to have their toys?

Side note, I find it interesting that "bros" is now a pejorative - cryptobros, techbros. Are there other instances? We've come a long way from Mario Bros!

I think it originates from "frat bros" which has been a negative phrase since before the internet.

Re: North Korean hackers stole a record $1.7B of crypto last year

#133

I wonder how many ICBM can that get you... probably like 3 or something... - Found my answer: https://www.brookings.edu/what-nuclear-weapons-delivery-syst... Not a lot...

..I mean...one of those in Seoul is WWIII and MAD of all of Asia...so like...isn't that enough?

I’d like to think that if it was from NK, it would likely be MAD of NK, but not all of Asia. If China was attacked for instance, they have the capabilities to ensure MAD of any other nation or all of them, via a network of nuclear armed submarines - from undetectable locations - even after the nuclear destruction of their mainland. This makes it pretty unlikely for another nation to fire nuclear weapons into China.

Re: North Korean hackers stole a record $1.7B of crypto last year

#134
post #51

Earlier quoted context omitted.

If 99% of BTC mixers' volume is helping laundering international drug trade money, arms or human trafficking, it's not exactly hard to demonize mixing itself. I have no data to base this on, but I assume that privacy absolutists are a tiny, tiny drop in the pool of blood and crime.

do you feel the same way about Tor? If 99% of Tor's volume is helping laundering international drug trade money, distributing CSAM, etc, should it be demonized as well?

Mostly, yes. I sympathize with the goals in theory since I grew up on 90s internet dreams too but as a practical matter if you run a large website you’ll see mostly attacks from Tor, it shows up a lot in news about crime, and it’s noticeably helping people in actual repressive regimes because it’s still too easy to identify the network traffic when the stakes are high.

Re: North Korean hackers stole a record $1.7B of crypto last year

#136
post #96

Earlier quoted context omitted.

What makes you think they'd behave any differently?

Are you implying the Korean people are inherently "evil" or something?

What a strange comment. If anything, he was implying that the rulers of NK are evil and he didn't even really say that.

Re: North Korean hackers stole a record $1.7B of crypto last year

#137
post #30
post #6

Earlier quoted context omitted.

> Not bad for a supposedly backwards repressed regime What do you mean by supposedly? > It also exposes a wider problem the crypto community are not addressing. What wider problem? That money (in any form) can be stolen by a malevolent state?

> What do you mean by supposedly? The DPRK is often portrayed as incompetent, helpless state purely able to eke out an existence by the grace of China (to whom it is useful only as a sort of attack dog cum buffer state). So the fact that they've managed to run an operation that can steal this much crypto may come as a surprise to many. I don't imagine their intelligence agencies are quite on the same level of electro…

I’m not sure it’s out of line with the normal news media portrayal: for decades, it’s been understood that there’s an elite which has access to many things which the average citizen is prevented from doing, and this seems more in keeping with that since ransomware doesn’t require unusual levels of skill as much as legal immunity. This seems in line with the level of resources and skill they’d need to do things like the kidnappings and assassinations: a modest number of people and resources, but not remotely near the level they’d need to field a modern army or high-tech economy, and nothing like the ability to hit a hard target.

What limited that before were the protections built in to the real banking system. Stealing a billion dollars and actually getting away with it was hard until cryptocurrencies were introduced with far fewer safeguards.

Re: North Korean hackers stole a record $1.7B of crypto last year

#138
post #18

Estimated GDP of North-Korea is around $16B (2019); just for context.

Looking at other countries on https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(nomi..., North Korea is near the middle of the pack too. Really puts into perspective how enormous an amount of money this is by most countries' standards.

Re: North Korean hackers stole a record $1.7B of crypto last year

#140
post #119
post #110

Earlier quoted context omitted.

It's not that they don't exist, but the easiest way to gain access to a computer system is always going to be to ask for the password. https://xkcd.com/538/

I have no evidence for this, but my feeling was always that the highest-volume exploits were just having a bot run yesterday's Day-0 on every IP listening on a port. You can't get that kind of volume by calling people and asking for their password. If you leave an unsecured mail server accessible to the internet, it'll start sending spam emails within 30 minutes. On the other hand, phishing emails are also automated,…

It's probably safe to say that phishing is the most common method among APTs like state intelligence agencies. It's cheap, it's easy, it works. No reason to burn zero-days unless simpler methods with less exposure don't work, and they usually do.

But we can broadly categorize security incidents into two bins: first are opportunistic attackers which broadly attempt a method that sometimes works. Two common examples are minimally-targeted phishing emails (think Best Buy invoice) and automated scanning for old versions of WordPress with known vulnerabilities. Second are targeted attacks, where the attacker chooses a target and then attempts different methods to reach success. Overall targeted attacks are far less common than opporunitistic ones, but because they involve a higher level of effort they're only attempted when there's a high level of motivation. Targeted attacks tend to result in greater financial losses than opportunistic attacks, for example, because compromising machines to add them to a botnet usually isn't worth the effort of a targeted attack, but getting banking credentials or crypto wallets usually is.

All of information security is fairly bimodal in this way. It often seems like even technical professionals like software engineers struggle to understand basic security practices, but I think this is one of the biggest causes: most people tend to think about one case and ignore the other. Unfortunately one of the things that makes security very difficult is that both cases are real and the two require fairly different practices to deter, prevent, and detect.

Social methods are far more common with targeted attacks because "true" social engineering involves a higher level of effort, like time on the phone. That said, phishing falls into an in-between where some consider it to be a social method but it is amenable to widespread automation. There's also a wide spectrum of effort in phishing. Many are tempted to try to categorize phishing activity into a binary of "phishing" and "spear-phishing" (I hate these terms), but that doesn't really reflect reality very well. In a large corporation you can usually find examples of phishing that are targeted to varying degrees of specificity: at anyone, at corporate employees broadly, at people in the industry, at employees of a company, a department in that company, and even carefully tailored to a specific employee. The frequency of course tails off as you get more specific, but then it's not that unusual for some organized crime group to run a sustained campaign of fairly closely-targeted phishing as happened recently with Twilio.

Opportunistic attacks are certainly greater in volume to the extent that some call them "internet background noise," but most think that targeted attacks probably produce greater total financial damage. Security is very faddish though, not only on the defense side but also on the offense side, so it probably varies from year to year. For example, the emergence of ransomware was a major trend that required a strategic shift in defense in many organizations since ransomware attacks were fairly low effort but also very high damage in many cases.

Post reply on HN