Earlier quoted context omitted.
> It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution. I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to…
Given it's an official Google blog post related to a nation-state threat actor, somebody asking for valid attribution could be a way attackers try to: 1) Derail the conversation 2) Find out ways to further cloak their footprint IMO if you've worked in the field, you know it's a dumb question meant to invoke something. "Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!" Sadly,…
Back to the subject at hand, and taking a more general view, trusting a big Pentagon-contractor [1] (and not only) such as Alphabet on the subject of other countries' cyber-attacks against the US (and its Western allies) is just futile.
[1] https://www.reuters.com/technology/pentagon-awards-9-bln-clo...