Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

181–190 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#181

Earlier quoted context omitted.

They just identify talented individuals and send them to schools in China or elsewhere to learn the latest tech.

source? interesting if true.

Why would you doubt it?

The brightest students of most nations are often sent abroad to enrich their countries with knowledge from the great universities. NK is almost unique in its inability to do this at non-Chinese great universities, so that is the only viable route.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#182
post #138

Why everyone working with the government doesn't use hardware keys without passwords so that fishing is useless?

I know some people in the US government who definitely need a hardware key to access computing resources including email. They work for the Dept of the Interior on science stuff, nothing related to national security or otherwise sensitive info. They mentioned this was a pain in the ass, and a very weird restriction since technically any member of the public can ask for a copy of their emails via FOIA.

sounds like the primary goal was better attestation

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#183

Earlier quoted context omitted.

They just identify talented individuals and send them to schools in China or elsewhere to learn the latest tech.

source? interesting if true.

"Major North Korean universities, such as the Kim Il-sung University and the Pyongyang University of Foreign Studies, send a few dozen exchange students to Peking University and other top-ranked Chinese universities each year."[1][2]

"North Korean hackers are sent vocationally to Shenyang, China for special training. They are trained to deploy malware of all types onto computers, computer networks, and servers."[3][4]

1: https://en.wikipedia.org/wiki/Koreans_in_China#North_Koreans...

2: https://web.archive.org/web/20090114201016/http://news.xinhu...

3: https://en.wikipedia.org/wiki/Lazarus_Group#Education

4: https://web.archive.org/web/20180621134306/https://www.scmp....

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#184
post #54

Earlier quoted context omitted.

My basic understanding is that a 'dual use' tool is moreso based on intent; using the same analogy as when this came up on HN over a decade ago [0], a good kitchen knife can be at least as dangerous as a lot of explicitly 'banned' knives but because it has a non-illegal use it doesn't fall into the same category as, say, a DDOS tool. And AFAIK there hasn't (yet) been a case where NMAP has gotten someone in Germany in…

This might be akin to lockpicks in the United States. Not illegal in and of themselves, but if you are possessing them with intent, it's a different matter.

I think it's worth mentioning that this varies by state... while most allow you to possess lockpicking tools freely, some states do have "possession with intent" rules you need to be careful of.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#185
post #168
post #92

Earlier quoted context omitted.

> see the painful experience of Germany's unification I had thought that Germans from both sides were overwhelmingly supportive of re-unification, even if it would cause short-term pain??

I don't think that people are like... against unification in principle, but if you are looking at it from the perspective of the State.... lots of pain and money, and at least in the German experience there was plenty of decent state enterprises for West Germany to (glibly) pillage from. People will handwave about North Korean resources, but even those are more or less accessible via China. And on top of that at the…

Would you consider that half of the USA also votes the wrong way too? And the UK? London people tend to think the rest of the country votes wrong as well. There is a divide in most countries, I think Germany is not that different, except for the fact that it actually was split up before!

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#186
post #150
post #146

Earlier quoted context omitted.

Surely people can still phish for the user to insert their hardware key to approve something malicious?

What is phishing resistant MFA? - https://www.sans.org/blog/what-is-phishing-resistant-mfa

Exactly. 'Resistant' not 'impenitrable'.

The article itself says that 100% phishing resistance is impossible. So I stand by my arguement that if you give an idiot a Yubikey, it still doesnt save them from themselves.

>Does this technology eliminate all risk? No. As this becomes widely deployed new attacks will be developed, but it will be MUCH harder for the cyber attacker.

> FIDO is extremely resistant to phishing attacks but adopting FIDO does not mean your organization is secure against phishing.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#187
post #31

Earlier quoted context omitted.

If anything the hackers in north korea are probably world class if the government is getting their students into focused training programs early in their schooling. Western nations have nothing equivalent due to schooling being generalist and undergrad and grad school not really introducing you to the sort of work you'd actually do on the job as a hacker. 22 year old western hacker for a 3 letter agency is going to h…

> 22 year old western hacker for a 3 letter agency is going to have maybe a 6 month softball tangentially related internship of experience under their belt while the north korean might have years and years by that point. I was with you right up until this bit The agencies concerned tend to recruit people that have demonstrated ability in that field, and they've usually got it with "self-directed" training :)

Lurking forums and irc is probably a terrible way to train a hacker than a dedicated program that introduces you to the tools you'd be using on the job right away. Even today people don't even like hiring self taught engineers anymore like 20 years ago, when there are many more people today who have gone through legitimate education programs.

The one hacker I met in my life went to West Point and had no experience they didn't gain from being placed in their program after graduating with decent test scores.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#188

Earlier quoted context omitted.

It is complicated, but Moral Development theory does cover the phenomena of why some won't understand until they personally grow through the stages of development. Have a great day. =3 https://en.wikipedia.org/wiki/Lawrence_Kohlberg's_stages_of_...

Spies do tough work for not that much pay. (Certainly less than they can earn in the private sector.) They’re starting from a position of duty. Given the stakes the questions they’re tasked with operate at, I’d guess they tend to be in the postconventional regime more than most people.

Sounds like an absurd fiction... and still unrelated to a proper business. =3

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#189

Earlier quoted context omitted.

>I mean the US had no problems selling Nazi Germany arms at the start of the war. This claim doesn't appear to be true: https://www.reddit.com/r/AskHistorians/comments/1k6yi1z/comm...

It's both frustrating and all too common to see blatant historical falsehood being casually thrown around as if it's well known fact. Doubly frustrating knowing that in order to rebut such falsehood, you have to either do your own lengthy research to find the evidence of __absence__ (which is a lot harder comparing to the evidence of __existence__), or hopefully someone else already did said research and more hopeful…

My idea is a little "!" which pops up on the comment byline if the comment fails an AI fact check. AI fact checks are obviously far from perfect, but at least it would be a start. @dang

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#190

Earlier quoted context omitted.

source? interesting if true.

Why would you doubt it? The brightest students of most nations are often sent abroad to enrich their countries with knowledge from the great universities. NK is almost unique in its inability to do this at non-Chinese great universities, so that is the only viable route.

I would doubt it because North Korea has extremely strict controls on who exits the country for any reason, but especially for education. I know this has happened before (for example Kim Jung Un studied in Switzerland under a false name when he was a kid), but it's extremely rare, and runs contrary to the North Korean philosphy of Juche, self-reliance.
Post reply on HN