Live data from Hacker News

RedStar OS 3.0: Remote Arbitrary Command Injection

myhackerhouse.com

21–23 of 23 posts

Re: RedStar OS 3.0: Remote Arbitrary Command Injection

#21
post #3

What interests me is does they respect licenses of the open source stuff they use?

The DPRK does not respect the GPL, unsurprisingly.

Though they are a party to the Berne Convention, so they ought to.

Re: RedStar OS 3.0: Remote Arbitrary Command Injection

#22
post #19
post #11

Considering the source (of the OS, that is), it begs the question whether these bugs are accidental or deliberate. Or, put another way - would using a fully patched and hardened Linux distro of some denomination or the other warrant a visit from the secret police, suggesting you revert to using Red Star for -ahem- patriotic and surveillance purposes?

Almost certainly accidental. Consider the population of NK (not large — 24 million). Now consider that it's a closed society; access to foreign media and learning materials is going to be restricted. Now on top of that, consider that learning to program requires (a) learning an enemy language (danger! spy/defector warning klaxon!) and then access to lots of presumed-subversive foreign tracts that are sufficiently abs…

This. They're worried that if they let their dev's google everything their devs will defect.

Re: RedStar OS 3.0: Remote Arbitrary Command Injection

#23
post #3

What interests me is does they respect licenses of the open source stuff they use?

No, it's all closed source. The binaries aren't publicly distributed either, they seem to be the result of leaks.

GPL'ed code is probably legal in this case, because they don't distribute publicly. It would be a decently easy case to make in an international IP court that distribution within North Korea is not a public release. However, if a North Korean citizen demanded the source code for Red Star, they may be obligated to provide it, lest they are in violation of the GPL.
Post reply on HN