Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

211–220 of 302 posts

Re: North Korean campaign targeting security researchers

#211

Earlier quoted context omitted.

"All of our secret agents are loyal patriots, while all of theirs are brainwashed hostages!" The reality is that like every other country's intelligence services, they would obviously recruit for patriotism. This question is like asking why US intelligence agents who have access to information about the DPRK beyond the propaganda don't defect to the DPRK's superior healthcare coverage, zero school shootings, and bett…

Yeah — other than the famines, forced labor, summary executions, and mandatory dictator cult it’s probably a great place.

It's not that it's a great place, it's that an individual who is deep into the indoctrination (from a lifetime of exposure) might not be as aware of the realities of their world vs the outside world, even with Internet access.

Re: North Korean campaign targeting security researchers

#212
post #194

Earlier quoted context omitted.

Could you please expand on your iMessage comparison? I don't understand what you're referencing.

I don’t know if I 100% follow or agree with the comparison of iMessage and GitHub actions. But iMessage has had a number of interesting security vulnerabilities over the years in image parsing and deserialization. One example: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i... Or a story from today: https://news.ycombinator.com/item?id=37425007 So perhaps the similarity between iMessage and GutHub action…

And yet Android had multiple high and critical CVE's reported in the last few days with little coverage:

https://source.android.com/docs/security/bulletin/2023-09-01

Re: North Korean campaign targeting security researchers

#213

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

I don't think there are many options here: - They can't get to X freer country as that's just difficult for all North Koreans - They likely can't just stop hacking for carrot and/or stick reasons. They are likely closely monitored. - Maybe some people drink the kool-aid. I'm sure these people are very well compensated.

They are likely closely monitored

Imagine getting a week of solitary confinement for trying to read a Korea Times article.

https://m.koreatimes.co.kr/pages/article.asp?newsIdx=358723

Re: North Korean campaign targeting security researchers

#214

Earlier quoted context omitted.

I don't think there are many options here: - They can't get to X freer country as that's just difficult for all North Koreans - They likely can't just stop hacking for carrot and/or stick reasons. They are likely closely monitored. - Maybe some people drink the kool-aid. I'm sure these people are very well compensated.

They are likely closely monitored Imagine getting a week of solitary confinement for trying to read a Korea Times article. https://m.koreatimes.co.kr/pages/article.asp?newsIdx=358723

Also pay the writers, I need another season of severance :'(

Re: North Korean campaign targeting security researchers

#215
post #90

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

This also serves as a reminder that code hosted on github might be malicious and we shouldn't blindly trust those just because the author seems to have similar interests.. I've done that multiple times :(

We have pretty high bars for what we allow in terms of outside dependencies, but that doesn’t mean they do. It’s basically a crap shoot if you choose to do open source at all.

Re: North Korean campaign targeting security researchers

#216

Earlier quoted context omitted.

"All of our secret agents are loyal patriots, while all of theirs are brainwashed hostages!" The reality is that like every other country's intelligence services, they would obviously recruit for patriotism. This question is like asking why US intelligence agents who have access to information about the DPRK beyond the propaganda don't defect to the DPRK's superior healthcare coverage, zero school shootings, and bett…

Yeah — other than the famines, forced labor, summary executions, and mandatory dictator cult it’s probably a great place.

If you're a member of an elite cyber-intelligence military branch who knows, it might not be as bad.

The USA is also great if you earn 200k/y as a software developer.

If you're a teacher, not so much.

Re: North Korean campaign targeting security researchers

#217

Earlier quoted context omitted.

Life is probably not bad in North Korea, than the propaganda lead you to believe. Especially if you remain loyal and are a valuable asset.

> Life is probably not bad in North Korea, than the propaganda lead you to believe. If this were the case then it would not be necessary for them to shoot people trying to leave.

The East Germans did that, too

Re: North Korean campaign targeting security researchers

#218
But the tool also has the ability to download and execute arbitrary code from an attacker-controlled domain.

Also known as "automatic updates". Thank you, Big Tech, for indoctrinating the mainstream population into accepting this subservience (or forcing this non-choice on them) --- and now that that subservient and trusting attitude includes security researchers too, it's ironic to see it coming back to bite you.

Some of us knew all along what that attitude was going to lead to, and probably not all of us are security researchers either --- we've just seen all the other negative effects of letting you push stuff to our machines and run it, and put two and two together.

Re: North Korean campaign targeting security researchers

#219
post #133

Earlier quoted context omitted.

Security researchers generally have more 0 days.

Also being a security researcher doesn't necessarily mean you're any good at securing your own systems. If you can breakout of the quarantine area of the things the researchers know not to trust, you'll commonly find their own systems are insecure as hell.

Yes exactly. The fun bit is breaking stuff, securing stuff is soooo boring.

There are different mindsets in this game. You want one type of person to find the holes in your system, and a different type of person to protect it.

Re: North Korean campaign targeting security researchers

#220
post #195

Earlier quoted context omitted.

I mean, the response here was a blog post, which doesn't feel particularly upplayed. I also virtually never hear about NK from anyone or fear of NK from anyone day to day, nor do I hear about it particularly often from policy makers. No one is campaigning on fear of NK that I have seen. Perhaps TN is just a radically different world, I'd frankly believe it, but I haven't seen anything too significant at all. The last…

> I mean, the response here was a blog post, which doesn't feel particularly upplayed. I wasn't criticizing the blog post, I was responding to a comment in this thread that claimed that for some strange reason the danger of NK is systemically underplayed by the media. I argue that no, the media more typically overplays it, much like it overplays the threat from other non-peer nations. I'm assuming you don't feel like…

Can you give an example of media overplaying NK?
Post reply on HN