Live data from Hacker News

N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

nytimes.com

31–40 of 159 posts

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#31
post #11

Earlier quoted context omitted.

I believe the reason this is "a big deal" is due to how the average US citizen reacted over the recent Sony Breach and the US Government's blame of NK (I might add with no supporting evidence, most industry professionals in high doubt, and even some security companies providing evidence to the contrary of statements by the government). The average US citizen was outraged that some other government would have the auda…

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying. - The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States. - The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communicat…

I hold Sony primarily responsible for the release of private data, due to their ignoring basic security practices. Why are health records stored on Sony Pictures servers along with everything else? Why were data silos and graduated access not in place? I never see any of these corporate officers held to account for their decisions to not spend resources for security. The only people I have any measure of sympathy for are the rank-and-file employees caught in the middle of decisions made by well-compensated executives who never have to face the consequences of their disregard for anything other than themselves and their own compensation.

I have to take issue with "norms" for intelligence services as well. These are groups with no morals or ethics, what makes you think they would ever adhere to any sort of "norm." These are criminals and criminals do not adhere to norms imposed from anyone other than themselves.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#32

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded. What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials. The document on Der Speigel speaks primarily about taking copies of intelligence from SK ha…

And another thing from Spiegel's article. NSA routinely attacks targets and then makes it look as if someone else did it: > But the loot isn't delivered directly to ROC's IP address. Rather, it is routed to a so-called Scapegoat Target. That means that stolen information could end up on someone else's servers, making it look as though they were the perpetrators. So how do we really know it was North Korea, and not ju…

We can't really know. There is no way to be perfectly certain.

That said one can apply an Occam's calculus using whatever information and reasoning you do trust. I personally trust that, whomever the #GOP was, they were motivated by SONY's role in developing "the movie of terrorism". This seems to me to be consistent with what the group published and with their 'Christmas surprise' showing collaboration between the State Department and SONY on the development of the movie related to its diplomatic value - something I don't think the NSA or allies would do. So I think the group had NK sympathies in mind. Granted, this doesn't rule out attribution to other states or hacktivists who hold these sympathies.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#33

Earlier quoted context omitted.

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying. - The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States. - The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communicat…

I hold Sony primarily responsible for the release of private data, due to their ignoring basic security practices. Why are health records stored on Sony Pictures servers along with everything else? Why were data silos and graduated access not in place? I never see any of these corporate officers held to account for their decisions to not spend resources for security. The only people I have any measure of sympathy for…

I seem to be in the minority on Hacker News, but as someone in the professional computer security field I know that any company or state/department/organization can be hacked by a motivated attacker. In the case of SONY, the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent. The malware similarly could not have been detected, as signatures for this specific compilation were not known.

I have a hard time blaming the victim of a cyber attack that would have been practically impossible to prevent. I agree that SONY made bad decisions with regard to its hording of unnecessary data, but also recognize that this is hardly unique to SONY and not standard advice given by security professionals (it should be).

Norms are important so that you can accuse 'groups with no morals or ethics' of doing something wrong. Norms may only discourage and not prevent behavior but without norms its difficult to find common ground for behavior that may otherwise be chalked up to 'culture' or 'tradition' or 'nature'.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#34

Typical for the NYT to bury the strong countervailing evidence against the official war-mongering story in a couple of paragraphs 2/3rds of the way through the article. Still, the sophistication of the Sony hack was such that many experts say they are skeptical that North Korea was the culprit, or the lone culprit. They have suggested it was an insider, a disgruntled Sony ex-employee or an outside group cleverly mimi…

Typical for Hacker News posters (in general) to dislike the United States government so much that, despite having complained and worried and speculated about the sophistication of the NSA's online snooping for the last year in a half, they assume that the government couldn't possibly have obtained any evidence they didn't want to release to the public, instead trusting the high certainty of experts who have decided that it couldn't have been North Korea because the Korean region setting is for the South Korean dialect or the writing didn't have the right 'Korglish' errors or other such trivialities (those are both actual points that have been made).

It's not as if the claims in this article that the U.S. has successfully penetrated North Korean networks (to the extent they exist, anyway) should be any surprise; it would be highly surprising if they hadn't. One might imagine that while the North Koreans are not super advanced, they know enough about how to analyze and remove malware that it might be better to stay vague, even at the cost of appearing less credible, rather than disclose specifics of what communications you're able to intercept. Yet surely, just because the finger is pointing at one of the usual enemies, it must just be warmongering rather than reflecting reality.

(Yes, yes, WMDs in Iraq. It is certainly possible that the U.S. really is that incompetent and/or hawkish. I just don't think it's very likely.)

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#35

Earlier quoted context omitted.

I hold Sony primarily responsible for the release of private data, due to their ignoring basic security practices. Why are health records stored on Sony Pictures servers along with everything else? Why were data silos and graduated access not in place? I never see any of these corporate officers held to account for their decisions to not spend resources for security. The only people I have any measure of sympathy for…

I seem to be in the minority on Hacker News, but as someone in the professional computer security field I know that any company or state/department/organization can be hacked by a motivated attacker. In the case of SONY, the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent. The malware similarly could not have been detecte…

> but as someone in the professional computer security field I know that any company or state/department/organization can be hacked by a motivated attacker.

You seem to give Sony too much credit, and also forget that they had a file server with open internal access which had a directory called "Passwords" which contained a plain text file with all the credentials to their internal servers.

That's something I'd expect to see at some small business with no professional IT on staff... certainly not from a multi-billion dollar company with thousands of employees and a full-time professional IT staff.

Sure, the attackers may very well have spearphised their way inside, but once inside, they didn't have to go through any of the normal hassles of island-hopping with more exploits, etc. They just logged in like they belonged.

Motivated attacker or script-kiddy, once inside, Sony made it awfully easy.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#36

Typical for the NYT to bury the strong countervailing evidence against the official war-mongering story in a couple of paragraphs 2/3rds of the way through the article. Still, the sophistication of the Sony hack was such that many experts say they are skeptical that North Korea was the culprit, or the lone culprit. They have suggested it was an insider, a disgruntled Sony ex-employee or an outside group cleverly mimi…

The sophistication of the attack is pretty questionable IMO. The malware used can be purchased by anyone on the black market and had been used before by Iranian hackers in 2012. Furthermore, spearphishing emails were used to get inside the network. Furthermore, how would sophistication be evidence against a State actor with (a reported) 7,000 personnel?

When I hear "sophisticated" in the context of a breach, I think "we weren't paying attention"

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#37

Earlier quoted context omitted.

I hold Sony primarily responsible for the release of private data, due to their ignoring basic security practices. Why are health records stored on Sony Pictures servers along with everything else? Why were data silos and graduated access not in place? I never see any of these corporate officers held to account for their decisions to not spend resources for security. The only people I have any measure of sympathy for…

I seem to be in the minority on Hacker News, but as someone in the professional computer security field I know that any company or state/department/organization can be hacked by a motivated attacker. In the case of SONY, the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent. The malware similarly could not have been detecte…

> In the case of SONY, the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent.

Investment can make spearphishing much harder. Defense is not always absolute, but about raising the cost for the attacker.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#38

Earlier quoted context omitted.

To be fair, there were other issues involved in the Sony hack that are not present in NSA spying. - The North Koreans attempted to impose a heckler's veto on speech by private citizens of the United States. - The Sony hack had direct and very visible consequences for Americans (economic consequences, release of personal data like salaries and health information, embarrassment of people by releasing private communicat…

I hold Sony primarily responsible for the release of private data, due to their ignoring basic security practices. Why are health records stored on Sony Pictures servers along with everything else? Why were data silos and graduated access not in place? I never see any of these corporate officers held to account for their decisions to not spend resources for security. The only people I have any measure of sympathy for…

I agree about lack of basic security, and that's the reason we have security compliance programs. Security Awareness Training, classification of health records as sensitive, and properly segmenting those sensitive health records from the rest of the environment are all appropriate controls that security compliance prescribes. It took me 6 months to decipher PCI and 3 months to implement. To others, compliance may seem like a joke, but I felt very confident that at least I had done 100% my due diligence in protecting our customers and employees. I think that's all they can ask and all we can give, 100% honest due diligence.

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#39

Earlier quoted context omitted.

I hold Sony primarily responsible for the release of private data, due to their ignoring basic security practices. Why are health records stored on Sony Pictures servers along with everything else? Why were data silos and graduated access not in place? I never see any of these corporate officers held to account for their decisions to not spend resources for security. The only people I have any measure of sympathy for…

I seem to be in the minority on Hacker News, but as someone in the professional computer security field I know that any company or state/department/organization can be hacked by a motivated attacker. In the case of SONY, the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent. The malware similarly could not have been detecte…

> the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent

I'd challenge that assertion. Employee's are often the first line of defense for any company, be it seeing something suspicious or knowing when to alert the right people. Investing in phising attack training can be very worth-while. Or at least adopt a strict company policy that helps ward off the basic forms of this attack.

It's not uncommon to have a company-wide policy that users are not allowed to open attachments in any email from anyone without IT's approval. It's inconvenient, sure, but it protects against multiple email-based attacks (everything from simple viruses to more advanced phishing attacks).

There's even phishing attack training specifically targeted at large enterprise (they send phishing attack emails to your targeted employees and when they fall for it, they get a quick lesson and explanation). [1]

[1] http://threatsim.com/how-it-works/

Re: N.S.A. Tapped into North Korean Networks Before Sony Attack, Officials Say

#40
post #4

If that's true, who's to say our guys didn't launch the attack from their computers? Why would they even admit to being in there? The NSA doesn't say anything unless 1) they have to, or 2) they want to. I don't see why they would make this claim.

Certainly false flag operations are a tactic that has seen reliable and regular use, especially in counterintelligence. But what purpose exactly would a false flag operation against SONY serve? Definitely not as a pretext to take action against North Korea - the US could much more easily justify actions against NK than it has many other nations in its history.

I think the recent re-introduction of CISPA and calls by world leaders to end encryption hint at the qui bono.
Post reply on HN