Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

301–309 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#301

Earlier quoted context omitted.

Different species, you can't generalize like that. It's pretty unclear what actually happened with H1N1. Scientists were able to resurrect the more virulent strain in the lab two decades ago and it was just as potent in lab animals... Two possibilities are that it did in fact mutate to become "milder" or those strains were already circulating. Either way, H1N1 killed so quickly it ran out of victims and the highly le…

I was under the impression that it mostly killed by causing cytokine storms.

I won't claim to be an expert on 1918 influenza, but here's a reference for the claim I was making: https://pmc.ncbi.nlm.nih.gov/articles/PMC5481322/

After reading this, I am less sure of the claim "most", but it seems that opportunistic infection was an important factor. There were a few unpleasant ways to die...

Re: We identified a North Korean hacker who tried to get a job

#302
post #276

Earlier quoted context omitted.

Don't passkeys still have tons of vendor lock-in attached? A password I can put into any password manager I want and transfer it to a different password manager and neither the password manager company nor the company for which I made the account is any the wiser.

I was talking about a self-hosted OIDC provider to avoid a vendor lock in. You can transfer passkeys from vaultwarden to any other password managers

I could be wrong or misinformed, but I thought part of the passkey spec included some kind of remote attestation mechanism to facilitate vendor lock-in (ie Google could say its account passkey is only valid if stored in Chrome's password manager, to make up a silly example).

Re: We identified a North Korean hacker who tried to get a job

#304
post #151

Earlier quoted context omitted.

If your resume says you live in NYC for example, and I do something like "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" and they respond with I-278, that would raise red flags. I have never heard of anyone calling the I-278 anything but the BQE. It's just like the bar scene in Inglorious Bastards, with the fingers…

> "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" I lived in NYC for a year and I have no clue. My answer would be probably something along the line of "Haha! Yeah. Traffic is terrible in the city... or so do my friends with cars say. I for one take the subway everywhere, so no clue what you are talking about. But…

You would presumably be able to answer questions about the subway then.

Re: We identified a North Korean hacker who tried to get a job

#305

Earlier quoted context omitted.

> "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" I lived in NYC for a year and I have no clue. My answer would be probably something along the line of "Haha! Yeah. Traffic is terrible in the city... or so do my friends with cars say. I for one take the subway everywhere, so no clue what you are talking about. But…

You would presumably be able to answer questions about the subway then.

I could answer questions about the lines I used, yes. Doesn’t mean that I studied the subway maps.

But my point is that the “everyone in X calls Y Z” kind of trivia is not reliable way to say if someone is in X. For example because not everyone in X is native to X. Also because many would use the proper and official name of the landmark in an interview setting.

Re: We identified a North Korean hacker who tried to get a job

#306

Earlier quoted context omitted.

This is really not a constructive comment to make. This is going to ignite a flame war.

They're in control and responsible for their responses. Blaming someone else for one's anger or overreaction is indicative of abuse. "You made me lash out," is simply not a mature way to live one's life.

The moderators of hacker news expressly ask that people don't post like you just did.

Re: We identified a North Korean hacker who tried to get a job

#307

Earlier quoted context omitted.

Cryptocurrency is just a technology to give people the means to generate assets, and transfer them, themselves. Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. Regulation is just repression, rebranded.

I was with you until that final sentence. Regulation can be used for repression but it's also an essential part of any large scale real world system.

Why?

Re: We identified a North Korean hacker who tried to get a job

#308
post #59

Earlier quoted context omitted.

Not sure some rank and file 50ct army "hacker" wants to take the risk to insult their god-dictator.

If he's acting under NK command, this wouldn't be insulting, it's just doing a hacker's work. Besides, you cannot have it both ways: either North Korean hackers are a "50ct army" or they are a credible threat. Most seem to be arguing they are a credible threat. Also, he can always take the second option: "why are you asking about this in a job interview?", something many legitimate Korean candidates could ask.

> If he's acting under NK command, this wouldn't be insulting, it's just doing a hacker's work.

I understand where you are coming from, I wanted to express my idea that their person cult shaped culture might be so alien to us, that what seems obvious to us, might be a non-option to them. At least at the level where I imagine such operators.

> you cannot have it both ways: either North Korean hackers are a "50ct army" or they are a credible threat

I assume the people performing the en-masse long term infiltration are not the same with technical skills who the execute technical attacks.

Post reply on HN