Live data from Hacker News

Countering threats from North Korea

blog.google

41–50 of 172 posts

Re: Countering threats from North Korea

#42
post #41

I am so fucking done with the internet turning into a trash pile of scams and exploits.

Who is even routing with North Korea? Seeing how the normal populace there literally doesn't have access to the internet, what on earth is there to be gained?

You know who.

Re: Countering threats from North Korea

#43
post #41

I am so fucking done with the internet turning into a trash pile of scams and exploits.

Who is even routing with North Korea? Seeing how the normal populace there literally doesn't have access to the internet, what on earth is there to be gained?

Hong Kong and Russia:

https://bgpview.io/asn/131279#peers-v4

http://cooks.org.kp/en/ is hosted on that network.

Re: Countering threats from North Korea

#44

Earlier quoted context omitted.

Countries have been doing terrible things to people since long before the internet

True but before the internet it was limited to the locality. The internet feels like a public park that gets trashed by folks all across the world and not just by the neighbors. (Just to be clear, I sympathize with your point as well)

[deleted]

Re: Countering threats from North Korea

#45
Google itself is gathering people's personal data and uses fingerprinting methods to track them. This is done on billions of people, and not even limited to their actual logged in users! It would be nice if governments put an end to Google's invasion of people's privacy. It is much more important than some failed attacks.

Re: Countering threats from North Korea

#46

Earlier quoted context omitted.

A statement from Google.

I'm actually surprised Google would say this is from the DPRK government without also saying it had has been verified by US federal government authorities. Usually they leave it for others to deal with statements at that level.

I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years.

(Disclaimer: I am head of TAG)

Re: Countering threats from North Korea

#47

Couldn't they just hardware mitm the CPU and Ram, not to be prisoner of AES. This way they can dump stages as well.

Sure, but that requires having a fully instrumented host get attacked. If all you have is a few reports of compromised machines, it's much harder to work backwards to the exploit. The attacker will switch things around before phishing again, etc...

Honeypots are harder than they look, basically.

Re: Countering threats from North Korea

#48

Quoted post unavailable.

In this case we only obtained a Chrome exploit.

Whether that means they didn’t have exploits for other platforms as part of this attack or that we just didn’t succeed in determining them is unknown.

TAG has certainly found and reported exploits in other platforms many times so it is not a matter of not caring.

Source: I am lead of TAG at Google

Re: Countering threats from North Korea

#49

Earlier quoted context omitted.

A statement from Google.

And even when knowing how a country or particular state-backing is identified, there is nothing preventing other hackers from adding the same markers to their own software

NK hackers are kwnon for adding false flags

Re: Countering threats from North Korea

#50
post #4

Earlier quoted context omitted.

We see some of this with just normal spear phishing against companies. The "single click" thing is reasonably common, it makes things a bit harder to catch as often the clickthrough will change to whatever is being spoofed in the first place. A homophone ycornbinator.com would serve the malware first time, then next time it would send a permanent redirect. Unique IDs you'll see in things like spam SMS, both to work a…

I am receiving increased SMS spam past week. Is connected to this exploit? Msgs are all different domains with unique ID appended.

Probably not. No signs that this is linked to any mass activity.
Post reply on HN