Live data from Hacker News

Countering threats from North Korea

blog.google

81–90 of 172 posts

Re: Countering threats from North Korea

#82

Earlier quoted context omitted.

I'm actually surprised Google would say this is from the DPRK government without also saying it had has been verified by US federal government authorities. Usually they leave it for others to deal with statements at that level.

I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years. (Disclaimer: I am head of TAG)

How do you know what country is actually behind any of this? I’d imagine that would be very difficult given nation states can host content anywhere in the world and will want to make it look like it’s coming from elsewhere.

Re: Countering threats from North Korea

#83

Earlier quoted context omitted.

I too saw one of these. Very odd since I was expecting a note about a job.

Don’t reply to those SMS. Your geolocation can be derived from your reply, even a STOP or UNSUBSCRIBE reply.

Can you explain how this works if you don't click any links?

Re: Countering threats from North Korea

#85

Earlier quoted context omitted.

Web assembly is extra code and complexity in a web browser compared to one without, so there are more potential vulnerabilities

I don't buy it because you can apply same reasoning to every new / changed line of code, yet it ain't always true The question is, is WASM's security model / sandbox "safer" / "easier to actually execute" than JS'?

WASM _IS_ JS. Some browsers do things to make it run faster. JS runs in its own security sandbox and is already suppose to be safe. Browsers get exploited in all kinds of ways, and IIRC, there have been WASM-specific exploits as well in the past.

Your question is non-sensical as is. I think you need to expand it to have people be less confused as to what you’re asking.

Re: Countering threats from North Korea

#86

Earlier quoted context omitted.

I too saw one of these. Very odd since I was expecting a note about a job.

Don’t reply to those SMS. Your geolocation can be derived from your reply, even a STOP or UNSUBSCRIBE reply.

Yes, would like to learn more as well.

Re: Countering threats from North Korea

#88
post #58
post #6

What evidence do they have that suggests these threats are coming from North Korea?

> These groups' activity has been publicly tracked as Operation Dream Job and Operation AppleJeus. Following those links yield these two documents, which both have "Attribution" sections. Presumably some of these tell-tale signs were identified in the ongoing exploitation. https://www.clearskysec.com/wp-content/uploads/2020/08/Dream... https://securelist.com/operation-applejeus/87553/#attributio...

I'm very curious how we can attribute a threat to a particular nation state, given pretty much anything in code/IP/modus operandi/etc. can be faked by one party to look like another. I went through both links and all I found was a lot of hand-wavings like

> One of the top identifiers of Lazarus is their dual attack mission – money theft and espionage. This modus operandi is unique to North Korea, as other state actors usually focus on espionage only. North Korean money theft operations are carried out in service of the government, as a way of funding the nuclear program

Like, seriously? "You not only do espionage but also steal money, therefore you're NK"?

Post reply on HN