North Korea’s Naenara Web Browser: Weirder Than We Thought (2015)
whitehatsec.com
whitehatsec.com
Did everyone else know about this? I didn't. Interesting. I stopped using Chrome and switched back to Firefox 3-4 years ago because Firefox got a better, and was slightly worried Google would eventually do stuff like that.
Now in general they don't even need it, other browser fingerprints are working pretty well:
Not saying they necessarily do that, but if they are indeed able to associate the "installation ID" to every request made with the browser, they have the information to do this, if they decide to do so.
On the other side, it is interesting how close they have made recent versions of Red Star OS to look like MacOS X. I guess they don't care a lot about copyright infringement. Which is possibly related to the fact that Kim Jong Un has had, at least in the past, access to an iMac [1].
[1] http://www.businessinsider.com/brand-new-photo-confirms-that...
[0] http://www.wipo.int/treaties/en/ShowResults.jsp?country_id=9...
The other thing I'm wondering, could they have been doing this to avoid outsiders to access their network? If we try to access 10.something it will try to reach an internal network and thus we won't be able to access their ips. If we somehow manage to send the request to 10.something over the network some node/server on the way will probably drop it.
There are ways to send such packets outside of your local network.
I don't think that's necessarily true, and it kinda seems like you're falling into the trap of believing your enemy to be a real-life cartoonish caricature.
North Korea is still a large nation, and while their resources are very limited, it's still a lot in absolute terms (as in, not compared to other nations).
Anyway, there is some evidence to the contrary of your assumptions: http://www.bbc.com/news/technology-32925503
On the contrary I think they're pretty normal and like anywhere IT gets no respect or resources
[1] http://www.websitepulse.com/help/testtools.china-test.html
(.00001% of the market)
Either way they'll probably run into issues down the road but I'm sure it's working just fine for them right now. Of course, my knowledge of how distributed their network infrastructure is across their country is lacking so maybe it does cause issues for them?
...
> Here’s where things start to go off the rails: what this means is that all of the DPRK’s national network is non-routable IP space. [emphasis mine]
That's quite an unsupported leap. He found some software that uses non-routable IPs, that doesn't mean the entire country's network only uses them.
The DPRK has exactly one known ISP (Star JV, AS131279) and (as far as I can tell from various looking glasses) they advertise exactly three /24s out of their 175.45.176.0/22 allocation, via exactly one Chinese transit provider (China169, AS4837 which is China Unicom's backbone).
We can also see from registries and generally poking around that 175.45.176/24 is used for authoritative nameservice (e.g. the DNS servers for .kp and reverse delegations for the Star JV /24s are here) and website hosting, which makes it very unlikely to be used for non-infrastructure host addresses. Being an old ISP lag I might also guess that there'll be an pair of NTP peers in there, an MTA, and separate source addresses for DNS resolvers (although I'd concede that with the DPRK no guess is reliable)
That leaves a total of 508 globally reachable IPv4 host addresses for the whole country. I suggest that this is insufficient even for the devices allocated to the relatively small group of individuals permitted to access the internet, from which it is not unreasonable to infer that everything else is in RFC1918 (or equivalent) space behind a proxy, which this article suggests is 10/8 or (my guess) most likely some structured sub-allocations thereof.
Here are a couple of pics I took of IP addresses printed on the walls in a school's computer lab:
Portal: http://i.imgur.com/MTYlNVo.jpg
Bookmarks: http://i.imgur.com/QWEooy5.jpg
For those intrigued as to what those addresses might've been, have a read of Bill Manning's roll up of the special case IP allocations: https://tools.ietf.org/html/draft-manning-dsua-08
North Korea's intranet has its own DNS system, and they also (contrary to the article) assign a bunch of IP blocks not in RFC 4192 internally.
People who do have access to the outside Internet do so through an HTTP or SOCKS proxy with login credentials.
Edit: it's also possible that people living in embassies in NK have consoles, but I have no idea how they get internet there, probably not through the national ISP.
maybe it a cry for help? Someone "accidentally" left a single https request there, hoping google will redirect North Korean requests to an open proxy allowing them full access to the Web.
I would be shocked if the DPRK is not doing this.
It's also a potential security issue since many of those certificate re-signing devices fail to verify the original certificates first, causing them to happily re-sign traffic that was already MITMed and erase all of the evidence.
In looking around at the certificates that they support, I was not surprised to find that they accepted no other certificates as valid – only their own. That means it would be trivial to man in the middle any outbound HTTPS connection, so even if they do allow outbound access to Google’s JSON location API it wouldn’t help, because the connection and contents can be monitored by them.
13. In looking around at the certificates that they support, I was not surprised to find that they accepted no other certificates as valid – only their own. That means it would be trivial to man in the middle any outbound HTTPS connection, so even if they do allow outbound access to Google’s JSON location API it wouldn’t help, because the connection and contents can be monitored by them. Likewise, no other governments can man in the middle any connections that the North Koreans have (I’m saying that with a bit of tongue in cheek, because of course they can according to Wikileaks docs, but this probably makes the DPRK feel better — and more importantly they probably don’t know how to do it in the same way as the NSA does, so they have to rely on draconian Internet breaking concepts like this).