The Rise of North Korea's Hacking Army
newyorker.com
newyorker.com
For ~$1M you can successfully attack and completely compromise essentially any Fortune 500 company in the world.
For ~$1M you could target the current model year of any brand of car in the world and develop a remote attack to simultaneously target every car of that model year at rush-hour and engage the cruise control at maximum speed, engage the anti-lock braking to disable the brakes, and, if applicable, engage the autosteer to turn slightly into oncoming traffic as these researchers [1] demonstrated could be done 5 years ago on a budget of only $80k.
For ~$1M-10M you could likely target the most popular types of generators used in a power grid and at the very least deactivate if not disable their software governors and over-rev them to destroy them as demonstrated by the DoD 14 years ago [2] and as militarily deployed by Russia against Ukraine [3] which could result in the loss of power for months if sufficiently widespread.
At the very least our internet-connected stoves with remote turn-on [4] are safe since, as we all know, the software developers for stoves are the best minds of our generation so it would cost far more than the ~$1M to hack a Fortune 500 company to remotely turn on the gas at 2 AM in the morning and then the igniter at 3 AM with results like this: WARNING [5][6].
For less than the price of a tank any government can develop a weapons system that is comparable in power to a full scale nuclear first strike that you can deploy instantly in your enemy's territory. Not just that it can be tuned to any scale of destruction you want from an individual all the way up to full scale nuclear strike, and it can be done untraceably or, even better, you can pin it on one of your other enemies as the CIA had the capability to do [7]. Frankly, any government not feverishly developing such weapons systems given that they only cost a few measly million to develop for the immense capabilities they provide is either ignorant or fighting the last war. This is The Tool that a small nation can use to achieve parity with superpowers given their miniscule cost and immense leverage.
[1] https://www.wired.com/2016/08/jeep-hackers-return-high-speed...
[2] https://www.youtube.com/watch?v=7GSEchbDuB8
[3] https://en.wikipedia.org/wiki/December_2015_Ukraine_power_gr...
[4] https://www.geappliances.com/ge/connected-appliances/ranges-...
[5] https://www.youtube.com/watch?v=a2JPLMzQjkk
I do believe that you might be making a bit of hyperbole with the scale of possible terror potentially possible for such small amounts of money. Some crazy mofo should have done this by now. You're telling me that ted kaczynski types don't exist for hacking?
The capability to engage in a large scale cyber-physical attack is maybe 10-15 years old. Not even a generation has passed since it became technologically feasible. To put that into perspective, Ted Kaczynski started his attacks when he was 36. If at the very moment that it became possible an 18 year old "crazy mofo" also figured that out they would still not be as old as Ted Kaczynski was when he started.
You'd expect state actors to use these attacks to achieve a particular goal, where the cyber attack option is weighed against the cruise missile option. Permanently destroying a power grid doesn't make a ton of sense for any reasonable objective other than total war.
Also, considering the destructive potential of those cyber weapons, are there any international laws surrounding the usage of them against civilian targets?
Employ on site Red and Blue teams or pay externals for regular penetration tests and security audits that feed back results to your site/infra/dev-ops teams.
None of this is new but most businesses ignore them since it's seen as an expensive snake oil and most importantly, "it's never gonna happen to me".
Or they see that multiple Fortune 500 companies were affected by breaches and all of them are doing fine. So attitude can be - "it's inevitable, but we'll be OK anyway"
That usually comes down to - who are your adversaries? Parent implies that given enough money, high value targets can be compromised for less money than conventional military arsenal.
For an average individual, small company dealing with non-sensitive data - preventing non-targeted attacks is likely high priority e.g. Preventing your applications, data from getting compromised because its vulnerability was detected in the random scan of the attacker (or) your staff plugged in a flash drive with ransomware.
Some simple non-exhaustive preventive measures are - Operational Security(Training staffs to not click unwanted links, social engineering attacks(not to reveal too much about their work online, Better identity management etc.) Application Security(Ensuring security focused application development, keeping up-to date with the patches for libraries etc.), Collecting less customer data as possible(Ensuring customer privacy).
Without that info, I think one of the only universal recommendations (whether you’re a trillion dollar FAANG or 2 person startup) is buy U2F keys for everyone* and enable them everywhere. Also try to know what assets you have, and patch everything regularly.
* yubico make great U2F keys which I recommend. Others such as google also make keys
Never browse the web, read e-mail or otherwise run any Internet client from any machine with data on it and instead use a separate machine or if unavoidable a VM on top of a reasonably secure hypervisor to run the browser.
Secure every single systems assuming that the network is compromised.
Restrict access data to only those who need it.
Avoid software written in C/C++ for anything security critical at all costs unless there is no alternative.
Only hire competent programmers and sysadmins.
Invest in proper physical security.
Basically, each component in your threat model should have no less than two controls to protect it. Assume that 'active' systems (antivirus etc) can and will fail. Passive measures are predictable and cost effective, but have limitations - a mixture of both is ideal.
Think of it like a well fortified house. You don't just stick a robotic machine gun on the roof and command it to shoot people it doesn't recognize - everybody knows from intuition that's a bad idea. Instead, you layer up your defences. Passive measures are a great start: a steel door, bars in the windows, bollards to keep vehicles away, etc. Then you layer active measures: lights and cameras, sensors in windows and doors, keycard access to different areas, etc. Anything more than that you need to develop your threat model; are you defending against bears or against a helicopter gunship? A moat won't protect you from a chopper, and radar guided anti-aircraft missiles won't be very effective against bears.
To evaluate the quality of your security, you should hire a red team, a team that emulates an attacker, to attempt to breach your security. If they are able to breach your systems then the key takeaway is that your security process is systemically incapable of defending against attackers with that level of budget and resources which is supported by the empirical evidence that a team with that level of budget and resources did, in fact, breach your systems. This is in contrast to the standard takeaway which is to just fix the specific defects discovered since obviously the only defects that exist are specifically in the areas that were probed. To actually remediate the problem you need a systemic overhaul otherwise you will just keep getting the same quality of output that is equally defective.
Unfortunately, the prevailing state of cybersecurity has no functional solutions to these problems once you get to attackers with a few million dollars outside of the heavy-handed and highly inconvenient solution of disconnection. For systems with safety standards, that is a cost that should be paid. For any other system, you need to evaluate if disconnection is worth it in the context that there is a 100% chance that anybody with a few million dollars can successfully completely compromise your systems. If you only consider direct harms such as monetary damages, disruption of business, stock price changes, it is highly unlikely to be worth it compared to getting insurance at this time as most attacks that do direct harm are still being done by financially unsophisticated attackers who are still underutilizing their blackmail potential by at least 10-100x, so it is almost always financially prudent to just eat the cost. As for indirect effects, it is up to you to consider if IP loss, reputation loss, leakage of confidential information, etc. at the cost of a few million dollars is worse than the negative effects of disconnecting.
Hopefully, the same thing also applies to cyberspace.
On other hand, you have much more countries constantly exerting overt aggression despite retaliation by Western countries being quite possible... but never coming for all reasons from co-opted politicians, and insiders, to power of their public image, to plain cowardice.
Further, none of these things would cause an enemy to capitulate. If an enemy shut off power or caused car crashes in several major cities at once, the US isn't going to just surrender or even think about it. They're going to strike back with the widest array of options for employing force that earth has ever seen. Every option you listed would be pin pricking a giant.
Cyber warfare is super cheap, but it's also orders of magnitude less effective than sustained aerial bombardment or a complete naval blockade. Another tool in the tool chest, but not something I would base my national defense on
https://en.wikipedia.org/wiki/Bombardment_of_Ellwood https://en.wikipedia.org/wiki/Fu-Go_balloon_bomb https://en.wikipedia.org/wiki/Attack_on_Orleans
Not that they were huge casualty incidents, just amazing that most people believe the myth even today.
https://en.m.wikipedia.org/wiki/American_Theater_(World_War_...
The British aisles hadn't seen war since the 1700s prior to WW1. Neither German strategic bombing in WW1 nor the much larger blitz in WW2 brought about surrender or capitulation.
With regards to potential impact, I'm afraid it's a little more serious than smart lights changing colour. One could disable power-plants, steal money, vandalize factories. I saw a DefCon talk where the guy stumbled onto a totally open control panel for a waste-water treatment plant.
With a little creativity and co-ordination, this can be a very effective form of war. See also the Israeli's (or someone) disrupting Iran's nuclear ambitions.
If it were that easy, why hasn't a hack happened with a massive loss of life yet? Most big breaches involve credit card numbers or other personal info.
In any case, my dad called for a meeting of the church leadership and put a stop to it, but that was a big WTF moment. Is sending computer equipment and/or teaching North Koreans computer skills even legal from the US standpoint? I don't remember if said missionary was an American citizen or a South Korean one.
The same goes for a lot of aid that gets sent there. That people are suffering there is tragic, but it is so easy for aid to be diverted to primarily benefit the Kim dynasty and its closest circles while the majority of the country doesn't reap the benefits.
https://www.reuters.com/article/us-northkorea-missiles-china...
A) Even seemingly harmless tools can be turned into dangerous weapons and they've done so before, so the best course of action is to not support them at all because they'll just turn around and try to hurt us.
B) Even seemingly harmless tools can be turned into dangerous weapons so there's no point in obsessing whether what we give them could be used for nefarious purposes as they'll just come up with a way to hurt us if they want to anyway.
If NK wants to raise a hacker army, I don't think the existence of some used computers donated by American churches would make a meaningful difference.
* That said, we also have to consider the danger of the US government deciding the donation is illegal, so ... (shrug)
You had mainly paper documentation. With 10 or so of the best tech manuals to read, and a bunch of old machines to network together, and a few CDs of useful software, the right person could easily become highly skilled.
And by definition hacking means working out things that aren't already known (by many at least) so the absence of say stackoverflow and the other joys of the internet wouldn't slow those guys down either.
It was hugely influential in my development. I drew things, animated things, made music, wrote school papers and a neighborhood newsletter, made videos with wipes and title cards, wrote my first resume (at 15, hah), and of course played some games.
I give a tremendous amount of credit to having that in the home for my current computer literacy and career path.
I mean, computers have accelerated nearly every single industrial process they touched by few orders of magnitude, long before internet was a thing. They will be used exactly for the same purpose in NK still - operating machinery, operating poing of sale systems, keeping inventory, teaching.....also NK has intranet network, while the knowledge about it is limited, it's basically a very restricted and heavily filtered version of internet available to North Koreans.
There are accounts from people who have even tought computer science in NK:
https://www.vice.com/en/article/z4m8qx/how-to-teach-computer...
And general reports on what they use:
https://www.businessinsider.com/what-using-a-computer-in-nor...
So yeah, there are absolutely computer jobs in the country.
Outside Internet is available to the elites.
And yes, they have zero impediment smuggling just anything through China. Anecdotes tell of latest RolceRoyces on streets of Pyongyang.
In other words, any modern country?
Drives should be zeroed before getting sent off anyways.
https://en.wikipedia.org/wiki/Pyongyang_University_of_Scienc...
So...it was a hex dump?
(It certainly reads that way)
00000000 54 68 65 20 71 75 69 63 6b 20 62 72 6f 77 6e 20 |The quick brown |
00000010 66 6f 78 20 6a 75 6d 70 73 20 6f 76 65 72 20 74 |fox jumps over t|
00000020 68 65 20 6c 61 7a 79 20 64 6f 67 |he lazy dog|
This is also a common default format for many hex editors.The visual representation columns--which display all isgraph(3) ASCII values as their ASCII character, and every other 8-bit value as "."--could be interpreted by lay readers as a margin that decodes the octal and hexadecimal values which take up the 4/5ths of the 78-column display.
"The process by which North Korean hackers are spotted and trained appears to be similar to the way Olympians were once cultivated in the former Soviet bloc. Martyn Williams, a fellow at the Stimson Center think tank who studies North Korea, explained that, whereas conventional warfare requires the expensive and onerous development of weaponry, a hacking program needs only intelligent people. And North Korea, despite lacking many other resources, “is not short of human capital."
https://www.theguardian.com/world/2015/oct/13/why-do-north-k...
https://www.pri.org/stories/2015-01-22/problem-north-korea-s...
Does their posting content on Youtube make them less credible?
Judge the originator of the content, not who hosts it.
Might as well go "Ah yes, the internet. A trusted source of information."
That's how shallow your retort is.
However, SK is a free capitalist country, and NK defectors need to eat, so some of them find gainful jobs telling conservative pundits what they want to hear.
Of course there's no doubt that NK is a horrible, horrible place, but still, sometimes you have to take some of these viewpoints with a grain of salt.
Defectors in South Korea are by law not allowed to talk positive about North Korea.
If you isolate a country economically by cutting off all legal ways for it to trade with the international community, it will have to rely on illegal ways.
Generalized trade sanctions have time and again proven to be ineffective because they are so indiscriminate. They're meant to work as a deterrent, not a punishment. But the deterrent works with the threat of disrupting the economy, which only works short-term as the existing supply chains come to a halt and businesses panic. If you sit the sanctions out long enough, the economy will have already collapsed and will rebuild itself under the new restrictions. Once the economy has adapted, the sanctions are no longer a deterrent, they're just how things are, and the promise of conditionally lifting the sanctions feels like a trap because it would require changes to the economy that would again make it vulnerable to those sanctions if they were reinstated.
I really can’t imagine how bitter that would make me feel.
They're not crooks from their perspective. They're indoctrinated into hating the west, remember. As far as they're concerned they're likely to feel they're serving their nation and doing a good deed.
He was an American cryptographer who took a very public stance against the Vietnam War. Being forced to leave, he went and set up the world's most successful hedge fund, became a billionaire and led the nerdification of trading.
There are lots of really really interesting interviews with him on YouTube.
Or did you think the US doesn't do propaganda?
If you compare it to what many intelligent individuals wind up getting stuck doing in other developing countries it's a pretty awesome opportunity.
> I really can’t imagine how bitter that would make me feel.
That's how I feel about smart CS kids getting duped into working for the CIA or NSA, but I have less sympathy with those because they're coerced with cozy paychecks rather than the implied threat of literally being dragged in at gunpoint.
What's wrong with that? Would it be better if they were harvested by corporations to just make far more questionable things?
You could equally well frame it as "they are given a chance to do their patriotic duty", "they serve their country", "they are given an amazing job opportunity". Your wording isn't wrong, but it is an unusually harsh way to describe a military operation.
[1] -https://www.newyorker.com/magazine/2020/11/23/the-undergroun...
"The coding and the analytical skills on display at such events were like the Force in the “Star Wars” movies: it could be used for the light side, or for the dark."
"He spoke about the Stuxnet code in the way that an art historian might discuss “The Night Watch”: it was “elegant,” “precise,” “sophisticated.”"
"The malware consisted of rows of seemingly random letters and numbers flowing down a page, in pairs. In the margins were some recognizable English-language words—“Windows,” “everyone”—connected by cryptic punctuation. Choi could fluently and sensitively parse all this."
>Those people are pawns though, not curious hackers
Anyone using the site for their government or private job would be then. Practicing for your employment does not mean you don't like your job.
Or are you just in favor of collective punishment against North Koreans, individual actions are irrelevant?
I am not speaking in terms of a personal attack against oppressed North Koreans, and it's confusing that you appear to persist in turning this discussion into that.
I want hackers to learn more, I am not personally responsible for whether or not it is legal for a North Korean citizen to use a service offered by a US entity, and I do not have a strong opinion about whether it's OK to regulate that, it's not my speciality.
I was sharing an observation: people from North Korea are training their hacking skills using Hacker Rank. NK internet is strongly regulated, so those people must be using it for state sponsored purposes. Current trends for computing expertise in North Korea have been towards malicious acts by the government (not pointing fingers at individuals, I hope some of these NK hackers find a way to escape their oppression but I suspect they'll just be treated better than others so they'll continue to be oppressed next generation).
Please let me know what you think I'm saying that implies I am in favor of collective punishment against North Koreans based on my statements here so I can more accurately respond to your concern. I'd also love to hear why you have such a strong point of view on this subject, it may add color to help me understand your statements.
Your comments start with "I noticed a lot of people" and continues talking about the individuals.
>Please let me know what you think I'm saying that implies I am in favor of collective punishment against North Koreans based on my statements here
The part where you say a ban would be useless as they'd just circumvent it seems like saying a blanket ban is justified. Or where you wondered why Hacker Rank let them use their platform at all. I will say, I'm less sure that Hacker Rank wouldn't violate the economic restrictions now, visiting the site makes it look a lot more like job recruitment than I thought it was.
Beyond that, I'll paraphrase. For absolutely no reason, you assume that everyone using a computer in North Korea must be using it for hacking. Yet in the society you live in, can you name a single business that does not use some kind of software the tools at Hacker Rank helps improve?
They have plenty of use for the training outside of criminal hacking, and you saying it's a "workaround" for them to access educational resources ignores this.
>I'd also love to hear why you have such a strong point of view on this subject
I hate how people treat North Koreans as either mindless tools of the state or pitiable oppressed masses. None of your comments have acted like any of the people signing up are real humans expressing complex desires in their admittedly somewhat shitty situation. Imagine how you would feel to wake up suddenly blocked from the service because they decided they don't like where you're from.
Fair, but as I've now stated several times, that's not what I intend, so your continuing to read it that way is your choice.
>it seems like saying a blanket ban is justified.
How could an easily circumventable ban be what I am advocating for? That's absurd. I'm saying a ban would be pointless because if the goal is to keep them off the internet, it won't. In stating this I make no statement about the validity of an attempted ban in the first place. To be clear, I do not agree with banning people or countries from the Internet.
>Or where you wondered why Hacker Rank let them use their platform at all.
Yep! That's pretty much it. I know that Github, for example, has been made to limit access to Github where sanctioned. I thought that maybe such a thing would apply to other SaaS companies. I am not at all surprised they are on there, most startups aren't wrapped up in government level regulations. Github didn't seem to have a lot of trouble with this until Microsoft acquired them, as an example.
What surprised me maybe a little was that the profiles (I'm avoiding saying individual now) I found were very blatant so I doubt would have flown too far under the radar to anyone looking (government authorities) and would potentially have caused them to talk w/ Hacker Rank, given the nature of the site. Yes, it's basically a recruiting agency, but it's also a place to practice red team skills. This kind of information is available in MANY places, so I'm not even implicating Hacker Rank as being an accomplice in any way, just sincerely curious about how some North Korean hackers ended up on a US hacking site :)
>you assume that everyone using a computer in North Korea must be using it for hacking.
I mean, maybe? I'm not equipped to make that assertion. I think the profiles I saw were an indication that those profiles existed to practice hacking on behalf of the North Korean government. I don't think that's particularly controversial. I saved the names on the profiles I came across somewhere, and if they're reading this and feel wronged because that's not why they used Hacker Rank I'll buy them dinner if they reach out to me.
I do believe that computers and internet access are limited in North Korea, and that makes them a valuable commodity, one controlled by the North Korean government, and I expect them to use those resources in an economically viable way, so it is my intuition that running large scale red team trainings would be a great thing for them to be doing.
>They have plenty of use for the training outside of criminal hacking, and you saying it's a "workaround" for them to access educational resources ignores this.
I didn't know there was an educational exemption, and I very much appreciate your pointing it out to me. I used the word workaround because I still believe these profiles were created on behalf of work for the government of North Korea. This is a reasonable assumption, and you've provided no counter examples as to what kind of non-government run hacker culture exists in North Korea, if there is one, it must be fascinating and I'd love to learn more about it from you.
>They have plenty of use for the training outside of criminal hacking
Absolutely, these hackers are likely learning a defensive skill as well, and even if acting on behalf of the government of North Korea, I don't claim they don't deserve to develop these skills, never have.
>I hate how people treat North Koreans as either mindless tools of the state or pitiable oppressed masses. None of your comments have acted like any of the people signing up are real humans expressing complex desires in their admittedly somewhat shitty situation. Imagine how you would feel to wake up suddenly blocked from the service because they decided they don't like where you're from.
Thank you, this is much appreciated context. I apologize that the way I spoke diminished the individuals involved, that's clearly a theme here, but I think you should ask more questions before jumping into the many assumptions you've made, we could have had a lot more productive and interesting conversation if you stated your last paragraph in any of my other responses!
Thanks again for responding, and I'll keep this in my pocket when thinking and speaking of marginalized and oppressed people in the future.
>Yes, it's basically a recruiting agency, but it's also a place to practice red team skills
I've never used Hacker Rank, but the Wikipedia page does not make it seem like that's one of the focuses of the site. It says it "focuses on competitive programming challenges for both consumers and businesses, where developers compete by trying to program according to provided specifications." Which may explain much of our misunderstanding, I would not assume a member of the service was engaging in "hacking" at all.
I've somewhat wondered if there's a second Hacker Rank, but the first page of search results showed nothing.
> but I think you should ask more questions before jumping into the many assumptions you've made
Your first reply to me said "those people are pawns though, not curious hackers," I didn't think it was an assumption to think you actually thought that.
Looking back I may change a few things about what I said but better to just put it out there. I think using hacker rank to train algorithmic and programming skills is none the less (under my opinion that these skills are being developed for malicious purposes, which I think we agree could be defensive, or even just personal curiosity), and doesn’t change my surprise at finding the profiles, given my assumptions about the sanctions. Hopefully this somewhat closes the loop on our back and forth, and i appreciate, again, your willingness to talk this out :)
Edit to be clear: found profiles on hacker rank. Confused with hacker one because of age and time. Still curious about NK hackers training up algorithms, it’s fascinating. I owe you a big apology for the confusion. I also agree that it feels like we are in agreement on the important parts.
It's typically known as the "paradox of tolerance" by the way, your mistaken version didn't ring any bells, and I assumed you thought the argument ended in a logical paradox.
Among those "privileged" people are the ones who are actually capable of leading a revolution in North Korea, and will not be outspoken about it until they have a proper plan. I do not believe in imposing restrictions on them.
https://home.treasury.gov/policy-issues/financial-sanctions/...
Their social engineering skills are impressive!
Similarly, although Nixon was famously paranoid, he was also right about the soviets fomenting and amplifying vietnam war discord, too.
It's not completely implausible given what happened to Otto Warmbier:
Because in the eyes of a poor individual civilian who had food to eat yesterday and didn't today due to some stupid embargo, the US is responsible for their hunger.
We detached this subthread from https://news.ycombinator.com/item?id=26910229.