I'm the hacker that brought down North Korea's Internet for over a week. AMA
old.reddit.com
old.reddit.com
Indescribably based.
Then, in response to what should have been an obvious outcome to his actions, he commits what should be described as a "crime against humanity" against the entire communications infrastructure of a foreign country with nuclear weapons.
There is nothing based here. This is stupid with a tinge of greed and ego mixed in.
Also, if the entirety of the US goverment will not protect you from foreign state-sanctioned personal attacks, what should one do? Just sit there and take it, even if one could stop it?
> The State Department has a thing called "Rewards for Justice" and they talk extensively about the NK problem and how we're being hacked all the time. They pay millions for information. I told them "I don't want any of your money, I want you to know who I am [insert wired article here] and that I can listerally make any attack coming from the country North Korea stop in its tracks within minutes. Let me grab their response:
> https://imgur.com/a/s-lX6inGA
> Just be ready to be fucking infuriated. They have a bunch of shit about how we need to take on the NK cyber threat. I literally give them a SOLUTION and they say it's not within their purview, go to other intelligence agencies. I told them I FUCKING DID. No response since.
https://old.reddit.com/r/IAmA/comments/1divlp3/im_the_hacker...
For him to unilaterally decide to commit an act of war against a foreign nation means he should also be held accountable for it in international criminal court.
Were this any other two nations you might have a different tone. But these are the facts of the matter. He played with fire and if he winds up dead because of it he only has himself to blame. The only people I am concerned about is anyone else now facing danger because of his idiotic actions.
Meanwhile NK offense regularly attacks him on a nice day, and on every other day installs ransomware on US hospital infrastructure, putting actual lives at risk... All this guy did was shut down their capability to do so.
I am unaware of any law that he broke. IMO, he also did not do anything immoral.
If NK took down our infrastructure, it would be our fault because we have been warning our corrupt leaders for years and nothing is being done.
Examine how their own actions were a large part in creating this particular outcome? Then question if they're worth continuing under such circumstances?
> No response since.
Yea, maybe diplomats should lead the charge, and not self important hackers with a desire to "shut down the internet" in a fit of nerdy rage?
The reason that I posted this AMA on HN is that a lot people with influence peruse this website, and it would appear that this person went to intel agencies first, then went to State, and was shut down on all counts. Not just shut down for his personal validation, but shut down as far as potential operations.
I posted this in the hopes that someone with influence would see it, and work to prevent this from ever happening again. This guy tried to go through all the right channels. The US gov failed him, and all Americans, at every level.
Ideally, an intel contact would have responded with: "thanks, I'll make sure that the proper people know about this. Await a reply." Reply: "Please come in... OK yes, we know and will save it for an emergency. Never mention this again. Here is your monetary award, as advertised."
For unknown reasons, that did not occur. After this all happened and got written up in Wired, he is finally getting contact from the appropriate people. Let's not let this go this far in the future.
Ask yourself. Do 'hackers' talk like this or military/government employees?
Also ask yourself, is WIRED a 'hacker' friendly magazine or a government affiliated state media?
Some top WIRED offerings
'Former FBI Agent Explains How to Read Body Language...'
'Former CIA Chief of Disguise Breaks Down 30 Spy Scenes From...'
Not to mention reddit and reddit AMAs been used by government agencies to push an agenda.
Ask yourself, is this something that a US government agent would do?
He said thought his tools would be "stolen?" Then this is a lame manufactured pretext which makes it worse. It also makes his actions and broadcasting them _more_ of a crime.
I'm not sure what your point is here.
I fully understand why the US and partner governments won't be able to respond in kind, but there is certainly a lot more that could be done in that domain.
That the public believes this is our biggest problem from an international policy perspective... (as far as this topic, that is)
These governments are turning a blind eye, if not quietly supporting such because of the sheer economic and social damage.
I know a local hospital group paid 22mil in ransom on top of a lot of days where stuff barely got done.
Iirc United Health said a recent attack was probably 900 million in total costs to them?
It adds up.
yeah, some of those governments have even admitted to spike their own citizens with LSD to see what happens, and COUNTLESS other things. oh....
Responding in kind has minimal value because it’s not a deterrent.
Maybe it's just my lack of knowledge of some regionalism, but doesn't it seem very odd that a technical person would use "in the open source", to refer not to code, but to a PR article on some news website?
--
[0] - https://irp.fas.org/congress/2005_hr/062105jardines.pdf
back in the day it was just "reading the newspapers and talking to the local cab drivers", but on 2024 you're scanning forums and social media, on top of news sites.
go to a military-related subreddit and start asking questions about stuff, and you'll eventually get an expert to chime in. Make wrong & stupid claims and then have them slap you down and spill some details -- that's how they got dudes to release classified tank info in Warthunder.
dudes in Palestine and in Ukraine are getting killed because they post selfies and tweets that have GPS coordinates in the metadata. Not hidden behind any top secret firewall, easy to find if you're checking VK or Instagram, but very real implications for dropping bombs.
OSINT is also absolutely a thing in Cyber, where you can get a lot of details about a target by reading their press releases -- "Corp X signs big new deal with Oracle" -- which can give you a new attack surface. Phishing, on a long, broad timeline, has a very high success rate, so go onto Linkedin and start connecting to people. Figure out their tech stack, create a Sales Guy account, and start reaching out to Architects and Managers, and then map out the teams that might have elevated access...
First time I see "cyber" used as a noun. Is that short for "cyberspace", i.e. the internet, or is it something else?
It is a scam. Especially attribution of hacks to states that are on the Washington shit list. There is just no way to know.
To summarize, there are many people in government who are interested in open source intelligence.
Traditional sources of intelligence are gathered with secret means and therefore must be restricted in distribution to prevent burning the source. This means you can have the best possible intelligence but be unable to a) act on it or b) distribute it to people who can.
The value proposition of using open-source intelligence is that you can distribute it very widely to decisionmakers since it's already "out in the open". Intelligence isn't about hoarding secrets for the sake of such; it's about getting information to people who can use it.
The political issue is that people assume that "secret = higher quality" when there's no inherent value to secrecy. So, spy agencies overinvest in secret-gathering, get a ton of info, and are unable to do anything with it.
Meanwhile, if someone posts a tank manual on the WarThunder gaming forums you can give that to every soldier that might encounter that tank.
This is doubly important in tech because many big tech companies play a significant role in national security but cannot get intelligence that would help protect them, and by extension, American interests.
That’s cool and neat for guerrilla warfare, but I would assume the NSA and DoD are already aware of that possibility? I wouldn’t even be surprised if they saw the DDoS happening on network monitoring tools. Why clandestine meetings for that?
I get why the media is interested, it’s an awesome story.
Then they should have caught this when he came forward to multiple agencies, and was told that no one cared.
Please see my related comment as to why I submitted his AMA to HN. It's to bring to light this egregious lapse in US gov procedures:
https://news.ycombinator.com/item?id=40733355
Disclaimer: I do see the possible benefits for citizen liberty, where all agencies do not share every interaction with citizens. However, when a US citizen volunteers something actionable, there should be a special cross-agency path.
The first is that it was already obvious to anyone who has worked with large-scale networks even before firing up traceroute. It was already widely known that North Korea has bad peering, because nobody but China wants to peer with them. The US is where most of the major cloud companies are headquartered (i.e. resources can be commandeered), and the defense budget would support an _enormous_ DDoS attack without even flinching.
Secondly, denial of service attacks are worth much less to governments. They have the capability to physically break infrastructure either obviously with bombs or clandestinely via who knows what. They don't _need_ a DDoS to deny service, and it's certainly not their most effective way to cut off communications.
There is no lapse, egregious or otherwise. This kid is playing in a game he doesn't fully understand, and likely just annoying people who have been playing the game a lot longer and at a deeper level than he is.
He thinks being able to DDoS chokepoint routers with $5000 worth of VMs to spam traffic is an amazing discovery. It isn't. That's why no one cares.
Don't blame them. Enom fee's are extortionate. And when DNS breaks it still works.
North Korea hacked him, so he took down its internet - https://news.ycombinator.com/item?id=30180566 - Feb 2022 (238 comments)
Sometimes the person who says "I'm really smart, like mensa level", does some really ignorant and stupid things.
Killing a US citizen on US soil would not go down well.
> North Korean state media threatened "merciless" retaliation for his depiction in the film. Seth Rogen responded, "People don't usually wanna kill me for one of my movies until after they've paid 12 bucks for it."
https://en.m.wikipedia.org/wiki/The_Interview
Where is the merciless retaliation? Keep in mind this film has a graphic scene where Kim Jong Un dies…
I would wager that if NK would attempt to harm this hacker it would be through using third parties like cartels or local gangs. This could offer NK plausible deniability and physical access to the target, but it also complicates their operational control and increases the risk of exposure. The calculus for NK would include considerations such as:
- The individual's public and former government status, which might provoke a stronger U.S. response if harmed. NK would have to vet the hackers assertions that he still has meaningful and significant contacts within the USG. - The cost and complexity of outsourcing such an operation discretely. - The types of U.S. responses that might follow, from diplomatic measures to cyber counterattacks.
While an attack via third parties is plausible, and given these factors which I am sure there are others I haven't considered, it would require NK to balance the benefits against the potential repercussions and the likelihood of successful attribution. But I am very confident that if they do follow through it will be using a cartel or local gang as proxy for the reasons I mentioned.
P4x's public disclosures and technical skills make him a unique target, but as he himself noted, the operational capabilities of North Korea within the U.S. are limited. It's a nuanced threat landscape where indirect methods might be considered but are not guaranteed to succeed without significant risks.
who know if NK will do it again, but showing his identity so that NK know who they should target is really stupid
Incidentally for anyone who's actually paying attention, the first rule in covert actions is being and staying inconspicuous. The real world isn't like Hollywood where people working in the shadows can become celebrities as a side gig.
I hope this guy has a really good security detail now that he painted such a biglyarse target on himself. God damn, man.
Some hacker movie said the problem is when you brag about it, and you desperately want to... and just looking at his post with the edits, he really is metaphorically jerking off to how awesome he is.
Holy frakk, he's even posted his face on that post. GOD DAMN! I half look forward to reading about how 2 women were fooled into pranking^W assassinating him (1). I hope dude isn't thinking of travelling to Asia anytime soon.
1) https://en.wikipedia.org/wiki/Assassination_of_Kim_Jong-nam#...
North Korea is a poor country with millions of starving citizens, and rather than sending food aid, you broke down their only comms to the rest of the world?
Only the elite in that country has access to the Internet. The starving citizens do not have access to the Internet, and even if they do/did, they're so heavily monitored the minute they even glanced at something controversial they'd be shipped to a concentration camp.
Sure, but then the overall population might be depending on it indirectly.
Whom it did affect a bit, hopefully, were the people complicit in the repressive dictatorship that runs the country.
The repressive dictatorship that engages in, among many other bad things, scams and online fraud to partially finance the country. For this they of course use the internet. So, taking them off-line for a week may have prevented someone from getting scammed. Good result.
Probably didn’t. Can’t say definitively. Shipments of critical resources could have been disrupted, et cetera.
Doing this with zero context was probably reckless by this hacker. It also likely had zero real-world consequences.
There's rarely such a thing as a clear, objectively simple 'good result' for this sort of action because outcomes have knock-on effects. For example, if the North Koreans responsible for maintaining internet access were executed over this that diminishes the result significantly.
Every resistance action carried out by every resistance group against tyranny throughout history has been washed in the blood of people who did nothing wrong.
As an analogy, we should have empathy for homeless people stuck in poverty, but if one of them continually bikes to your house and tries to break in, is it morally dubious to eventually take their bike chain rather than just shooing them away each attempt? I imagine the moral razor would fall on similar lines.
In the homeless analogy, maybe the attempted-robber's friends go hungry, since he usually uses the bicycle to go to the grocery store.
To me, I don't imagine this changes the calculus much, since almost any intervention will have side-effects.
If it's something "we like", then it's ok, if not, then prison.
Same for geopolitics... in one case, we care about teritorial integrity, that minorities should not seced, and in others we help with the breakup of countries... well.. or in some cases, we act is if nothing is happening at all, and noone wants to break away at all :)
This means no other country has jurisdiction in North Korea, besides, there’s also no incentive to help in case DPRK asks for help.
France doesn’t investigante crimes that happen in Spain, Portugal doesn’t investigate crimes that haven in Canada, the USA doesn’t investigate crimes that happen in Germany, etc…
You’re citing centuries-old political philosophy, only remnants of which remain in our world [1].
The West that arose after WWII and through the Cold War is decidedly non-Westphalian. Concepts like human rights, non-proliferation and self determination are non-Westphalian. The Nuremberg trials were anti-Westphalian.
The closest modern analogues to (and proponents of) Westphalian philosophy are Russia, China and North Korea.
Westphalian sovereignty as a historical concern is a myth [2].
[1] https://en.m.wikipedia.org/wiki/Guarantor_of_the_imperial_co...
[2] https://www.cambridge.org/core/journals/international-organi...
Not an enforcement priority for the same reason a lot of domestic abuse goes unprotected: the victim is uncoöperative.
> going by the West’s own laws, or the spirit of them, anyway
Pyongyang and prosecutors would have to show he attacked a “protected computer” under the CFAA [1]. Given the two routers he allegedly overwhelmed were internet connected, that shouldn’t technically be hard under Trotter and Kane. But it would be a novel expansion of interstate commerce to encompass a country with whom Americans cannot legally trade, i.e. do commerce.
Put another way, North Korea’s status as a sanctioned country might put this into a legal grey area—it might not be criminally punishable. To settle that question would take a lot of prosecutorial resources. It’s not clear those are well spent on a case where the witness won’t coöperate.
[1] https://www.coreyvarma.com/2015/01/what-is-the-computer-frau...
Good point: a final hurdle inhibiting criminality is his lack of profits. No disgorgeable gains. That means you’re only left with damages, which again, requires the victim’s coöperation to assess.
Some things are too big to just mess around with, I would feel extremely vulnerable having pulled such a stunt.
Sure. But OP asked why he isn’t being arrested. Plenty of people piss off the IC when they publish e.g. long-coveted (and independently discovered) zero days, or write an exposé on something an agency was hoarding for interagency political value.
We're already well into causus belli territory with NK, but nobody wants to go there: https://x.com/tarah/status/1798036415932187127
Summary of thread: Society doesn't handle 2nd order consequences well. NK cryptolocker attack on healthcare-involved systems in British hospitals disrupted treatment to the extent that hundreds of people died who probably wouldn't have.
Expanding on that: Organized crime groups located in and sometimes tasked by RU SVR & GRU (not to mention NK state groups) have caused sufficient disruption to US healthcare systems to have indirectly caused more US Citizen deaths than the Sept 11 attacks. Right now cyber that does not directly cause destruction such as making buildings blow up or poisoning water supply is treated as just an annoying white collar crime.
I don't think anyone wants the US Government to be in a position where their options are to admit powerlessness or get proportional against nuclear armed states.
Somewhat related: https://blogs.icrc.org/law-and-policy/2023/10/04/8-rules-civ...
He very much could, if politics changed. The US hates NK not because they are authoritarian but because they are not aligned. If they were to be aligned, and this guy didn't act on proper authorization, he could find himself in hot waters in the USA.
Plus he might have broken a bunch of "international" rules which could see him in trouble if he was to travel to some countries.
It is really reckless; but then there is a good chance he was acting behind some agency.
Almost certainly not. The vector would have been saved. And he wouldn’t have maintained this public profile ex post facto.
Consider, for example, taking it down during today’s state visit? (After you’ve quadruple checked that the Russians have independent connectivity.)
However, a minimal amount of cyber attacks probably actually originate from NK directly. It’s known the NK hackers are trained in China and attacks probably flow through compromised VPS accounts, VPNs, open proxies, and open SOCKS-5 located around the world.
The NK hackers could be sitting in NK using the systems I referenced above to do their attacks and were not able to because they couldn’t connect to the internet. Maybe so, but they are most likely usually sitting in China and other locations.
That exercise that Russia did a few years ago to see if they could function cut off from the internet? For north Korea that's the regular self-imposed status quo. I don't think it will have had much impact on daily life there.
> dotslashpunk: lol, no I only say that during either sex or when I'm able to join a meeting successfully with my microphone and speakers actually working. Both are rare.
Talented and funny. He's wearing his new found fame well.
What I read is that guy did a clever DDoS, which is mildly impressive, and decided to become a twitter celebrity/NK assassination victim. I am no hacker, but I expect real hackers to be laughing their asses off.
two wrongs don't make a right, usually.
Yes only the elite have the internet, but also the internet is likely used internally for communication, which is important for resource distribution.
I don't give two shits about the elite in NK, but the starving folks living there have my deepest sympathy.
I'm lucky to have a lot of advantages, and I can't help but see many of them as an accident of birth.
I think I can make it simple. Would love to hear of any cases refuting this.
If the country is on the US State Department's 'Sponsored' program list (currently DPRK, Iran, Sudan, and Cuba) it doesn't count. Florida terrorism ok, you get a pass and called a hero: https://en.wikipedia.org/wiki/Luis_Posada_Carriles
Comparing to other more recent Florida originated attack on against a poor country, the assassination of Haiti's president. Haiti is not on that country approval list, go directly to jail: https://www.justice.gov/opa/pr/four-florida-men-arrested-plo...
No internet means less control. Brings them closer to the starving folks level, more chance of actually being a "people's republic" then. There's not much government worth salvaging in that country, basically an army.
The only loss would be them improving their security now. Other world governments may have left that vulnerability untouched purely in case they need to use it at a later stage.
Maybe they’re another Russia, their tanks and artillery all crumpets. But maybe not. They have a lot of them on paper [1].
[1] https://en.m.wikipedia.org/wiki/List_of_equipment_of_the_Kor...