Has North Korea Started the First Cyber War?
mashable.com
mashable.com
What I can say is that we need to make it much more difficult to infect personal computers here.
If you show me a Korean government or non-trivial Korean corporate website, I'll show you a website that uses at least 3 activeX controls and is optimized for IE6. Most public computers and the majority of personal computers I've used here have been running IE6 or 7. I'll admit that in Seoul and larger cities like Pusan, Ilsan, and Gwangju, you'll sometimes catch people using Macbooks at Starbucks. Score one for security via obscurity, but non-IE folks can't use ANY banking website or government site (National Tax Service, National Pension, National Health, etc).
Even though I'm in the "most wired country in the world", the majority of high schoolers, uni students, and business people I've interacted with aren't more tech-savvy than your average grandma. Everyone runs the dubious AhnLab Anti-virus as a mandatory magical medallion that came with the computer.
We need to do better - Korea's great ability is overnight change on a massive scale. The day President Lee announces that all browsers should be upgraded to the latest version is the day that all browsers will be upgraded to the latest version. Seriously.
Barring that kind of concerted effort, should the day come when I see a non-IE browser or something other than WinXP/Vista on a Korean adult's primary/only computer, I will eat this hat. This one, right here.
On the other hand, Koreans are never behind the state of the art - they do relish having the latest and greatest things to show off. You can count on one hand the number of second-hand stores in Seoul, mostly because new=good.
They simply have no problem conforming to the flock, which, in the case of internet security, is rarely a smart move. When eventually some high-level government official or TV channel will point this out, suddenly everyone will take notice, and they'll all move on, as a flock, to the next thing, and the next, and next.
That forum is fun to click around, btw. Only members are allowed to post and only points of view that agree with the official DPRK line are allowed. Contrast with this: http://www.washingtonpost.com/wp-dyn/content/article/2008/12...
On the other hand I doubt any of the other few possible states (China or Russia) would turn to such demonstration of force against US unless they had something to gain from it.
What's left then? Some crazy group like 4chan or some errorists? They would be shouting "we did it" before you even heard the news about the attacks.
Oh well... back to square two.
So this could plausibly be one such strike in an on-going conflict that is far more 'real' than script kiddie squabbling.
Could have been a penetration attack to steal technological secrets.
Could have been a penetration to plant backdoors/loggers for later use.
Could be service disruptions to hamper a particular project. (Take down the network serving No Fly List sorts of updates to get a possibly-compromised agent on a plane or over a border.)
Could just be a 'recon' attack to see what we have connected and how we react. A sort of digital equivalent to the kinds of 'disruption' that we financed and supported from Okinawa toward China for many years.
But I personally find it hard to believe that any state-sponsored cyber 'strike' would be limited to a DDoS on public-facing services. That sounds like a smokescreen at best.
http://en.wikipedia.org/wiki/Economy_of_North_Korea
There might be a little extra in there some where for a trip to Fry's for some l33t hax0r t00lz.