US Links North Korea to Sony Hacking
nytimes.com
nytimes.com
The evidence has to be better than this to make an accusation against a state. Botnets overlap a lot because the way they are built is with automated scanners that take advantage of common vulnerabilities. It isn't uncommon to find a botnet client that has been hacked a half-dozen other times and has had rootkits installed each time. A large part of sophisticated botnet droppers is removing all the previously installed botnets on a server where a vulnerability has been found.
Having one client in common with another attack network is a low or insignificant figure.
Similar applies to common modules found in other malware. Authors reverse engineer and re-appropriate techniques or libraries from other successful malware all the time. That is also not evidence of a link to North Korea.
> That suggests, but does not prove that that the same group or individuals may have been behind both attacks.
--Washington Post
> It is not clear how the United States came to its determination that the North Korean regime played a central role in the Sony attacks
To me, that sounds like they aren't privy to the reasoning used.
If the US has better evidence, why not show it? I'm not saying NK didn't conduct those attacks, I'm just saying the US government isn't really a reliable source about anything.
If there is a retraction it will be in a year's time and buried under an ad for washing powder on page 17.
You simply don't need evidence anymore when the media, unwittingly perhaps, construct the narrative for you.
Why is the New York Times held in such high esteem? Was there a period of time when it truly was a paper of record? These days it seems like the name Pravda on the Hudson is well deserved.
However, there is an age old equation that works fairly well for attribution: opportunity + motive + evidence. Opportunity in cyberwarfare is a complex item to tease out and has more to do with opportunity costs than anything else (the strategy of cyberwarfare demands owning everything immediately rather than later and the exercise becomes one of triage).
In this instance we do have both a motive and some evidence that point to North Korea, and it is in line with the sort of theatrical politics NK is known for. IMHO more evidence and an analysis of opportunity cost are a must to pin NK down further, but you can be assured that (unless officials have ulterior geopolitical motives) they have a pretty good idea about the cyber capabilities and actions of other nation states - more than they are apt to release to media outlets.
Everybody seems to have forgotten that this started as a financial ransom demand and the attackers made no mention of the movie or the DPRK until Sony and the media did.
I'm not suggesting the DPRK are not involved, but that it is a very big leap to go from media speculating about motives to the US government formally accusing them. The details leaked to the NyTimes do not substantiate this leap.
It truly is difficult to attribute and only with more evidence and a more careful analysis of timeline, the malware, and the communications will things come into focus.
One thing I have not yet been able to find are numbers for the ransom. I've seen the emails demanding ransom and the defacings demanding the same, but nowhere have I seen a number of dollars being demanded. Have you seen that anywhere?
Re: computer hacking considered "terrorism" - this represents yet another way "terrorism" no longer means the despicable act it was originally associated with. And doesn't that make the "War on Terror" also a "War on Hacking"? How the hell are we going to win a war on hacking?
I do hope that the OP was not using the GW Bush administration definition of terrorism...
You can try to fight the total annihilation of meaning in our language, but as you see here it is a losing battle.
terrorism
socialism
marxism
hero
capitalism
free market
invisible hand
imminent
torture
collect
to brief
espionage
surveillance
privacy
freedom
search
Opportunity costs are exactly as low for every country that the US decided to antagonize by placing on their evil axys list, and only marginally bigger for any other actor, because nobody will catch the hacker.
The only item of yours that can not point to anybody that you want is the evidence. Evidence-less finger pointing is not a sane sport.
Opportunity costs are not exactly as low for every country, as they have different capabilities, use different tactics, have different budgets and talent pools, and have different interests. Triage is going to be different for different state actors. Pure and simple. I'm not sure that an opportunity cost analysis indicts NK - and in fact I do suggest that work needs to be done there in the original comment.
That's just a good a reason as any other motive for any other suspect given that I've seen.
IMHO, SONY & USgov have more of the first 2 than N.K. and the 3rd can just be made up.
USgov., I think they will take any chance given to them to put China, Russia and N.K. in a bad light.
The big question your analysis seems to beg is why #GOP would demand that the movie not be shown. In the scenario where Sony and the USG want to spin this as anti-NK propaganda (certainly this is not out of the USG playbook), why would #GOP play along? I don't understand #GOP's motive in your scenario.
I'm not sure that I personally buy that the evidence is manufactured - that there is motivation enough from the USG to invent that evidence. But this is where there is reached an impasse. There just isn't enough information at this point to really say. Either speculation can be right.
It'll be interesting to watch as this continues.
Companies are "brands" for hackers. "I hacked Target. Home Depot was me." etc. Sony is a huge brand. Keep the lulz going, and see how big it can get.
When in doubt, blame China.
That doesn't mean the threats are legitimate. Or that North Korea is involved. But the actions of folks involved do give serious weight to such an accusation.
If you think about it, it makes perfect sense. The continuous release of leaked data means the attacker probably had access for a considerable amount of time to completely download the large number of files. My guess is that they had escalated their own access during employment and routinely monitored the communications of executives.
This was most likely the work of someone that had or maintained a blackhat past. This is someone that most likely had access to a botnet, knew where to go to buy/download malware (underground forums), and knew how to obscure their connections (and where to directly connect). And if you think about it, posting to Pastebin? Definitely a US-thing, and not so much a Chinese thing.
I'm willing to bet this person/people will be caught through old-fashioned profiling. Cross-checking the terminated IT employees with previous convictions for computer crimes, their personal emails with known hacker aliases, and other investigative techniques.
[1] http://www.tmz.com/2014/12/17/sony-hack-inside-job-north-kor...
I think its more to embarrass Sony than anything.
The other explanation seems to be that #GOP would demand the movie not be shown to confuse the scent of their real motive (revenge? lulz?) (but this is also questionable IMO). It also seems unlikely that an ex-employee would use the same IPs from previous Korean state sponsored attacks, although maybe they could have bought access to these servers on underground forums? Others are suggesting that this is entirely invented evidence - I see no good reason to believe that.
I know a lot of people are speculating that Sony has something up its sleeve, like a limited-time-only release right after Xmas, or early next year, or a digital release, etc. I'd consider that an extraordinarily slim to nil outside possibility. The material leaked in the Sony hack does not exactly give the impression that these guys are marketing geniuses. Just sayin'. :)
For what it's worth -- not saying you're suggesting this, just that I've now heard the theory a couple dozen times -- some people are speculating that Sony engineered this entire fiasco as a publicity stunt for the movie. That sort of thinking is beyond-the-pale naive. Sony doesn't want to be civilly or criminally liable for having doxxed thousands of its own employees. Believe me.
I bet they will release it later in the new year with excellent financial results.
The film is getting such incredible hype a huge amount the profits will be in the opening night. Check out the Rotten Tomatoes score: critics are divided on whether it's a good film, but 96% of people want to see it.
If Sony don't release the film eventually internationally, they'll lose money - but withholding it makes it a scarce commodity, drives hype etc.
What you are now reading about The Interview isn't politics, it's PR crisis management.
http://www.rottentomatoes.com/m/the_interview_2014/?search=t...
A general rule of thumb is that a movie studio spends at least as much on prints and advertising ("P&A") as it does on production costs for the movie itself. That is to say, if the movie cost $35M to make, Sony sunk another $35M or more into P&A. So it would need to earn more than $70M to break even (more than that, because everyone's taking points off the top-line gross, plus profit-sharing with theaters and distributors, etc.). Is it possible that Sony could earn that much on this sort of movie, given its notoriety? Maybe, maybe not. Notoriety alone can rarely get you to $70M. (It's possible, but unlikely.) To stand a better chance, your movie also needs to be halfway decent.
Once again, I have no idea if this movie is good or bad. Just saying this for the sake of explanation.
This also isn't taking into account the ROI from turning Sony into the victim in this scenario - not a massive company with a tiny, unsophisticated infosec team who messed up big time by not investing more in security.
Source: http://deadline.com/2014/12/sony-scraps-the-interview-120132...
Reddit discussion: https://www.reddit.com/r/movies/comments/2pmasy/its_official...
It's #1 on /r/all, comments are not that insightful.
How to be a media outlet in 5 easy steps:
- do not provide any sources, at all, unless of course you're dogfooding
- make bold claims based on hearsay, comments from random strangers and uneducated/irrelevant celebrities
- judge and slander people before any researched verdict has been reached
- spread lies and make them truths through mob behavior, then support your original lies by pointing to the "public consensus"
- do not take responsibility for any of your actions, ever, unless it generates money and/or attention
The repercussions of these half-assed "investigations" worry me to say the least.The evidence linking this to any nation-state at all at the moment is incredibly weak, bordering on non-existent.
With these administration comments, is it more likely that NK was actually responsible? It's still possible that this will turn out to be the overblown suspicions of somebody unfamiliar with how digital attacks work, published too quickly because they fit the narrative. We've seen the state of journalistic fact checking lately, and even if this is the NYT, 'senior administration officials' isn't a bulletproof source. But it's also possible that we now live in an era where nations wage proxy digital war against corporations not just for theft but for ideology.
This would be a strange new state of affairs. I wonder how long before corporations are fighting back? If, say, Samsung's expected value for government reconstruction contracts following NK's fall was in the tens of billions, how difficult would it be for them to cause a couple military installations, power plants, or leaders' flights to explode and make regime change more likely?
Source? The bomber would be liable but why would Sony be? (Provided that they informed at least law enforcement and certainly if they made the details of the threats public).
In retrospect, I was wrong - it was the theater chains who would be exposing to themselves to that risk, so they (very logically) cancelled their showings. As a result Sony was forced to pull the film's theater release.
Less, in my view. It's true that if a liar says the sky is blue, that doesn't make the sky pink. However, if that liar is the United States government, it doesn't hurt to have a look out the window.
As with other new frontiers of geopolitical leverage there will be a painful learning and a growing period for the internet. There's so many ways it could turn out and I fluctuate between being hopeful and pessimistic and what I will temporarily think is 'realistic'.
http://www.wired.com/2014/12/north-korea-did-not-hack-sony-p...
I find it funny how fast pop-media news jumps on top of a bandwagon without actual investigation.
Earlier we were being told "North Korea is definitely behind this". Right now everyone is saying "North Korea is probably not behind this".
Why bother with networks that just regurgitate information from other people? Don't push a point of view, just lay out actual facts and let the readers come to their conclusions as more information is made available.
For instance, New Gingrich said:
> No one should kid themselves. With the Sony collapse America has lost its first cyberwar. This is a very very dangerous precedent.[1]
> @RobLowe it wasn't the hackers who won, it was the terrorists and almost certainly the North Korean dictatorship, this was an act of war [2]
So now we have uninformed rhetoric coming out from people who—unfortunately—may have their opinions viewed as credible due to their past as an elected official. This was a candidate for presidency in 2012.
[1] https://twitter.com/newtgingrich/status/545339074975109122
[2] https://twitter.com/newtgingrich/status/545339504803196928
If the hack was indeed state sponsored as this article claims (based on comments from unnamed intelligence officials), then it seems much more likely that the hack was done by Chinese hackers than North Korean.
You don't think that they would have a cyberwar unit?
I have got to look up how to join more direct communication to the reclusive government of north Korea, in my own name, recording my own return address, and making clear that I will not be pushed around by a regime of thugs. I have recently been following the suggestion of another Hacker News participant and have read the three-volume history of the Nazi regime by Richard Evans, the Third Reich trilogy. Evans notes in various places in his books that even the Nazis were responsive to international opinion on some issues. In the early period of the Nazi regime, Hitler used to receive personal letters from American eugenicists and segregationists who praised the policies of his regime. I don't want my not saying anything at all to be construed as consent or as fear of indicating disagreement with a dictator. I will have to openly and frequently express my disagreement with the world's remaining dictators until they all fall.
The North Korea Now website
http://www.northkoreanow.org/take-action-now/get-your-voice-...
provides advice on how to write letters that may have influence on the regime there. Sure enough, one part of the advice is to write to China, the country that does the most to prop up Kim Jung-un's regime. A letter to be broadcast by Free North Korea Radio
http://www.northkoreanow.org/now-accepting-letters-from-amer...
might also help. A Washington Post editorial from October 2014
http://www.washingtonpost.com/opinions/north-koreas-leaders-...
lists other steps to take to express disagreement with the regime in north Korea.
So I'll write a letter--now seems like an excellent time, honestly.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
Disclaimer: I'm not pro war and generally not pro- US foreign policy. The events in Iraq were shameful. Our involvement in Libya and the so called Arab spring was shameful. Our involvement in Ukraine and general treatment of Russia has been deplorable and painful to watch. I think we should stop saber rattling at Iran who I believe would join the modern world much more quickly if they weren't being constantly threatened and undermined by a power that has done them some serious wrong in the past. The US's seemingly unconditional support of Israel, Saudi Arabia and the Gulf states is unconscionable in my estimation.
That being said, I feel differently about North Korea. I believe this country truly is dangerous and steps should be taken sooner vs. later to dis-empower it. I am genuinely worried worried about what might come from there in the next decade or two if things continue as they are.
Just my opinions.
I truly hope people still aren't this naive after an entire decade of this kind of "journalism".
Namely that the attackers don't even mention the movie, but instead seem to be on an ant-Sony crusade. Mentions of the movie by the "attackers" only seem to start happening when people started saying it could be NK.
The sudden urgency inside the administration over the Sony issue came after a new threat was delivered this week to desktop computers at Sony’s offices that if “The Interview” was released on Dec. 25, “the world will be full of fear.” It continued: “Remember the 11th of September 2001. We recommend you to keep yourself distant from the places at that time.”
Won't anyone think of .. national security?