Why the Sony hack is unlikely to be the work of North Korea
marcrogers.org
marcrogers.org
First, various people like sony have been forcing VFX houses to go through draconian security changes to stop this kind of threat. (supposedly because one of us leaked expendables 3, despite none of us having the complete movie or sound)
These rules include three separate zones, of which only one has access to the internet. All USB storage is disabled. All internet access must go through a terminal server. (all our phonehome services for disks now don't work)
All data must go through a purgatory like intermediate stage, for the data ops guys to move out to the "outside" zone, for upload to studios.
We then have monitors to look at the data flow, to see if wierd stuff is happening.
So if they'd followed the MPAA's own advice none of this would have happened, unless of course it was an inside job. Which in my mind there is little doubt.
But of course, conspiracy theories and big companies being unfair against the nineteny-nine-percent, are all much more newsworthy than reality.
Hence goes my last post on HN. I'll come back when - if - reason someday prevails over sensationalism.
The earlier stages (Assets, texturing) need internet for reference :)
Strick AD password, account lockouts after n attempts, password rotations every 90 days.
The internet must have an air gap between it and the "production" network. So that means internet in terminal server clients. (we used to be able to get away with VLANs, and just have a clientside VM on a different VLAN)
No automated mechanism to move data between the "production" network and the outside world. Any data that needs transporting must be accounted for (and that's literally terabytes a day.)
My bet is that while Sony was forcing other vendors to follow draconian security measure, they themselves had very lax security. Keeping SSN of 3000+ employees in a non-encrypted excel file?
That alone tells me Sony didn't have tight enough security, hence hack by outside (teenagers or N Korea) is more likely.
Things like this happen all the time, where a big company/org tells vendors to follow some rules while they themselves ignore them. All the time.
The problem is that a lot of the first release stuff came from HR. As we all know HR types rarely understand computers, let alone security. Even if they had a password repo that was super secure, it would be easier for them to share a spreadsheet, so they'll do that instead.
For all we know, Sony could have had fairly tight security. From my understanding there were hefty ACLs to stop various sides of the business talking to each other. Yet these were still breached, for a long time and lots of data seeped across.
The way the malware was written, and the actions of the hacker(s) leads me to suggest that this was an inside job. It is very had to sneak out large amounts of data, and fiddling with change control whilst not being detected is very difficult. Unless you know how to imitate the normal ebb and flow of work life.
The problem SPE have now is that they'll have to throw away everything and start from scratch. All previous data will have to be quarantined, all infrastructure from the server, switches, printers to the workstations will have to be disposed of. Why? because there is no way of proving that there isn't any malware still embedded.
#2: There's no such thing as "Traditional Korean" (just South Korean, and North Korean), so saying that they don't speak "Traditional Korean" in NK is pretty severely misunderstanding the language. The Korean locale/encoding is very easily changed as a setting, obviously, but it's also possibly used by NK hackers because it would let North Koreans type in Korean. Saying "North Koreans don't speak the same kind of Korean as spoke in South Korea, and thus wouldn't have a Korean locale set" is kind of like saying "Americans have their own dialect of English as distinct from the British, so they probably will not have any English-language keyboards."
#4. Doesn't the fact that the hack seems to be for retribution and not for personal gain precisely fit the motives of a propaganda-oriented country? Would you expect a dictatorship that works on propaganda and political influence to really negotiate some sort of deal with Sony?
My bet is that it's some mercenary hacking group hired by NK, not necessary a state-sponsored thing but by a few high-up individuals within NK --- but not by North Korean hackers themselves.
#5: Maybe they were trying to avoid the Streisand effect?
#6: Why would a disgruntled insider be more media savvy than a state famed for propaganda?
#8/#9: while this may be true, neither provides much evidence for or against the DPRK being the attacker
#10 isn't even an argument.
Yes, it could just be US agencies filling the anti-NK propanganda machine via ridicule.
(Except maybe to its own people -- but that's their internal politics, not for foreigners to judge, especially since they are so selective about which countries they judge cough SA cough)
They are two countries that used to be one and had a civil war. What do you expect? Flowers and cakes?
How about countries that non only test, but have actually used nukes in wars (2 of them, on civilians), as well as countries that regularly invade other countries, including countries that have nothing to do with them (e.g. Korea itself, Vietnam, etc)...
People in glasshouses et al...
Anyway, why would you think I'd consider those to be beyond the judgment of foreigners? Or are you just seizing the moment to make a sarcastic comment without regard to people's actual thoughts on the matter?
The problem is that USA has a hollier than thou attitude that's not content in "judging" but also plays world cop.
Please realize that when you are having a discussion with actual people, railing against things that "the US" thinks is pointless (because most people recognize that countries don't have a singular hive-mind), and you paint yourself as a troll.
We sure don't have those were I live.
Maybe the greatest incarceration rate in the world?
...that part of it is even run for profit?
...and that's also predominantly for black people?
Or how about seggregation (until the sixties !!!! and de-facto even now)?
Or abducting people and taking them to a remote non-legal prison -- without a trial or anything? And then torturing them for years.
How about one of the most ruthless and anti-democratic police force this side of a dictatorship? One that can kill you just because you got out of your car when they stopped you? (!!!)
How about talking the land of native americans? To the point that they've been reduced to live in "autonomous" shitholes?
Should some third country have invaded to put an end to those?
(Haven't even mentioned the huge abuses of foreign policy, because this is about internal stuff).
Comparing the US to NK is still ajoke though.
US == Bad
Everywhere Else == Good
Or: Every government that has every done anything bad
is *exactly* equal to every other government that
has ever done anything bad.
Neither of the positions seems particularly defensible...You're either mad with hate of the US or just legitimately out of your mind.
So, like US agencies pretending to be North Korea?
At some point, somewhere, someone will posit that "it's all the US' fault!".
This doesn't necessarily mean it's not true, but in certain cases, like the fall of the Roman empire, the evidence is probably kind of weak, unless your alien friends have let you in on the existence of a CIA time machine.
You guys can downvote all you want, but the law is true. Get a big enough discussion on any political topic, and someone will explain how the US is the root cause of whatever problem.
The evidence for covert operations is by definition weak.
The historical precedent though of other acts (that have been verified or been unclassified) in the past 60 years, speaks volumes...
Let's put it this way: countries with global reach, and interests in controlling the whole world, especially areas with natural resources, trade ways and such, are not that many. Even less have worldwide operations, tons of equipment and expertise, the most well oiled armies/agencies in the world, and a historical penchant for messing outside their borders (e.g. http://en.wikipedia.org/wiki/Mohammad_Mosaddegh )and crude propaganda (e.g. http://en.wikipedia.org/wiki/Operation_Mockingbird ). And even fewer believe in things like "Manifest Destiny" or that they are the model country for the world (hardly any European country believes such crap, besides maybe Germany, and that didn't turn out that well for them).
I don't think NK is one of them. It might qualify for some stuff (dellusion, crude propaganda, but then again noone outside their borders believes it), but it hardly qualifies for others...
It seems that you are putting your conclusions ahead of the few known facts.
Even if they indeed hack Sony, that still puts them in "innocent boy scout" territory compared to most advanced countries.
The military budget of North Korea is estimated to be around $10 billion USD. It has a million active troops, 6,600 tanks, 700 MLRS, 460 fighters, and so on.
The country is perilously poor. Many people starve. But the means are there for an operation like this, especially if sponsoring foreign groups, if the motivations allow.
And to counter the growing narrative that the NK thing came out of nowhere as a convenient excuse -- the country was very offended by this movie six months+ ago, long before the hack, to the point of threatening military retaliation if it was released. Engaging in or hiring hacking groups to put the pain to Sony seems entirely within the realm of the possible, though threatening actual terrorism is a bridge too far, and overplayed their hands if they were involved with that.
But even that figure ($10b) is comparable to places like The Netherlands, Quatar or Poland (hardly forces to be reckoned with), and 1/3 of what South Korea spends:
All military figures are BS. North Korea has 1,000,000 active member troops. Canada has 68,000 active member troops.
North Korea has more of everything than Canada, including aircraft, boats, and even nuclear weapons.
Canada spends $23 billion per year.
And as to forces hardly to be reckoned with, if you're talking in a convention war with the US or something, sure. To put that into contrast with hacking Sony, though, is utterly ludicrous. The latter could likely be achieved paying a group less than it costs to operate a single fighter aircraft for a year.
Remember how US tanks handled Iraqi ones?
You might have to narrow the definition of 'reality' somewhat for that to become true.
Also, there are plenty of non-Western countries were Snowden wouldn't go too. I'm pretty sure that had he remained in China, he wouldn't be in as good of a position as he is now. Is China part of the "West" that "acts as one?" Hardly.
We don't have to go far to find examples that disprove your "West acts as one" assertion. This is a thread about North Korea, so I give you Hans Brix (or Hans Blix if you prefer), and the failure of the USA to secure a UN resolution in 2003. The USA couldn't even convince France or Germany that the Iraq invasion was justified (let alone wise). If it wasn't for Tony Blair the list of US allies would have been very very thin indeed.
The whole article is weak.
The author also suggests that North Korean material is likely to contain Chinese; this is also bullshit. As part of its ultra-nationalistic ideology, North Korea has been trying for decades to purge their language of loan words, including Chinese. On the other hand, (Traditional) Chinese letters are routinely found in many South Korean publications even nowadays.
Besides, no modern operating system even supports the ko_KP locale, so anyone in Pyongyang who wants to use foreign-made programs will have to resort to ko_KR. For all we know, the hacker could have been a South Korean teenager with Japanese citizenship living in Hong Kong or whatever.
Someone hates Sony / SPE, and paid for the attack.
How did I come to this conclusion?
1. No matter how mad you are, being angry is not enough fuel to collect 100tb of data and then leak it out in 25gb chunks. You need motivation to continue, and money is that motivation.
2. While company security is terrible everywhere, and with enough work anyone can be hacked, it takes a measure of skill and careful planning to pull off a hack like this. This is a not a "we got lucky" hack. It was planned carefully.
3. The amount of data, and the selection of which data gets released when, as well as the difficulty overall of the operation, says to me that multiple people were involved in the hack.
A reason why it isn't North Korea: If it was ( either intentionally or accidentally ) it is in NK best interest to either claim responsibility and embrace it, or to prove they didn't do it. They have done neither. This implies that they can't prove they did or didn't do it, because nobody under NK government control was involved.
There's really no need for anyone to have get paid in this scenario. I'm not saying it isn't possible, just that it isn't necessary to explain what happened.
The disgruntled employee is really the "husband did it" in murder investigations. It's so common you have to investigate it by routine every time. They probably don't have enough audit data to track the leaker, or they would already have done it.
Have you seen the way the releases are organized?
They are all compressed using rar files. Rar releases are trademark of scene releases. This was done by professional hackers who have been around long enough to stick to using rars...
I don't advocate downloading the releases so I can't really say much about the contents of the files themselves, only regarding the directory structure, since the file listings of some of the releases were publicly released online by infosec pros.
That doesn't necessarily have to be the case here however, the h4xors in question could just as easily have written the malware too.
The timeline for North Korea doing this or hiring someone to do this is off. They would've had only 3 months to put together the project.
Your psychoanalysis makes sense in the world of corporations and individuals. But in the world of geopolitics, personal feelings don't matter.
This is North Korea telling the world "We still matter. We may not be able to fight you directly, but we can still hurt you."
> 1. No matter how mad you are, being angry is not enough fuel to collect 100tb of data and then leak it out in 25gb chunks. You need motivation to continue, and money is that motivation.
By leaking the data in a slow trickle, they keep the hack in the news. This attack was designed to get maximum attention in the press, because the more we talk about North Korea, the better for them.
> 2. While company security is terrible everywhere, and with enough work anyone can be hacked, it takes a measure of skill and careful planning to pull off a hack like this. This is a not a "we got lucky" hack. It was planned carefully.
You're right, but think about the kind of hack you could perpetrate if you had a $1 million budget to hack a company. You'd probably buy exploits and malware off the black market, modify them for your purposes, scout the network, then trigger your plan into action. Which is exactly what happened here. It's not like NK are cavemen beating rocks together; they are at least as competent and technically advanced as Russian organized crime syndicates (in fact, my hunch is that NK hired Russian hackers to either train their people or carry out the attacks).
> 3. The amount of data, and the selection of which data gets released when, as well as the difficulty overall of the operation, says to me that multiple people were involved in the hack.
I disagree; the data released was designed to cause maximum embarrassment (and media coverage). The hack itself was not incredibly sophisticated - it's not even as complicated as the Home Depot credit card hacks, and not even remotely in the same league as something created by a skilled state actor like Stuxnet.
> A reason why it isn't North Korea: If it was ( either intentionally or accidentally ) it is in NK best interest to either claim responsibility and embrace it, or to prove they didn't do it. They have done neither. This implies that they can't prove they did or didn't do it, because nobody under NK government control was involved.
They can't outright claim they did it; because that would be an act of aggression. They left a trail of breadcrumbs long enough to tie it to them, yet still have enough plausible deniability that countries who want to believe them because they have an ulterior motive against the US can do so. For example, Russia never admitted they shot down an airliner despite damning evidence to the contrary - who you believe simply depends on what side you support for geopolitical reasons. Realpolitik at its finest.
really? a nation-state attacking a for-profit multi-national corporation with little more than embarrassing information is an "act of aggression"??
you better read up on your military history my friend.
US companies get hacked all the time...have you not been reading the internet over the past, oh, 10 years?
also, there is still big doubts that the NK's did this.
Also, my final point is rather weak and ignores the possibility that NK wanted to do it and wants to be able to deny they did it also.
I still doubt it is NK for many different reasons. Another one to throw on the pile is due to the threats of violence if the movie is released. Terrorists don't threaten and then back off, they simply commit the actions without giving you a chance to stop. Eg: If it was NK, they would say "In return for creating this movie, we are going to do X". Of what benefit is it to NK to not deliver on their threats?
Is it established at this point in time how the entire attack was accomplished and exactly what taken was taken? I think not. Avoiding detection for so long while actively exploiting a system is no small thing.
I don't doubt that the attack could have been done by NK, in fact it is likely that it was funded by NK. What I doubt is that it was done ( the actual hackers ) by anyone who agrees with NK politics. This seems strongly to me like work for hire by digital mercenaries. Whoever did it seems to be just following instructions rather than thinking. Eg: Go steal all their data and dump it to the world.
As others have pointed out, there are many other more selfish things that could have been done with the data than dumping it to the world.
And the method of attack has been pretty well established: they somehow obtained access to the network (likely by buying stolen credentials off the black market) and used some 0-day exploits (also likely purchased off the black market) to gain access to core IT systems. They then figured out where the data was, hauled it off over a weekend, then pushed out malware over NetBIOS that wiped the PCs.
And it's not about being selfish: it's about North Korea improving their standing in the world political order through a show of force. Realpolitik is the way international politics works: morality and truth go out the window, and it's purely about who has power and the will to wield it. By staying in the news, NK is controlling the US media cycle in the same way that an invasion of Ukraine does. In fact, there's probably been more discussion of this hack than of the Ukraine conflict, so I'd say it accomplished its goal.
I'm not following. Taking responsibility would mean a massive violation of international and domestic laws and probably more sanctions. It would shame Chinese leadership, yet again, that their vassal state is a reckless danger to the world.
Disproving its not them is kinda tricky. What data has been shared with them. How could you really disprove anything?
The only way to prove they didn't do it would be by having someone under their control involved in doing it?
That is, the best NK could do to prove they aren't to blame is by outing someone within and claiming it wasn't an operation condoned at higher levels.
It would be a win win for them then. They can say "yeah we hate the movie and dislike the US. Yes we told some people to try and hack and shame the US. No we didn't know or approve of them accomplishing it by trying to ruin SPE." They could avoid starting a war that way, but still gain "credit". Also they would look good by publicly saying "yeah this was bad; we would never officially approve of what was done".
My question back; if they weren't involved, how could they possibly prove they didn't do it?
Then you have all the movies and tv series, which, without any hint of irony, show "spies" and the like from such countries, operating in the US (and with full teams and equipment), even infiltrating the secret agencies and such.
So you have uneducated people from rural fly-over country that cannot even pin-point Germany on the map, believe what they see in those series, not as an actual fact, but as something that could potentially happen or is credible. (Just imagine what the kind of people who think evolution is bad for school curriculum believe about foreign countries).
To convey the BS-detection levels a European feels, consider a report were Inuits are the major threat and Inuit operatives are preparing an attack on the US, hacking networks, and the like... Or maybe Mexico, or Canada... (This BS doesn't work as well when it's about a place you know, that you might have visited and that's close to home, right? Whereas anybody can imagine any kind of BS for some remote third world place with 1/1000 the resources).
(Of course there are people that watch non-ironic action movies were the President bare-handedly fights the bad guys http://en.wikipedia.org/wiki/Air_Force_One_%28film%29#Plot !!! We might watch them for the special fx and action scenes in Europe, but we call them typical hollywood BS and use huge tons of irony about them).
Homeland was pretty subversive in its first season, I mean, up until Brody decided not to blow himself and the rest of the high-ranking officials up in that bunker it was a pretty bleak affair: a decorated US marine, now a politician, who decides to kill the VP of the United States and a couple of other generals, you don't usually get that in block-busters. Afterwards, and especially starting with season 2, it did indeed become a propaganda thingie.
Otherwise you're completely spot on. As a film junkie it really bothers me that our generation doesn't have its "Apocalypse Now", "The Deer Hunter" or "Rambo I - First Blood" (whose director has just been interviewed in the latest Cahiers du Cinema issue), it's all white-washed, depressing propaganda. There are a few exceptions here and there (De Palma's "Redacted", Bigelow's "The Hurt Locker", partially), but otherwise we're treated not as adults, but as kids who need to be told "nice" stories about what's really happening around us.
The US hasn't been "weak" compared to anything since the USSR collapsed, and probably not even when it existed.
The US shown as "weak, disjointed, and behind the ball" is the classic tactic to show that some lame figure is a "credible enemy", so that any pre-emptive attack or move is justified -- since we're talking about "capable enemies" that could really damage the country.
It's akin to putting a gun on the hands of some black kid the police shot, to make him look more threatening that he was.
Except it's an established fact that North Korea has considerable cyberwarfare capabilities, nothing that needs to be fabricated either with this hacking or in pop culture.
Who would do this and for what reason? The CIA can be batshit insane, but nobody ever would sign off on making millions in damage to a movie company to make an already evil country look more evil.
Your post is 90% "murricans are dumb" and 10% baseless accusations.
This also from a non-American.
Any interesting and credible literature on the subject, you can suggest ?
This is probably the most complete report available to the public for easy download.
Then just a few hours later the New York Times came out with an article claiming that they have information from some Washington sources that it has been confirmed to be North Korea. I checked the author bylines, because Judith Miller and the NYTimes, and David E Sanger I could see being politically motivated to make a case like that on some pretty flimsy evidence, but Nicole Perlroth has good tech journalist creds.
So, I dunno. Looks like it might be North Korea after all.
At the moment, I figure there are three scenarios, and none of them are really wonderful to think about:
1. It's China, working through or with North Korea. They certainly have the ability (and in some cases, insider information), and they've been waging a network and technology-based conflict around the world for years now. But, in the past, they've been carefully diplomatic about managing relations between North Korea and the rest of the world; it doesn't make sense for them to suddenly paint a huge target on NK's back, and China's past exploits have been kept pretty quiet. I don't understand why they'd want this one to be big and public.
2. It actually is North Korea. We've been led to believe that they exist in a technological dark ages of sorts, with most of their infrastructure relying on technology that would horrify the average HN user. They're certainly belligerent enough, but now suddenly we find that they have not just the technology to pull it off, but also the talent? How does that kind of talent even develop under a strictly regimented government like North Korea's? What kind of ability do they actually have?
3. It's neither North Korea nor China. This is the most disturbing one to think about; now that the NYTimes and Washington are involved, it smells a bit like the kind of political maneuver with propaganda that we saw in the run-up to the Iraq war. At the moment, this is still really feasible, and it makes me wonder what Washington's motives might be.
Only time will tell for sure, I guess. Whoever is actually behind this, they won't be able to stay quiet forever.
See, this really isn't the case, and why most people believe this is beyond me, when a google search would suffice. I'm not criticizing you, actually, just pointing out that there's an incredible amount of misinformation out there about North Korea. Look at these photographs of a technology trade fair in Pyongyang this summer, for example:
http://www.northkoreatech.org/2014/06/23/another-look-at-the...
Most telling, IMO, is that a 32G usb is being sold for USD20, where at the time of writing, the same product was nearly USD16 on Amazon US. That's a remarkably low markup for a product, especially for one in North Korea. Also considering that it's a high volume, low price product with so little of a markup makes me think that other technologies must be very available and accessible, and that NK is hardly the technological dark ages that popular discussion has us think it is.
Of course, this all isn't to say that NK performed the hack, but I hardly think that a lack of infrastructure would really be the barrier if North Korea really wanted to train a cadre of hackers.
a) for people in the higher echelons of the party that are paid more (and might still be expensive to them), e.g. a 1% of the population
b) BS organised to give the impression that they are not behind, while in reality nobody can afford those, and the buyers are "actors".
Pretty much all of the very little I know about North Korea comes from articles like http://www.theatlantic.com/infocus/2012/04/glimpses-of-human... (e.g. #17 @ http://www.theatlantic.com/infocus/2012/04/glimpses-of-human...). Or http://www.asianscientist.com/2012/12/topnews/dprk-north-kor... -- that, plus the lights-out situation at night, plus their previous difficulties with rocket technology and their impoverishment, altogether gave me the impression that they're a couple decades behind other developed nations, technologically.
I always figured at least a little of that was propaganda of sorts, but there was also the occasional "I visited DPRK and took these surreptitious shots of what I saw" article that seemed to substantiate it.
Edit: also what camperbob said.
They've done this -- they have an elite military-hacker unit called Bureau 121 of about 1800 people, as described by a defector in a recent Reuters story I quote in my comment above:
They have very publicly show capability to launch long to medium range ballistic missiles and they have an active nuclear weapons program. I'm not directing this at your entirely, but I'm surprised how many people thing don't believe they lack the technical capacity for computer warfare.
What they do lack, apparently, is the ability to run a country that's not an oppressive shit hole.
[1] http://h30499.www3.hp.com/hpeb/attachments/hpeb/off-by-on-so...
Why do you think that? I don't see any reason to believe that based on my albeit superficial search so far.. In fact though, I see oddly coincidental and potentially biased 'creds' in her LinkedIn profile, etc. ('Her 2014 Times profile of security blogger Brian Krebs has been optioned by Sony Pictures.' https://www.linkedin.com/in/nicoleperlroth ).
Genuinely curious though if she is unbiased or if maybe she should be checked against.
I also try to be careful not to dig too deeply into the backgrounds of people writing articles I disagree with. Seems like a dishonest thing to do.
With regard to point 2, remember that this is the country that built a nuclear weapon and launched an object into orbit (with some dramatic difficulties on the way). If the NK government wants to get something done, especially something militaristically, they do it.
Seems far fetched as North Korean hackers are about as far away as you can get from US influence and power.
The concern that they'd state would be local hackers working for or with those elsewhere for what-ever reason (payment, disenfranchisement with local policies, ...) or just doing it "for the lols".
The potential knee-jerk hardening of laws in response to this sort of thing is not specific to this case: it could equally happen in response to any other very public exploit. The same for the more insidious "we've been waiting for an excuse to..." hardening of laws, for a more paranoid view.
Also note that CISPA passed the House this summer but failed in the Senate. Guess who takes over the Senate next year?
"North Korea is even angrier, and very shaken that a retired Chinese general said publically that China would not come to the aid of the current North Korean government if the government collapses or starts a war. China often makes official announcements via public 'comments' by retired senior government or military officials. This makes it easier to, if need be, back off from the new policy. China has not backed off this one. China is telling North Korea to do what China wants or else.
China wants work on North Korean nuclear weapons stopped. China apparently promised to be useful in the UN if North Korea resumed the six nation talks over North Korean nuclear weapons."
> Lets not forget also that it is trivial to change the language/locale of a computer before compiling code on it.
Here's something I am curious about: if this was NK and it is in response to The Interview, how did they get so deep so quickly? Other state sponsored hacks seem to span multiple years with multiple iterative hacks that get deeper into the target, but The Interview only wrapped shooting a year ago and wasn't really publicly known until mid 2013.
So sure, that's not done by North Korean hackers, but it's not excluded that it involves North Korean money.
I guess a strong clue will be to see if Sony's nightmares calm down after they've scrapped the Interview, as allegedly expected by the hacker. I'd rather bet on a bounty hunting follow-up, _a la_ 419Eater, which I confess I'd find extremely entertaining.
That's civilian; the military is a whole 'nother story:
From a Reuters story about the Sony hack [0]:
Military hackers are among the most talented, and rewarded, people in North Korea, handpicked and trained from as young as 17, said Jang Se-yul, who studied with them at North Korea's military college for computer science, or the University of Automation, before defecting to the South six years ago.
Speaking to Reuters in Seoul, he said the Bureau 121 unit comprises about 1,800 cyber-warriors, and is considered the elite of the military.
"For them, the strongest weapon is cyber. In North Korea, it’s called the Secret War," Jang said.
One of his friends works in an overseas team of the unit, and is ostensibly an employee of a North Korean trading firm, Jang said. Back home, the friend and his family have been given a large state-allocated apartment in an upscale part of Pyongyang, Jang said.
[0] http://www.reuters.com/article/2014/12/05/us-sony-cybersecur...
NK has made their own Linux distribution, and they made nuclear bombs. Being able to hack isn't out of the question.
In my experience, nobody takes DLP seriously, except maybe [some] government. It's more of a "At least we know about this issue; nobody feels like dealing with it, so just flag it and continue as normal." In fact, almost all DLP and similar systems i've seen were intended to only record violations so they have evidence to litigate with later.
> It’s clear from the leaked data that Sony has a culture which doesn’t take security very seriously. From plaintext password files, to using “password” as the password in business critical certificates, through to just the shear volume of aging unclassified yet highly sensitive data left out in the open. This isn’t a simple slip-up or a “weak link in the chain” – this is a serious organization-wide failure to implement anything like a reasonable security architecture.
This is all large organizations. All of them. As one previous manager so eloquently put it: "There are too many security violations for us to fix; all we can do is prioritize and go after the biggest fish." The only places that take security seriously are places that hire BOFH-quality security nazi managers.
> Who do I think is behind this? My money is on a disgruntled (possibly ex) employee of Sony.
Or a contractor (e.g. Snowden)
In general, in the numerous discussions I've read so far, people are much more focused on this breech itself, not on the root causes nor how to prevent these types of breeches in the future.
While I don't doubt North Korea's technical ability I sincerely doubt this is a real motive to attack Sony. Something screams ex-contractor to me and planting evidence to come from NK seems like a plausible avenue to avoid being caught.
If anyone wants to learn anything from this: don't use P@ssword1 as a password. If you've got that down, you're already better than the Sony studio.
This smells as fishy as it gets.
It's odd how the epic Sony Playstation Network hack from a few years back doesn't get discussed much in relation to the current hack. A signature of lulzsec strategy from that era was the staging of information gained from one intrusion to go deeper. So the passwords and information found through one intrusion was utilized to span out and find intrusion into other networks, in other companies or institutions. And this fermentation process before the release of hacks was in the order of months or longer. We know from that episode that Sony's network was penetrated deep. It would be foolish to not consider if much of that information didn't remain "in play" for future staging. But it seems everyone (meaning the FBI and Sony, the stakeholders in the prior attack) thought the case was closed when Lulzsec was no more.
If I am right (and it is really not clear that I am), and the data from the Playstation Network hack was at play, then there are two very interesting things to note: 1. the attackers chose to devoid themselves of even the anonymous brand. Action without brand takes intrusion as protest to a whole new level. 2. The FBI's official finger pointing to north korea shows how far behind they are in adapting to the new world and makes me wonder what future trolling still await us.
North Korea has repeatedly threatened nuclear war over the most banal thing. Of course it is usually treated rather lightly, but the country does have nuclear weapons.
The film and television industry is in the business of suspending disbelief. And they are no more immune to believing their own BS than any other industry.
I have no trouble believing that studios and theater chains think themselves to be so important that nations would go to war over them. As a whole, they are the least closely connected to reality of any business sector that I know about.
If Best Korea didn't retaliate over Team America: World Police, I think The Interview is probably safe.
http://www.laweekly.com/publicspectacle/2014/12/17/pulling-t...
"The truth is, America's commitment to free speech is dwarfed by our commitment to capitalism. Seth Rogen can stand in his house and say anything he wants about Kim Jong-un – but Sony has the choice to fund him, and even if it agrees, AMC can still pull the plug. The corporation, not the individual, has always had the power to decide what movie is a thoughtcrime. We're just only now visibly seeing the suits flex their clout. Despite everything, Pascal at least had the courage to greenlight a comedy about a sitting dictator. Will she be the last studio boss who can make that claim?"
I wouldn't be surprised if it turns out that the hacks or threats weren't conducted by NK, or by NK alone. This movie is in fact a threat to a particular regime in NK, but it's also a blanket threat against all totalitarian regimes (and corporations), and there are plenty that would be upset about that.
I've been scouring Hollywood for movies that appeal to mass social, political, or economic change that don't portray the instigators as crazed violent goonies. There are none in recent memory. The ones that do strike a chord become wild blockbuster hits and their motifs enter our collective consciousness as light-sabres or guy fawkes masks, but they are the rare ones. You don't find much of them in Hollywood because Hollywood does not instigate change.
It's a movie. It's a comedy. It has Seth Rogan.
Have you ever seen any of the writings on the walls in NK or speeches by their politicals?
Imagine what would happen if a likable character who isn't a crazed terrorist assassinated a political figure on the big screen and became a hero. Good feels all around, nothing wrong with killing a totalitarian leader, right?
[1] https://en.wikipedia.org/wiki/1993_World_Trade_Center_bombin...
A note: just because there aren't brutal violations of human rights in a country it does not mean people aren't fed misinformation and propaganda campaigns. This whole NK ordeal seems like something Goebbels couldn't ever dream of.
European countries, too, though to be fair most of their brutal violations of human rights tend to be through aiding the USA in setting up secret torture prisons and ferrying people to them.
https://webcache.googleusercontent.com/search?q=cache:https%...
Well, I think that's STUPID to say.
Many are saying it could be some teenagers somewhere in a basement that pulled this off. And guess what? A nation with 300 million is capable of getting people around some computers to hack. They can develop nukes (or claim to have) and develop short range ballistic missiles. If they are capable of it, they are capable of pulling something off that some teens in a basement do all the time.
And N Korea will do anything to protect the image/status of its fat leader.
In a sense, nothing to see, move on. It's only N Korea.
It's only the stupidity of the leadership at Sony that we underestimated, not keeping up security and then laughable response.
They gave up the right of free speech.
And we are the only nation that's codified AND that's been practicing it for hundreds of years.
Oh wait, Sony is owned by Japan... Must be especially sweet for N Korea, kneeling US and Japan with one hit.
http://www.nbcnews.com/news/world/north-korea-behind-sony-ha...
http://www.usatoday.com/story/news/world/2014/12/17/north-ko...
Expect new laws and regulations. Expect the public opinion to be against "hackers", "encryption", "privacy" and all that shit, etc
I have to say I find point 1 borderline offensive, that the English basically isn't bad enough to be authentic "Konglish". It can't have been written by North Koreans unless you see comprehension mistakes! Does the author know that perhaps counterintuitively, English is the most widely taught foreign language in North Korea? Or is he familiar with the barrage of English-language propaganda put out by the North Korean regime?
I wouldn't describe it as "broken English" either. Stilted and unlikely to have been produced by a complete native speaker, yes (e.g. old-fashioned English subjunctive in "our request be met"), but not ungrammatical. I have no particular trouble believing that it is an earnest attempt by a non-native speaker to write correct English.
Point 2 is the weakest. I have no idea where the author got the notion of North Koreans speaking their own dialects and traditional Korean being forbidden. Korean like any language has regional dialects in both North and South Korea, but the language itself was standardized before the division of the peninsula based on the Central dialect region around Seoul. This dialect region is split between the North and South so that for example the speech in Kaesong, North Korea is similar to the speech in Seoul, but Pyongyang falls outside this and falls into a different dialect region. Nevertheless, because Standard Korean was established before the division, the standard speech in North Korea is also based on the Central dialect. The Standard Korean spoken by someone from the North is not as different from what you would hear from someone from the South as one might imagine, as South Koreans may verify by watching a North Korean news broadcast. There are of course differences in orthography and vocabulary similar to what you would find between the UK and US in English (thus the "helicopter" example supplied by the author), but this has more to do with a natural divergence of the language after decades of forced separation than anything.
The closest thing I can think of to the notion of traditional Korean being forbidden is that North Korea banned Chinese characters from official writing right away, while South Korea didn't go as far but still eliminated Chinese characters from texts used in education. Korean has its own alphabet, but Classical Chinese was the traditional literary language, and Sino-Korean vocabulary (words derived from Classical Chinese) were often written in Chinese characters in a "mixed-script" style reminiscent of Japanese. In both Koreas, the end result was that Korean came to be written purely in the Korean alphabet. In South Korea this was gradual as the mixed-script style held on for a few decades, but by now most South Koreans have been educated writing only using the Korean alphabet. At any rate, Koreans wouldn't be using Chinese characters on computers anyway, North or South, so this is an irrelevant historical detail by now.
What does the author mean by saying that "the code was written on a PC with Korean locale & language"? That the actual coding was done in Korean? What kind of programming language used by hackers is in Korean? I am not familiar with the details of the Sony case so I would like to be enlightened on what the author actually means here.
It is probably the case that the most common encoding is ASCII, with the most common modern encoding being UTF-8. If you're writing code you don't want traced to a particular language, use ASCII.
You would only need a separate encoding if you were going to be writing the code with special characters. In this case a Korean encoding would only be useful for comments and string literals as most computer languages are ASCII based. Since the messages from the malware are apparently in English, this seems superfluous and more like a sign of a false flag operation. In this context, setting a Korean locale is an unnecessary and ill-advised step that would normally force you to go out of your way to get right.
Wikipedia has more specific information regarding Korean language encodings: http://en.wikipedia.org/wiki/Korean_language_and_computers
“In the file we had a line with broken characters. Those characters didn’t render right under any encoding, except EUC-CN [Chinese] and EUC-KR [Korean] … In this case, the readme.txt file could be read fine under either EUC-CN and EUC-KR, which means the file was most likely generated from a computer set in either Chinese or Korean – or the hacker deliberately converted the file (which seems unlikely),” Karpeles said.
I should add that EUC-KR is a South Korean legacy character encoding, but the corresponding North Korean encoding (EUC-KP?) is hardly ever supported so in practice North Koreans would be likely to use EUC-KR.
But Russia really really doesn't like us and has nothing to lose with trade, etc.
Hypothetically, this is occurring right now, and is less traceable, less newsworthy, and more effective than a loud public attack on a major multinational company. Hypothetically, I could probably keep it up for years before anybody noticed.