On the other hand, this strikes me as totally within the realm of possibility for North Korea. They have the skills, they don't really give a shit about pissing off Sony or the FBI, and they have motive.
On the other hand, this strikes me as totally within the realm of possibility for North Korea. They have the skills, they don't really give a shit about pissing off Sony or the FBI, and they have motive.
Hollywood is famous for screwing people over, so I doubt there is a deficiency in people with grudges. Suppose one of those people were willing to spend $50k on this? Suppose they had a friend or a second cousin with a connection to some people with skills and a taste for large-scale lulz?
Disgruntled (usually ex-) employees have been known to do some pretty insane, destructive things, without appropriate regard for personal consequences. What was the name of that guy who locked his ex-employer out of their infrastructure and caused a big rumpus a few years ago, again? More to the point - we know that there exist people who are capable of walking into their workplace with an assault rifle; the existence of a person inclined to execute the attack on Sony should not be surprising.
That's why it doesn't make sense as North Korea. Their accepted motive goes as far as THE INTERVIEW, which was dodgy-enough to begin with, but which has already been shelved. Why would North Korea be threatening to release more information if their goals were already met?
Ignoring the rhetoric, the actions here looks much more like garden-variety data-ransom. If "their demands" were "x-million USD, don't contact the feds", then everything makes sense. Wiping the data. Only mentioning THE INTERVIEW after the press seized on it (misdirection and increased pressure on Sony). Actively promoting the tastiest bits of leaked data to the press. Releasing more as further deadlines pass without some unnamed capitulation (that's larger/different than simply shelving THE INTERVIEW). Having The Big Bad Deadline for a large future release.
That the US Government is publicly on-board with the DPRK theory also doesn't fit an actual "hack by North Korea" situation. The US Government gains nothing by naming perps, which is why they almost never do it, not even after the consensus opinion of third-party researchers makes an inescapable conclusion. If the perpetrators actually were North Korea, the US government would stand to lose more than most times, as we're currently trying to lure the DPRK back to the six-party talks. (A subject much larger than Sony Entertainment.)
That attribution would make perfect sense if the government is coordinating with Sony, but has to try to convince the hackers they aren't involved/competent/two-hops-away, etc. Given how cozy the US press is with the US government, I wouldn't be surprised if they were knowingly pushing the "it's totally North Korea" angle in the service of the investigation.
They are not. You are working off of outdated information: http://gizmodo.com/sony-hackers-thanks-for-running-scared-we...
(As an aside, if anyone wants to make a friendly wager, I'd bet up 3 BTC on the fact that this is indeed a NK attack, so long as we can agree on some sort of reasonable time period and way to confirm, such as an arrest or confession. Either payment to the winner, or payment to the winner's designated charity. Is there a site that allows for committing to BTC bets with some sort of escrow or multi-sig release feature? If not, there should be.)
I'm not saying that the DPRK couldn't do it, only that no proof has been offered that they did. Given the lack of proof, assigning blame to anyone is premature.
Parenthetically, it is amusing to me that the accepted narrative has so quickly become that NK definitely did it.
http://variety.com/2014/biz/news/sony-cuts-over-70-jobs-more...
As I see it, after the three (if Im not mistaken) last successful attacks at Sony, I wouldn't say they're skilled _enough_. Not even skilled basically.
Again, as I see it, it's Sony's fault: after the first attack at playstation network, the least they could do is stop using plaintext files to store passwords.
But no. Second attack with the same results and now a third.
So no. They're not even close to be characterized as skilled (and that goes especially for the managers/whoever did not decide to leave the I-store-passwords-as-plaintext practice).
>be skilled enough to evade the FBI, but still somehow be stuck in some mid-tier Sony IT gig.
Skill (whatever that is) has very little to do with how successful you are at your job and/or which company you are working at.