Update on Sony Investigation
fbi.gov
fbi.gov
I'm disappointed by the lack of evidence given by the FBI and other departments investigating the attack that directly tie the incident to a specific government or group of non-state actors. Many well-known security professionals have given opinions contrary of the FBI's findings, stating that it's not only difficult to determine the source of the attack but also incredibly dangerous to attribute the attack to a specific government given so little direct evidence.
There are so many aspects to this story that don't add up, but most strikingly, the press's push to point the finger squarely at North Korea for all this.
Normally the FBI would want to see monetary loss of e.g. $50k (arbitrary number I just chose) before they start caring, so your credit card probably isn't going to cut it.
...who are pandering to a crowd, and based upon essentially no information at all, but just the same sort of "I think" gut feeling notions that we see on HN. While there should always be questions about government honesty, it's rather incredible how far people will reach to find to clutch onto something that backs whatever their initial knee-jerk opinion was, seen throughout the comments here.
Quite a few comments are among the "they're making this up to go to war", which is simply incredible: Are people so far out of the loop on world players or current events? The US in no universe will launch a military action against a rogue, shells-pointed-at-Seoul, nuclear armed nation because they hacked Sony. That premise alone is simply absurd.
Is the US trying to isolate North Korea? They're already completely isolated. I mean...do people understand the situation North Korea is in, and the complete lack of tools to deal with this? The US gains literally nothing pointing the finger at North Korea.
literally nobody has said that, all that most people have said is that if you're going to accuse another nation of an act of "cyberwar" at least provide proof. Is that too much to ask?
Literally quite literally doesn't mean what you apparently think it means.
And the general conspiratorial narrative is that the US is trying to blame a blameless North Korea to achieve...something. Not sure what.
To assume the US Government's PR team won't use anything/everything to reinforce, reiterate or bolster it's own agenda is just idiocy. There are far too many examples throughout history where it has.
Whether or not that means that this investigation is a farce, is another question.
Its not like the US has to manufacturer an excuse to complain about them. There is an abundance of genuine North Korean antics to choose from if they want to.
The people who comment on HN about politics are hilariously confused.
It also loses nothing, which might be the case if Russia or China were behind the attacks.
It's much easier to address public fears with an easy scapegoat than to owe up to the overall frailty of network-driven industry. Could you imagine the cost of creating "the TSA of networks belonging to important private entities?"
What is the equilibrium in a world where state funded actors can anonymously attack major companies / infrastructure components? I am not convinced that is possible for a Sony to secure itself to such a level that it will not be vulnerable to attacks by state actors.
Sounds like a huge bounty for whoever gets the contract.
They're more of an annoyance than anything else. The strategy so far seems to have been to wait it out and hope their crazy cult-regime finally collapses. I don't see any reason anyone would want to expedite this unless they thought there was a clear and present danger of NK escalating in both belligerence and power in the near future. I can imagine the former, but not the latter.
The Korean War was in many ways similar to a "more power" version of Ukraine today.
Plus their prison camp system, internal mass famines, brutal authoritarian dictatorship.
I obviously don't know the story behind this. The point is, there are plenty of opportunistic and self-serving domestic interests who probably don't either but can nevertheless turn this hack into a very beneficial event, regardless of who did it. From their perspective, NK being the source is actually the best-case scenario.
It matters little because the big issue here is that a group of cyber terrorists have effectively shut down a major corporation and most western countries are just standing by. if that is not green lighting future copy catting nothing I don't know what is.
The President should screen the film at the White House and allow it to be distributed to the armed forces
Is that your gut feeling? :p I understand it's backed by strong arguments but so were (some) security professionals opinion. They might give updates after the FBI's communiqué and are aware of the limitations of their argumentation. That being said I do share your opinion on the matter...
EDIT: elaborating... EDIT 2: Not sure why I'm getting downvoted. No matter how much I believe US won't go to war there is always a possibility I could be proven wrong. I don't think security professionals analysis was based on "no information at all" (think things we know about North Korea), no more than the analysis we have about US not going to war.
Even if it wasn't North Korea, the U.S. still gains nothing from this except for maybe making NK look even worse.
And the U.S. might make some stupid political decisions, but there's a difference "ill advised" decision and a flat-out stupid decision. Going to war with NK would mean South Korea getting attacked by NK. Would the U.S. risk that?
I honestly do not think so, because it'd signal the end of the U.S.' diminishing credibility in the global sphere. Nobody wants to be friends with a country who'd willingly throw a friend under the bus simply because another country (which has very few friends) hacked into one of millions of corporations in said country.
If the U.S. and USSR could go years without nuking each other, I believe the U.S. has enough restraint to not launch (enough of) an attack on NK that would provoke a NK response towards their southern neighbors.
The US gains quite a lot by pointing fingers at a bad guy. This bad guy happens to be North Korea. Anything just to keep the public distracted and the media happy to report something else but CIA torture.
References?
What I remember is a well-argued article pointing to many parts of the hack that would seem to disqualify North Korea - for example the use of a (South) Korean language locale which North Koreans would in fact not normally be able or likely to use, broken English with little relation to how North Koreans would speak, etc.
Now, North Korean could be making a careful effort to impersonate Western hackers making a crude effort to impersonate North Koreans. But that's kind of reaching and there's a bit more than no evidence.
That article was a classic case of "assume the end result, and then make everything you've heard...including indirect, second-hand rumors, fit the mold you've set". You probably saw that "analysis" on here, and it was quite soundly destroyed as being largely ignorant.
https://news.ycombinator.com/item?id=8766411
But it went with them because it fits the case.
Further the whole "that bad English doesn't fit how I think bad English should look" is...well it's preposterous. The article also uses a ridiculous email exchange which could be anyone as proof -- again, fitting the mold.
There is literally nothing in that, beyond some person's subjective take on how a person might mangle English (this is one of those classic claims that assumes some grand conspiracy...but that the conspirators were too dumb to get the basic stuff right), that is based upon legitimate analysis.
They want to point at a country that will say "damn straight we did it" even if they didn't (North Korea is perfect!)
There have been attacks on the US government IT infrastructure. Stolen designs and files from military contractors. Attacks on energy and distribution systems. Attacks on the banking system.
On the grand hierarchy of attacks, this is really, really low. I mean, given the severity and regularity of attacks against things that really, really matter, no the US certainly didn't need this to justify anything. The concern is very real, and significantly more important than some Sony Entertainment emails or movie leaks.
Most posters on hackers news, it seems, rejected the idea that the Sony hack was done by North Korea or any easily determined actor.
The US government now has an official conspiracy, that the attack was the work of the government of North Korea. Just because that is conspiracy theory doesn't make it wrong but I and many people still doubt it.
You are replying to an attack on the common dubiousness of many hn posters to the North Korea theory. The attack seems to involve the idea that doubting the US government conspiracy theory has to be, itself, some other kind of more dubious conspiracy theory, when it is actually the belief that there's no evidence in that direction and plenty of evidence away from that direction.
I agree that it is absurd, but Washington seems to be talking up that premise.
Obama Vows a Response To Cyberattack on Sony
WASHINGTON — President Obama said on Friday that the United States “will respond proportionally” against North Korea for its destructive cyberattacks on Sony Pictures, but he criticized the Hollywood studio for giving in to intimidation when it withdrew “The Interview,” the satirical movie that provoked the attacks, before it opened.
Deliberately avoiding specific discussion of what kind of steps he was planning against the reclusive nuclear-armed state, Mr. Obama said that the response would come “in a place and time and manner that we choose.” Speaking at a White House news conference before leaving for Hawaii for a two-week vacation, he said American officials “have been working up a range of options” that he said have not yet been presented to him.
http://www.nytimes.com/2014/12/20/world/fbi-accuses-north-ko...
One thing I would like to know, is if this whole thing was perpetrated by the North Korean state because of the potential offence to North Korea from showing their leader being killed, why has the scene of their leader being killed been leaked by the hackers and is now posted all over reddit? That really makes very little sense.
I continue to be blown away by Hacker News' collective refusal to believe that NK is likely behind this hack. Do you all also doubt that they were behind the other hacks mentioned by the FBI (e.g. on South Korean banks and media outlets)? Is it 'incredibly dangerous' to accuse them of that as well?
I understand the post-Iraq mentality of demanding evidence before going to war with a country, but that's not what's going on here.
Also, given how mouthy North Korea is, nobody finds it telling that other than a single denial on December 7th, they've been quiet? That denial, by the way, consisted of bullshit like saying that there were “a great number of supporters and sympathizers” with North Korea “all over the world,” including “champions of peace” who might initiate more “righteous reaction” against the United States’ “evildoings.”
Skepticism is healthy and encourages discussion. I am not observing a "collective refusal" as you put it, but instead a strong skepticism from the tech community (a community who has a good basis to interpret this story with).
"Do you all also doubt that they were behind the other hacks mentioned by the FBI (e.g. on South Korean banks and media outlets)? Is it 'incredibly dangerous' to accuse them of that as well?"
The discussion is around a specific cybersecurity attack, not North Korea's capabilities, so that's a bit of a straw man argument.
"I understand the post-Iraq mentality of demanding evidence before going to war with a country, but that's not what's going on here."
No rational person is making a case for war over this, but the fact that you mention going to war over this demonstrates why it is incredibly dangerous to make these assumptions about North Korea without looking at all the available evidence.
"Also, given how mouthy North Korea is, nobody finds it telling that other than a single denial on December 7th, they've been quiet?"
Quite the opposite. I think it would fit the profile if North Korea was being mouthy at this point in time. Their silence would suggest this is a delicate situation for them politically and they don't know how to respond to it.
Actually, we don't really have a good basis to interpret the story. The evidence that the US government has used to verify that NK was involved is most likely classified. The most straightforward way to verify the NK government's involvement is a high-level NK spy, or a communications tap on NK's political leadership. If it captured a high-level meeting regarding the "progress of the Sony hack," for example, then that would be pretty strong evidence of NK's involvement. Yet there's no way that any press release could include such info without also compromising their sources.
The point of the US government saying "NK is involved" is to say "We have verified NK is involved," not to give hard proof. Such proof may exist, but it may not be possible to divulge without also causing other consequences, as I mentioned above. It's not a trial, and they're under no obligation to present any of their core evidence or reasoning. It's up to us whether we choose to believe them or not.
The tech community sometimes overestimates how informed it is. For example, consider how someone would be viewed by the tech community if they claimed that governments were writing BIOS malware, and they made that claim before 2013.
So it seems mistaken to believe that the tech community is any better suited to interpret the story than any other community. Various intelligence communities or politics communities might even be better suited than we are at figuring out reasons why the story shouldn't be taken at face value, if any such reasons even exist.
Has there been a poll or are you just making that up?
Most of human beings are "belief oriented” which is the result of hundreds of thousands of years’ evolution. It’s the cause of most conflicts in the world. The widely supported Iraq war is an example. That’s why it is dangerous to do so.
In hacker news community, there are more “evidence oriented” post-modern people. This makes a difference.
Any discussion about Uber, or the evils of traditional capitalism (especially HFT) on here is full of distinctly belief driven people.
HFT is the easiest, it provides liquidity, helps to keep spreads narrow, flash crashes are nasty, but so rare there have been only 2 (and the cost of those was minimal, a few failed margin calls, oh noes).
Uber is tricky, because it's run by assholes, but that's not really different from the taxi (cab) industry in most cities. Plus they skirt the law, which was largely instituted to protect the interests of the incumbent taxi companies. It arguably helps to make the taxi market healthier, thanks to its increased efficiency, lower prices (larger supply), which leads to a bigger overall market, which likely leads to better relative wage for drivers. The potential negative externality happens when demand dries up, drivers are forced out of the market pretty fast, due to the more efficient pricing they must apply (or lose market share). And of course, Uber has competition Lyft (in the US) and Wundercar (in Europe) comes to mind.
And on traditional capitalism, the simple truth is that it's inescapable. People are locally rational, they have limited information, and oftentimes they have utility function that are non-optimal even locally, but they are rational nonetheless, and again, people are price sensitive. So capitalism is just the machine of progress that seeks more efficient allocation of capital. And even if you do away with property ownership (and try to opt for a temporary property possession model) you'll find that other types of capital still remain, they just get more perversely important (human capital, who knows who's who, influence, reputation, use of force, and so on).
And you can see that for these inferences you need evidence, but these are not single instance based cases like the Sony hack. It's much more sound and safe to trust and act upon these aggregates, than upon a single FBI "post" and the resulting drama.
On a related note, I discovered that many Americans have no ideas of the tremendous role of Russia in WWII, it has been completely erased from US collective memory the only thing that's left in popular US memory is USSR, communism is bad (and I'm pretty sure the details of why are blurry), and Russia can only be evil.
They are now painting other targets that way, like Iran, NK, and they used the same propaganda against Iraq. I guess they don't know (and acknowledge and take part of the responsibility for) the role of the US in creating the current situation in Korea.
There is a real lack of a measured and intellectual discourse in US public space (and by radiating influence, it's crushing it in the rest of the world).
Maybe you're looking in the wrong place.
Honestly, yours is truly a superficial, fake-sophisticate straw man, devoid of facts or information and pandering to the most simplistic anti-American tropes. I was happy to ignore it, but this caught my eye:
> I guess they don't know (and acknowledge and take part of the responsibility for) the role of the US in creating the current situation in Korea.
I'm curious what you mean by that.
Oh we have. http://en.m.wikipedia.org/wiki/Rape_during_the_occupation_of...
I quote: "Female deaths in connection with rapes in Germany are estimated to 240,000". Stalin himself had to ask them to be more gentle, what an irony from such a horrible person.
Besides, Russia was on the side of Hitler until Hitler betrayed it. It's not like they chose to be on the same side as US and democracy and freedom for the last year of WWII, it was the definition of "coincidence".
Anecdotal here - my mother's mother (an Austrian of Jewish descent) had to dress up as an old woman to avoid being raped in the Russian quarter of Vienna.
Russians were notorious for this, so my father (an Englishman) was welcomed with relatively open arms, as the English were known to them as gentlemen less likely to brutalise women.
If remembering and describing a country's past is only remembering the worst without any nuance, why would anyone remember the U.S. for any positive thing? Or maybe the torture by the CIA or the 100000 deaths in Iraq doesn't erase the helping others in WWII and we have to live in a complex world where nothing is really black or white. just try to remember salient Facts, not rewrite history. And some countries could benefit from learning to say: "we're sorry", more than to say:"we're awesome" (that's valid for the 2 bullies of the other 200 countries).
On the NK situation, crossing the 38th parallel during the counter attack without having the means for a complete military victory and occupation just helped polarize everything. And now we can link the 2: invading Germany and Japan was possible because Russia agreed, invading NK was not possible because russia was against it. And this whole idea of "checking with Russia first" runs contrary to the Cold War mindset.
My guess, there are some serious, institutional-shaking smoking gun emails between media execs, lobbyists, gov't.
Official PR response of all parties presently guilty is to make as much noise about anything that's not in the data dump.
Wouldn't those be released in the SPE exec. mail dumps?
My point is that this can't be a conspiracy by Sony, because they would never leak the extremely compromising information that has been leaked. A lot of the leaked information makes them look very bad.
If you are trying to say that the movie not being leaked means the movie never existed, that doesn't make sense. If North Korea did hack Sony, they would not leak the movie because they hate the movie and don't want anyone to see it. If a group of other hackers hacked Sony and are pretending to be North Korea (compiling code on computers with the Korean language), then they wouldn't leak the movie because North Korea wouldn't leak it and they are pretending to be North Korea.
Details about who's attached to a project as a star/director, or senior technician are easily available through trade newspapers and industry newsletters. The 'packaging' of a film ('Seth Rogen to star in The Interview') is the first stage of the marketing, taking place as long as 2-3 years before release, sometimes longer. Basically the way you get a film made is this: Write the script; find some famous actors who like it; get them to sign (largely) non-binding 'letters of intent' to act in it if it manages to attract financing; call up investors (including studios) and say 'do you want to put up the money for this? It's a great script, and I've got letters of intent from Seth and James!'; proceed to the stage of writing more binding contracts once you have money in the bank.
Long story short, there has been plenty of time for NK to become aware of the film and get offended about it. By some accounts the idea was in development since the last decade but got shelved when Kim Jong-Il died.
Quite often the easiest way to identify a criminal is to look at who benefited most from the crime.
On the Internet nobody knows you're North Korea (if you're sophisticated enough).
Also, their main evidence seems to be that "they used the same hacking software as North Korea had used before - and can be found on the black market". So this is a little like some hackers buying forensics tools that can hack iPhones, the same ones the police are buying, and then saying the police hacked the celebrity nudes a few months ago.
Assuming the FBI have no reason to lie, the more interesting question is "why did the FBI make a statement mentioning North Korea at all?"
The FBI could have chosen to not name the suspect. The only reason I can come up with is that the US is trying to send a message to the world (perhaps China specifically?) that the US is irrational, and may do something crazy at any moment.
The historical precedent would be the game of brinksmanship that played out over the Cuban missile crisis. Obama just doesn't have that sheen of crazy that Eisenhower had.
I stand by the assertion that the US was trying to come off as a little crazy in the Cuban Missile Crisis.
1. The NSA is competent, and has verified that NK is responsible.
2. The NSA is competent, and is lying about whether NK is responsible.
3. The NSA is incompetent, and erroneously concluded that NK is responsible.
Since we know that the NSA is filled with highly competent people (based on the quality of the people who periodically join the commercial world after a stint at the NSA) we can probably consider 1 or 2 the most likely explanation.
Which do you believe, and why? Unless there is strong evidence, 1 seems the most likely. It's also the simplest explanation.
Also, the reason I'm talking about the NSA even though the article is talking about the FBI is because this surely falls under their umbrella, and the NSA has the most powerful tools for verifying what happened. Other agencies would seek answers from them, and the NSA's input would matter. For example, one sentence starts, "As a result of our investigation, and in close collaboration with other U.S. government departments and agencies, ..."
EDIT: Could we focus on the question? Which do you believe, and why? Please feel free to add additional scenarios, but at least mention whether you believe them and why they're likely.
IMO strong evidence is lacking to make 1 the current scenario.
There are incentives to falsely place blame on NK and there is a wealth of history demonstrating that type of behavior. In particular the US may have wanted to attack NK for some time but lacked a way to galvanize the public's support. Opportunities to get backing for war are rare, and so there is good reason to think that the government would try to capitalize on them. The fact that the government isn't releasing evidence suggests that it is weak or non-existent.
There is also good reason to believe that NK did do the hack.
Experts do many things, one of which is to occasionally make predictions, where 10% might be more reasonable.
But, for work like imagining how a given goal can be realized, I would guess an "idiot" could compose an achievable plan less than a fraction of a percent of the time.
So, they may not have even been consulted on this - or (far more likely) their contributions, if relatively inconclusive, may have been cherry-picked for only those specific points which supported a politically-convenient, face-saving conclusion. (Which, as we all know, has happened before on a few infamous occasions.)
When you have a big hammer, sometimes everything looks like a nail. When you have a database of every IP address which sends packets transiting a collection point to every other IP address suspected of being a C&C (and the NSA & GCHQ do have exactly that), everything looks like a potential controller. There is a remarkably strong bias towards false-positive confirmation caused by (amongst other things) P2P networks and UDP packets with forged IP addresses. A bias the NSA (and/or GCHQ) would warn about: a warning that, alas, law enforcement tend to not always take to heart - which is (anecdotally) partly why GCHQ rather dislike working with the plod (and quite probably the same feelings persist in the NSA towards the FBI).
I still think the links to DPRK are very weak, if they even point that way at all - not that the North Korean government aren't vile dictators (they are) but because everything I've seen makes it look more like low-rent organised crime - indeed, I gather the payload and C&Cs used, which the FBI have (IMO) erroneously used in their attribution, are publicly available (though no, I will not link to them)!
What I've seen even (albeit weakly) indicates at least two actors with different names, one of whom asked for a monetary ransom, and the latter mentioned the movie after the media did and thanked the other (for giving them access?).
It may be (but there is no strong evidence either way) that the latter is actually the DPRK - in which case their "cyber-army" looks like low-rent organised criminals, which I admit would not be implausible, but speaks volumes about Sony's stunningly negligent incompetence!
The one thing I feel absolutely confident saying is this: Sony Pictures were an extraordinarily soft target, and this was not a display of any high degree of technical competence on the part of the attackers. It could've been anyone from North Korea to a disgruntled ex-employee (of which they have no recent shortage) to some random 14-year-old angry kid, or anyone in between. My sodding cat could have hacked them. ¬_¬
Smart people make mistakes, too.
In fact, I'm not sure why competence or incompetence affects the second half of your scenarios at all.
I don't think which I believe and why matters much here, but this is a "false choice" fallacy that seems to be based on personal opinion and doesn't accurately set up the question for others to answer. I think that should be called out.
I wouldn't expect the FBI to do a thorough job on matters of digital security or cryptography, but I certainly would expect that of NSA. And therefore it seems unlikely we will be told all the evidence that they have collected in order to conclude NK is responsible.
Edit: This assumes they are telling the truth, which they might not be. But if they do honestly think NK is behind this, they certainly have a wealth of secret evidence supporting that decision.
One week after the torture report, you simply can't make this up. Then of course, you did make this up, because nobody has even mentioned the NSA.
Also, from my experience, the FBI is quite incompetent. The 'evidence' so far is, as others are pointing out, that people in NK wrote similar malware and some of the components used. Trend Micro says that the malware used is available on the black market. This points to my previous conclusion that this is being paid for.
Whether NK government is involved in funding this particular hack is the real question. I don't think NK has direct control over the hackers at this time, because as others have pointed out, it is not in NK best interest for this to continue.
It is easy to pin the blame on NK, and I think that is exactly what the hackers want to happen. Personally I think Sony simply pissed off too many people and this is the inevitable result.
The irony of this statement is this is one of the primary reasons the department of homeland security was established, so sharing of information between these very offices would enable them to be more on top of stuff like this.
No, it wasn't. Which is evidenced by the fact that neither of these entities were among those moved from other Departments into the new Department of Homeland Security.
Improved information sharing among the parts of the intelligence community that were not consolidated into the DHS is the reason that various changes in the laws governing information sharing in the IC were changed, and that the office of the Director of National Intelligence was created to separate the head of the IC from the Director of a particular agency (the CIA) in that community.
I had written a lengthy post pointing out the many pieces of evidence you're ignoring, but I think the FBI release does the job just as well. I find the infrastructure evidence as interesting, if not more interesting than the similar code:
> Technical analysis of the data deletion malware used in this attack revealed links to other malware that the FBI knows North Korean actors previously developed. For example, there were similarities in specific lines of code, encryption algorithms, data deletion methods, and compromised networks.
> The FBI also observed significant overlap between the infrastructure used in this attack and other malicious cyber activity the U.S. government has previously linked directly to North Korea. For example, the FBI discovered that several Internet protocol (IP) addresses associated with known North Korean infrastructure communicated with IP addresses that were hardcoded into the data deletion malware used in this attack.
>Separately, the tools used in the SPE attack have similarities to a cyber attack in March of last year against South Korean banks and media outlets, which was carried out by North Korea.
This also does not mention that some of the code was compiled on a machine configured with Korean language settings. This doesn't establish definitively that North Korea was behind this, but it is consistent with that conclusion.
There is also classified evidence. You may choose to ignore it, but I find the claim deserving of some (though not decisive) weight, and certainly worthy of mention.
I don't think the action was directed clearly by high level NK officials.
Consider; what if the hackers had said "We are NK, war on USA" from the very start. Would that change anything? Nope. Just because something appears to be something doesn't mean it is.
Also; why is the evidence classified? The public already has the leaked data in immense amounts... many groups already have the malware itself that was used... How about they actually show the evidence instead of just pointing fingers.
Anyone can go "yeah it's NK; they do this sort of thing".
http://marcrogers.org/2014/12/18/why-the-sony-hack-is-unlike...
BTW, the original investigation on the locale concluded that the UTF8 character could be decoded with korean or chinese locales.
The fact that the hackers were using a korean (or chinese) locale doesn't prove that the hackers were korean, but it also doesn't prove that the hackers were NOT korean, as this blogger tries to do.
It's not like North Korea's government just picks random proles and tells them to start writing malware if they want to keep receiving gruel; anyone engaged in cyber-espionage is going to have a very high security clearance and be well educated by North Korean standards. You wouldn't be surprised by the idea of a KGB officer (or FSB these days) that spoke perfect English, would you? Why is the idea that North Korean spies would be fluent in dialect/idiom of their own language so hard to swallow? I would imagine that any North Koreans engaged in cyber espionage/security has spent at least some time infiltrating South Korean social networks, to gather intelligence, disseminate subtle propaganda (as opposed to the chest-beating type put out by the official news agencies) and so forth.
I don't know if the Sony attack was carried out by NK or not, but the idea that it could not have been rests on the notion that North Koreans are incapable of social engineering, acquiring language skills beyond their own, or impersonating anyone else for espionage purposes - a modern version of the trope that Russian spies could be quickly detected by the poor cut of their suits.
Since we know that the NSA is government agency we probably can rule out the possibility of it being competent. No matter how competent are the people are hired there.
Mob that consists of intelligent and competent individuals is still a mob.
Pedantically, wouldn't it have to be a false trichotomy since there were three presented options?
This looks like OP cherry picked 3 options from a 2x2x2 choice matrix with NSA competency, NSA honesty, and the truth as its axes.
That's what was presented.
> This looks like OP cherry picked 3 options from a 2x2x2 choice matrix with NSA competency, NSA honesty, and the truth as its axes.
That sounds about right, which would mean there ought to be (assuming each of the implicit dichotomies was valid, and that they covered the problem space), 8 categorical bins, which is why the presented trichotomy would be a false one.
I'm just happy some interesting discussion came of it.
That 2x2x2 table isn't complete, by the way. For example, "The NSA came to a different conclusion other than the most politically desirable one" falls nowhere within it.
That's why I didn't try to enumerate all possible scenarios, especially the less plausible ones. That would be uncharitable to readers, as well as talking down to them.
4. The NSA is incompetent, but correctly concluded that NK is responsible anyway.
I agree that the "incompetent" ones are pretty unlikely. As for choosing between the first two, the big question to me is motive. I've seen plenty of people proposing 2, but I've not yet seen anybody articulate why they would do so. The only reasoning I've seen consists of references to similar false attributions in the past, which certainly has happened, but there are always reasons for it.
So what would the motivation be to lie about it? The Iraq WMD lie was used to justify war, but hacking a movie company won't move the dial on national support for war against North Korea, and there are many better ways to drum up popular support for such a thing. Increased cybersecurity funding? Again, I don't think people will care too much about a movie company as the target. Maybe someone in the US government hated the movie and wanted to sink it, and NK is just a convenient scapegoat? Pretty far fetched. Some other group carried out the hack, but this can't be disclosed somehow? Doesn't make much sense to me.
Unless there's some sort of reasonable proposal for why the US would lie about NK being the source of the hack, it doesn't seem too useful to discuss that angle beyond a basic "and yes, they might be lying for some unknown reason."
If the NSA were able to identify with some certainty who the attackers were and it was another nation, and they forewent actually using this as an example of a real tangible good that comes from the intelligence gathering apparatus they've put in place after all the flak they've gotten, to me that colors the information somewhat. If they don't want to stand behind the assessment, it could be entirely political (none of the controversial programs helped, so don't fuel the fire of people asserting they aren't worthwhile) or it could be operational, as in they aren't as confident as the FBI is professing. I'm sure there are many other possible reasons as well, but I don't think it simply boils to competence or incompetence.
4. the NSA has nothing to do with this and the FBI are incompetant
Further, the equation of "competent" and "correct" in the scenarios is ill-founded; competent people can reach incorrect conclusions and vice versa.
> Since we know that the NSA is filled with highly competent people (based on the quality of the people who periodically join the commercial world after a stint at the NSA) we can probably consider 1 or 2 the most likely explanation.
Perhaps, but even if so, #1 and #2 need to be expanded to:
1a. The FBI is competent, and has correctly determined that NK is responsible, and is accurately reporting its correct determination.
1b. The FBI is competent, but has nevertheless incorrectly assessed that NK is responsible, and is accurately reporting its incorrect determination.
2a. The FBI is competent, and has correctly determined that NK is not responsible, and is misrepresenting its correct determination.
2b. The FBI is competent, but has nevertheless incorrectly determined that NK is not responsible, and is misrepresenting its incorrect determination.
It's also in their interest to position the threat as a national security issue because that's where they derive their power to regularly break the law through spying and other tactics as well as their over-inflated budgets. If the threat is coming from a hostile nation it helps their narrative better than a disgruntled employee or someone doing it for lulz.
In just one week we've gotten over the fact the USA tortured people to death only a few years ago, or at least the "news" has.
If the above is true should that cause us Bayesians to slightly believe their conclusion more? Or are they so influenced by governmental interests (who may want cyber warfare) that it really isn't a factor?
2a. They're lying for political reasons. (This seems to be the most common explanation in this discussion and others.)
2b. They're lying to make the real hackers feel safe and potentially make a security mistake.
Some other reason?
The NSA has much competence, but not omniscience. There's indirect evidence of overlap with NK hacking activities.
Maybe the evidence means NK was the prime mover. Or maybe it means NK got invited in later, during the many months of likely compromise. Or maybe it means NK was intentionally implicated ("framed") by others. Or maybe it's a coincidence of many teams working the same tools/pathways/compromised servers.
Certain agencies and people gain politically – in budget or prestige or minimization-of-embarrassment – by leaning towards the "finger NK" call. There's enough murky evidence it's defensible, whether true or not, and in any case hand-waving about confidential "sources and methods" makes the call low-risk. Who else are people going to believe?
So the NK call goes out, and no one's competence or veracity is really on the line.
There is no reason to believe the NSA is involved. The article does not mention it and there is no other official reason to think they are. The FBI have their own cybercrime unit.
But if the FBI investigation actually did conclusively show that NK was involved, what could they possibly have to gain by putting out a press release? To let the hackers know that we're on to them?
The only possible reason for a press release at this time is to widely circulate this piece of information, which must be valuable to the FBI for some reason. There's no need to complicate the issue further.
Agree that the "other"-other choice should be "come to whatever conclusion but not publish findings."
I do not see a huge motive, though. Also, I think we can assume that the NK is above average competent, too. Why would the NK find this so important to spend time and effort on? Did they buy options on shares in movie companies to make a lot of money? Is this a small operation by some NK agent or department head who wants to make an impression to his superiors, or intends to blackmail Sony Pictures (if that is the case, the villain should already have asked for money. We don't know whether he did).
4. The NSA is competent, and has good reason to carry out a false-flag operation.
As far as I can gather, only the CIA and FBI have published statements pointing to North Korea. I believe the NSA to be competent, but I have seen members of the US government lie repeatedly in the recent past.
Regarding Iraq, we know now that the US government lied and/or misrepresented facts regarding chemical weapons, biological weapons, and uranium enrichment programs. We know from recent revelations that the CIA considered, planned, and approved of false-flag operations in Cuba in the 1960s. Given this history, we should not rule out the possibility that the US intelligence agencies are misleading the American public intentionally to achieve their own goals, independent of the facts.
1) Most people are dumbasses
2) Often willfully so
3) This has troubling implications for democracy, representative or otherwise
These assertions, if true, affect everything in our public and private lives, including the development and dissemination of the story at hand.Unfortunate but let's be honest - nothing was ever going to be done about that report. The world is outraged, the US apologises and does nothing, and most people forget.
Be foolish to bet against that, since the US has never stopped being at war with North Korea since the 1950s.
> (probably giving the weapons to south Korea so the put the body count)
Given the pre-targeted artillery pointed at their capital, neither the people nor the government of South Korea are likely to get behind resuming active conflict with the North without some somewhat more substantial provocation than the SPE hack.
And US encouragement -- if it were to be offered -- is unlikely to change that.
They are not trying to hard right, I mean they trhowed down Saddam Hussain in a couple of years, but somehow they are unable to take North Korea despite fighting for more than 50 years (based on your claim), yeah... no.
Also, Sony Pictures is an American company which was bought by Sony, the Japanese megacorporation.
The torture report is just more details on what happened 10 years ago. No one is shocked or surprised. The guy in charge of all this left when the current guy took office in 2008. If we're playing nation state PR trickery games, it seems to be Russian and Chinese media outlets were really pushing the report as a way to distract from their own domestic issues, their own domestic human rights issues against their own citizens, and to continue to vilify the US as it serves them domestically to deter people from their god given rights to freedom, justice, and self-rule.
Of course, to many internet commentators, Russia and China never do dirty tricks like these, only the US. Shame we can't have a more evolved view of press release timing, news cycles, etc. Its just more anti-US conspiracy theories while the rest of the world, especially dictatorial regimes, get a free pass.
It wasn't so much a "Terrorist operation", as an act of horrible desperation by an incredibly disturbed individual.
This is a perfect example of why "Terrorism" is a dangerous term. It has huge definition creep.
"Intelligence officials “know very specifically who the attackers are,” said one individual familiar with the investigation"
http://www.washingtonpost.com/world/national-security/us-att...
Look, I don't trust the FBI completely. But as of this point they're the only people who have actually seen any of the pertinent evidence. Unless you have a prior that they are actually MORE likely to be malicious than not, there's no grounds to do anything but acknowledge their claim (with as much salt as your please, of course).
If foreign governments are now a real threat, industry should have some awareness of the methods being used so we can try and protect our own infrastructure. Especially as this seems to indicate they are using software that's at least somewhat known already.
So I guess the question is either who needs a war asap (follow the money?), or who needs a war-sized distraction?
https://www.techdirt.com/articles/20140106/00442525768/fbi-a...
http://www.fbi.gov/news/pressrel/press-releases/update-on-so...
Proposed Scenario:
- Malware is developed independently
- N Korean actors use a variant of it
- GoP uses a variant of it
A
B C
FBI hamfistedly assumes B -> C, not A->B and A->C.I would take everything they say with a grain of salt.
1. The FBI knows who did it and is telling the truth by saying it's North Korea. 2. The FBI knows who did it and is lying by saying it's North Korea.
Personally I think they're telling the truth in this particular case.
They explicitly mention that they are not sharing all of the evidence.
This is a habit that needs to change if they want greater support among the informed.
Their reasons were along the lines of "attacks that look very similar were from North Korea" but were those attacks conclusively linked? I'm also curious how they decided it was the government there, not a rogue group of people.
A Russian poster said, it was an odd use of the word "False" in the email, since in English it's "Lies". He said when you translate the Russian word for "Fake" or "Lies" it comes out as "False". Which, if you read the email and substitute the word "Lies" for "False" in the two sentences where the word is used, suddenly the meaning is totally clear.
Here is the email:
http://variety.com/2014/film/news/hackers-threaten-sony-empl...
Removing Sony Pictures on earth is a very tiny work for our group which is a worldwide organization. And what we have done so far is only a small part of our further plan. It’s your false if you think this crisis will be over after some time. All hope will leave you and Sony Pictures will collapse. This situation is only due to Sony Pictures. Sony Pictures is responsible for whatever the result is. Sony Pictures clings to what is good to nobody from the beginning. It’s silly to expect in Sony Pictures to take off us. Sony Pictures makes only useless efforts. One beside you can be our member.
Many things beyond imagination will happen at many places of the world. Our agents find themselves act in necessary places. Please sign your name to object the false of the company at the email address below if you don’t want to suffer damage. If you don’t, not only you but your family will be in danger.
Nobody can prevent us, but the only way is to follow our demand. If you want to prevent us, make your company behave wisely.
Just something I keep coming back to in all of this.
Technical analysis of the data deletion malware used in this attack revealed
links to other malware that the FBI knows North Korean actors previously developed.
For example, there were similarities in specific lines of code,
Did the original NK's malware use lines of code from somewhere else, and could this 'shared line of code' just be a very common line of code? encryption algorithms,
Encryption algorithms in common?! Oh, heavens! I use AES too! Maybe i'm a North Korean hacker and I never knew it! data deletion methods,
Because there are North Korean ways of deleting things that nobody else uses to delete things? and compromised networks.
If a network has been compromised by one person, it's probably been compromised by several. The FBI also observed significant overlap between the infrastructure used
in this attack and other malicious cyber activity the U.S. government has
previously linked directly to North Korea.
Using the same questionable ways of 'linking' like the above, I presume. For example, the FBI discovered that several Internet protocol (IP) addresses
associated with known North Korean infrastructure communicated with IP
addresses that were hardcoded into the data deletion malware used in
this attack.
THE SMOKING GUN! An IP address! And we all know those can't be spoofed! But just to clarify: An IP of some NK hardware communicated with an IP that was hardcoded in the malware. That 'hardcoded IP' could be a Google web server for all we know. Separately, the tools used in the SPE attack have similarities to a
cyber attack in March of last year against South Korean banks and media outlets,
which was carried out by North Korea.
The tools used are similar? They might have used Metasploit to hack a SK bank, but that doesn't mean everyone who uses Metasploit is a NK hacker. And off-handedly asserting NK did the SK bank hack is a bit of a hand-wavey move.--
It's clear that the FBI has no actual direct links or hard evidence. It has amassed a set of random unrelated suspicious notes and decided this is enough to be sure NK was the perpetrator.
And that's how law enforcement works in this country, folks. Some obscure hokey details get paraded around as hard evidence so they can look like they've done their job.
He mentions that we as an international community needs to establish better internet and cyber operating rules, and I think we are slowly but steadily heading to a decentralized internet as the answer.
The problem I see with decentralization is that non-technical people have absolutely no idea what it even is or how it can help. However, the trend with these major cyber breaches seems to be that they are occurring more frequently and being more widespread. This may be a push towards educating the public on the benefits of decentralizing information on the internet.
However the 'But Maybe...'and cynical side of me says Sony and the studios will use this to attack file sharing, and a new cyber crime law somehow out of this (http://www.theverge.com/2014/12/19/7420823/mpaa-decries-goog...).
Our hysteria at times just turns into loss of rights and freedoms for us, we have to stop this manic, short-term thinking behavior.
But let's be honest, the perp is North Korea. Nobody in this whole process will be stressing the need for transparency and restraint.
Looks like Sony's horrifying and insulting info-sec policies are going to be swept under the rug.
The evidence and the release of statements about that evidence seems extremely light, and way over the line of being dangerous.
Or if that wasn't the real goal, never let a good crisis go to waste, and just do that anyway.
All I've heard confirming this is from MPAA "cyberterrorism experts." And George Clooney, whose statement regarding the Nixon origins of the name "Guardians of Peace is also unverifiable.
I can't see how NK could have a hacker force when they are so behind in technology. For hackers to be good, they need to be educated with technology. That seems unlikely coming from NK.
http://www.vocativ.com/world/north-korea/unit-121-the-north-...
Even so, this article actually raises more question than it answers. Was Sony's security really weak or was the hack very clever? It may have been the former and if so, some other people might have the same information for quite some time now.
The intrusion in this case was most likely done by an insider, the feds themselves, or a hacktivist group. The feds routinely break into private systems and are known to go to great lengths to construct elaborate string operations [1].
The timing of the press release is highly suspect. An investigation into an international security breach can take months or years. The feds rarely comment conclusively at the outset because such statements can compromise the investigation. They've provided no evidence whatsoever to support their claims.
Tipping off the purported culprit in this way by claiming to have identified their tell-tale attack signature would make it harder to track future breaches. (It's like publicly announcing that a suspect's phone is being tapped.)
This press release violates standard operating procedure. And why haven't the feds filed charges if the investigation is all "wrapped-up"?
If a foreign nation was involved, there's no evidence that's the case. NK has been the subject of scathing media criticism in the west for years, but other critics weren't targeted in this way.
As others have pointed out [2], the intruders initially demanded a cash ransom. The theory that the attack was linked to a movie release was originated and spread by the media.
[1] "The Terror Factory: Inside the FBI’s Manufactured War on Terror" - http://trevoraaronson.com/book/
[2] http://krebsonsecurity.com/2014/12/fbi-north-korea-to-blame-...
Haven't we lost the hope and trust on Media and Agencies already?
http://en.wiktionary.org/wiki/ride_the_short_bus
So, yeah, please don't use it :) (if you really want to see the context of the common usage, you can do a google image search for "short bus".)
I think that was the context Archer meant. (s04e09 "The Honeymooners" when Lana an Archer pose as newlyweds)
BOFH: We can blame North Korea. Aren't we about to launch a comedy about their supreme leader?
PHB: Genius!!! (and left the room)
BOFH: Let me change the locale to Korean and recompile my virus!
We know CIA and NSA do sabotages as well and have hacked the whole world already - why do we think this right is reserved only for America and North Korea and other countries are not allowed to do this when it serves their interest?
That's quite the statement to make despite not watching it
for my money, it had a great trailer. the movie could be okay. it's easy to pile on to the notion that the movie is crap, as it makes the proceedings even more absurd. if the movie was good, then sony is somewhat vindicated, but we can't imagine that to be the case, because sony has bungled every moment of their response.
While not great comedy they're better than the Adam Sandler shovelware being churned out by Sony -- films that were given pretty heavy criticism from Sony employees in the leaked emails.
This looks like a new war from an European point of view.
;)
Still, of course this response is unwarranted.
>North Korea’s attack on SPE reaffirms that cyber threats pose one of the gravest national security dangers to the United States
Ah, the real meat of the issue? Has anyone else noticed the drumbeat ramping up in earnest for the next "War on fill-in-the-blank"? Sure, we all know that the threats are real, but it strikes me that we're about to spin up the full military/cyber-security complex, complete with its incessant fear-mongering, revolving private/public beneficiaries, and trillion dollar budgets.
Something about repeating the same patterns ad infinitum in response to every threat or perceived threat is just a bit exhausting.
Quartz covered that angle:
http://qz.com/315432/this-is-far-from-the-first-time-hollywo...
Most seemed to be a random, satirical event within the film or non-current leaders. The Chaplin flick seems the closest, but even that's subject to debate (per the article).
Not to say that any of these were especially wise either, just that the entire premise of "The Interview" seems especially stupid.
The plot of that movie revolved around a professional baseball player psychologically reconditioned to assassinate the Queen of Canada during a game. Oddly enough, neither the Expos nor the Blue Jays were the visiting team.
Interesting that the article only gave an honorable mention for the fistfight where Lt. Drebin rubbed the birthmark off of Gorbachev's head.
This isn't new, though the intimacy with which the subject matter is treated may be different.
[Edit] Actually I shouldn't have posted that. Some reporter is going to see this post, assume that I'm repeating something I heard from a reputable source, put it on the front page, and the whole world will suddenly believe that we were always going to invade Korea, because terrorism!!