5. This is an
FBI statement. As the Sony movie studio's network is
not a classified US Government network, it isn't the NSA's job to defend it.
So, they may not have even been consulted on this - or (far more likely) their contributions, if relatively inconclusive, may have been cherry-picked for only those specific points which supported a politically-convenient, face-saving conclusion. (Which, as we all know, has happened before on a few infamous occasions.)
When you have a big hammer, sometimes everything looks like a nail. When you have a database of every IP address which sends packets transiting a collection point to every other IP address suspected of being a C&C (and the NSA & GCHQ do have exactly that), everything looks like a potential controller. There is a remarkably strong bias towards false-positive confirmation caused by (amongst other things) P2P networks and UDP packets with forged IP addresses. A bias the NSA (and/or GCHQ) would warn about: a warning that, alas, law enforcement tend to not always take to heart - which is (anecdotally) partly why GCHQ rather dislike working with the plod (and quite probably the same feelings persist in the NSA towards the FBI).
I still think the links to DPRK are very weak, if they even point that way at all - not that the North Korean government aren't vile dictators (they are) but because everything I've seen makes it look more like low-rent organised crime - indeed, I gather the payload and C&Cs used, which the FBI have (IMO) erroneously used in their attribution, are publicly available (though no, I will not link to them)!
What I've seen even (albeit weakly) indicates at least two actors with different names, one of whom asked for a monetary ransom, and the latter mentioned the movie after the media did and thanked the other (for giving them access?).
It may be (but there is no strong evidence either way) that the latter is actually the DPRK - in which case their "cyber-army" looks like low-rent organised criminals, which I admit would not be implausible, but speaks volumes about Sony's stunningly negligent incompetence!
The one thing I feel absolutely confident saying is this: Sony Pictures were an extraordinarily soft target, and this was not a display of any high degree of technical competence on the part of the attackers. It could've been anyone from North Korea to a disgruntled ex-employee (of which they have no recent shortage) to some random 14-year-old angry kid, or anyone in between. My sodding cat could have hacked them. ¬_¬