North Korea, Denying Sony Attack, Proposes Joint Investigation With U.S.
nytimes.com
nytimes.com
Sony executives:
* Sony gets tons of free publicity for its new movie.
* It diverts attention away from those emails that were starting to make certain Sony execs look really bad.
* They don't look quite so hopeless and incompetent if they're getting hacked by a nation state.
FBI/CIA/NSA/DOD:
* It's something that can be used to deflect heavy criticism of their all-pervasive surveillance.
* It's something they can use to wangle more money - to face the exciting new "cyberwar" threat.
Reasons for North Korea denying involvement if they actually did it:
...
Also, the concept of "cyber-terrorism" being a thing seemed kind of ubiquitous to me, but from what I've been hearing, it really wasn't on the minds of the populous until the 24 hour news networks started drumming it up in relation to the Sony hack.
I doubt it was that, if only because North Korea has been complaining about this movie since long before the CIA torture report was released (so it's not like "The Interview" just popped up into the media after that).
Moreover the report itself is more a catalyst for discussing something everyone knows about than an announcement of something novel. The world has known the U.S. was torturing people during Bush for more than a decade by now. That's the whole reason terms like "waterboarding" are in our lexicon. Likewise Obama publicly eliminated the use of torture on his second full day in office, after running on a public campaign of banning torture during his Presidential run.
Choosing to exchange a report that is only a 'source of heat and light' for a serious cyberhacking incident that demonstrates the weakness of U.S. options vs. North Korea isn't really an upside for the U.S. government as far as I can tell.
Extortion and blackmail from state actors is precisely the thing the U.S. government is supposed to protect U.S. persons and corporations from, so a U.S. admission that North Korea has managed to "reach out and touch Sony Pictures" is bad news for the U.S. government, not good news.
The relevant actor in this case is not the whole US government acting on its own agenda, but departments of the federal government acting on theirs.
I already explained why it's great news for them - precisely because it engenders the same reaction that you just had. Good enough that they'd invent it even if it weren't true (just like yellowcake).
This isn't remotely true. There was no 'gaining steam'. It was a topic for a week, and then it was always going to fall off the table. There was no need to distract from something that was already fading from the spotlight.
You do realize that the "North Korea did it" story is also a conspiracy theory?
>one if it was even remotely true would be a high risk deception to pull off for both the government and Sony.
There's a veritable laundry list of times both have lied about more important issues than this and gotten away with it.
If we say that the FBI's position is part of the conspiracy, well then good luck ever leaving the conspiracy theory bin. You'll likely never get tangible information from another credible source. It'll just be a never-ending conspiracy theory.
There was a time when I would assume good faith for most FBI/federal law enforcement statements. After Clapper and Snowden, that day has passed. I'll still believe an FBI statement with evidence. But without evidence it's just words, and very possibly with an agenda that's hostile to my Constitutional rights.
Any theory about how it was done is automatically a conspiracy theory because it WAS a conspiracy. Using it as a pejorative in this context is stupid.
>I don't know what more authoritative source we can go to to decide
Most of the OPSEC community - who don't have a motive to lie to get more goodies out of Congress and whose story actually adds up.
My point was that if you examine the motives of all the parties involved, the FBI's story stinks as much as the CIA's did when they started screaming yellowcake. They have every reason to lie and the North Koreans have no reason to lie.
If you act like a mad man (in terms of diplomacy) don't be surprised if people assume the worst.
I'm not saying that the FBI is totally trustworthy on this, but it's one thing to distrust them and quite another to accord no epistemic weight at all to their claims about the evidence. While they may have ulterior motives, they (and NK itself) are also the ones best positioned to tell us the truth, if they choose to do so. And while, again, one should not take it on faith that the FBI always tells the truth, I'd trust them over the NK propaganda apparatus any day of the week.
I read the FBI report, and while I'm sure that there is plenty left out of the report, their diagnosis was based largely on first, structural and tactical similarities to other, earlier DPRK attacks, and second, North Korean IP addresses that were pinged by the malware. Both of these, to my layman's understanding, seem easily falsifiable.
All I stated is that within my own circles and based on the infosec figureheads I follow, that I have not seen a single individual who claims to have been convinced that this is indeed a DPRK attack. Because I'm obviously somewhat filter bubbles, I was asking for individuals whose opinion I could get which would help me expand my own filter bubble.
Dave Aitel has been raised as a counter example, and while he's certainly not unbiased, it's tough to find people in this field who are in fact unbiased, so I'm grateful to hear his opinion. I'd like to find more counter-opinions.
In terms of diplomacy this is simply how they are presented by the western media to a largely credulous western audience.
If they were truly as irrational as they are presented the North Korean government would have stopped existing decades ago. Mad men are not good at self preservation.
Never mind being able to develop heavy industry, nukes and a minor space program all while under sanctions.
Given this news, maybe the FBI was wrong. But the "professionals" in the doubt squad were mostly just guessing along with the rest of us.
One name. Seriously just one name.
And look, I really try not to shout conspiracy at everything.
But the FBI is relatively new to the Cybersecurity game. CNN yesterday was showing "MPAA cyberterrorism experts". The links to DPRK seem tenuous at best.
So in this context, when the organization who blackmailed Martin Luther King says something, I'm going to try to seek independent confirmation.
All the security professionals who I follow on the internet has either expressed doubts or outright disbelief that DPRK is culpable for this attack. Obviously, I'm in a bit of a bubble, so I'm trying to find independent people outside of my circle who agree with the FBI line.
My understanding of FBI cybersecurity is that until very recently, they were primarily responsible for domestic cybercrime.
Responding to "Cyberterrorism", to my knowledge, is something that has happened much more recently.
I, of course, am no expert in this regard, which is why I'm seeking out expert opinons! If you have more info I'd really appreciate having some more stuff I can take a look at.
But of course, this is little more than circumstantial evidence regarding the case at hand.
His latest post simply points out that the FBI has said North Korea is responsible, without elaboration or contradiction. https://www.schneier.com/blog/archives/2014/12/lessons_from_... So while it does not appear that Schneier has reviewed any evidence (what evidence could he review?) and reached his own conclusion, he seems perfectly content to credit the FBI's conclusions.
The FBI's assumption is absolutely newsworthy, and I'm glad Schneier reported it, even though he abdicated any judgement either way. You're correct in saying that he does not elaborate or contridict the FBI statement, but it should also be noted that neither does he endorse it. So I am moving Schneier from the "Having doubts" column over to the "ambivalent" column in my mental list.
Thanks for taking the time to provide more information.
https://www.schneier.com/blog/archives/2014/12/did_north_kor...
https://twitter.com/thegrugq/status/546409624891424768
Not that I think infosec professionals are very much more qualified to make guesses than the rest of us.
https://threatpost.com/dave-aitel-on-the-sony-hack/109988
But he sells offensive security tools to goverments and corporations, so he is not without bias. Actually this might be more in support of the OPs comment regarding gov support rather than refuting infosec peoples stance.
I've been asking this question for 3 days and haven't been able to get any response.
As you said, there's a bit of a conflict of interest here, but you'd be hard pressed to find someone who isn't biased.
I do think this supports OPs comment.
Surely if NK wanted to "cyber-attack" the US it wouldn't do it through a Japanese company. Or am I missing something?
Also, you have to understand that Sony is a 140,000 employee organization, with many different operating units that are functionally probably pretty separate. The Sony Pictures network and email system was likely entirely separate from other Sony divisions, especially since one was based in Los Angeles, and others are probably based in Tokyo.
The FBI, of course, is another story. But the two reasons you give for them to claim NK involvement would work just as well if any other nation or non-state actor were behind it.
And you're just not thinking hard enough if you think NK has no reason to deny responsibility. Off the top of my head: maybe they would rather wriggle out of whatever "response" it is that the U.S. is cooking up, maybe they want to retain what credibility they can so NK can plausibly deny involvement in future attacks, maybe the fallout is also hurting their relations with China, etc.
This news has also sparked these revelations:
http://www.theverge.com/2014/12/12/7382287/project-goliath
So there are a lot of issues at play here, which is why I'm cautious to endorse any viewpoint without really good documentation.
I definitely think you're right in saying North Korea has enough reason to deny responsibility. Let's not forget that Al Qaeda didn't take responsibility for 9/11 until 3 or 4 years after the fact.
Actually, applying the same line of reasoning also brought me to the same conclusion about Al Qaeda.
When Osama initially denied involvement it rang true because he had no motive to deny it if he actually was behind it. He wasn't going to suddenly stop being no. 1 on the FBI's most wanted list. He already had two sizable terrorist attacks to his name.
Whereas... consider what Bush and Cheney would have done if they had found conclusive proof that Mohammed Atta was the sole mastermind of the operation.
"Sorry guys, we can't retaliate because the perpetrators are all dead"?
Heh.
As far as the public is concerned they do have some credibility. If for no other reason than they were the ones who were actually hacked.
>The FBI, of course, is another story. But the two reasons you give for them to claim NK involvement would work just as well if any other nation or non-state actor were behind it.
They would, but by spinning the NK involvement story they can count on Sony's cooperation. If they started contradicting Sony and arguing that it was China the whole thing would seem a lot less convincing. This is a joint effort.
>And you're just not thinking hard enough if you think NK has no reason to deny responsibility. Off the top of my head: maybe they would rather wriggle out of whatever "response" it is that the U.S. is cooking up
Ok so name a plausible response that would scare them. Invade? Uh, not happening. Economic sanctions? Already doing that. Talk shit about them at the UN? North Korea doesn't care.
>maybe they want to retain what credibility they can so NK can plausibly deny involvement in future attacks
Which:
A) Again they would gain nothing from. B) Also completely goes against their modus operandi - when they gain military advantage they always crow about it. Every time. Did they cover up Taepodong? Hell no. They issued a press release.
>maybe the fallout is also hurting their relations with China
Or the opposite, because China would almost certainly be happy to mine the hacks for any useful intel. It's not like they are besties with the US.
Lets the timeline right
1. North Korea makes its disapproval of The Interview public and complains to the UN in the summer of this year
2. Sony is hacked and passwords are leaked. The passwords are the focus of the story
3. A couple of days go by, no mention of North Korea or The Interview
3.5 I've gotta be missing something here
4. Theaters (not Sony directly) decide the pull The Interview because of threats from NK
5. FBI blames NK for sony hack
6. Obama gets involved (?????)
The sequence of events just makes no sense. Then there are sites like reddit that are completely consumed by the story. The number of posts about it is insane, and there is little skepticism about the bizarre sequence of events or the blaming of NK.
http://www.theguardian.com/uk-news/2014/jul/14/gchq-tools-ma...
As best i understand they were "just" online threats, but came in the wake of similar threats to Sony employees and their families.
At this point in time i think there is a subset of internet trolls that get their "lulz" from finding some high profile controversial topic and throwing random threats at whoever is involved.
http://www.theverge.com/2014/12/16/7402649/sony-hackers-thre...
http://abcnews.go.com/Entertainment/theaters-now-pull-team-a...
Now if that is the same as the original hacker(s), never mind if they are actually attached to NK in any way, is another issue entirely.
- The media mentioned that this hack might be NK because of TheInterview.
- A spokesperson from NK replied "Wait and see" http://www.bbc.com/news/world-asia-30283573
- Another email from #GOP came out saying not to show TheInterview
- NK starts denying involvement.
- Yet another email comes out citing 9/11 and everyone gets scared.
4.5, SONY pulls the movie entirely after 4 or 5 major theaters decide to pull it.... after SONY let them out of their contractual agreement and said, in effect, "You do what you feel is right"
The Senate report on CIA torture is what you're missing.
[0] http://www.smh.com.au/world/vladimir-putin-invites-north-kor...
I'm not saying that this isn't what has happened, as governments are capable of wonderfully insane levels of stupidity at times, but it does seem relatively unlikely.
This more looks like someone who is massively pissed with Sony, not a particular film, and is just running with the NK angle for comedy chaos-monkey reasons.
And its just in time to distract from the CIA report.
Couple that with the revelations that we have tortured at least one prisoner to death, and I think there is plenty of cause for the dialog about torture to continue.
But... ultimately that's just how I feel about it. I don't think there's been any truly conclusive evidence one way or another, just people trying to make sense of what is known.
>> I'm not sure NK even has the computer skills to pull it off, for that matter
Ugh, it pains me to see people get this so wrong. Let me state this as plainly as possible: when you're attacked by a state, whatever encryption or security you have in place doesn't matter. They'll go after your weakest link, and exploit that until they have access to whoever controls your security infrastructure. It could be as simple as bribing an Ops guy, or it could be as complex as planting a spy, or secretly threatening someone with access. Once you're up against a state, all bets are off.This is a gross oversimplification.
Some states are much more capable than others. The US and China probably have more digital offensive capability than everyone else put together.
Some targets are much easier than others. Larger companies usually present a larger attack surface. Some companies don't care as much about security. If you're one person with really good OPSEC practices, you're substantially harder to go after than a large organization.
And, of course, all security is a matter of degrees. You don't need to have perfect security; you just need to have security good enough that the group coming after you can't justify the expense of circumventing it.
Also, I don't get how this hack helps North Korea in any real way. Maybe there really are 'links' as such, but I honestly wonder if this was something they put together as I don't see how it helps them.
* sony gets hacked.
* a few news articles about it.
* cia torture facilities get leaked and admitted.
* news coverage all over about it.
* US federal government does something its never done before and calls out a specific nation state as the attacker for the sony breach.
* news coverage of sony skyrockets and cia stuff disappears from media.
* us government goes on to say that they need to increase their "cyber defense" by having more control over the internet to protect individuals and companies from other nation states.
edit: oh also wasnt it just earlier this week that there was an article on hn about sock puppets?
I can image three reasons. First as I mentioned above, you might make official denials with the understanding that everyone assumes you did it anyway. Second, there might be internal infighting between the people who did it and the people who issued the denial. Or third, you might do it with the plan to take credit, then get cold feet afterwards when you realize how much heat it's bringing down, and then deny.
Or is there any other hypothetical rational for such acts that I am missing?
The Cheonan incident followed a very similar path. S Korea and the United States identified N Korea as the actor. N Korea denied the involvement and offered to work with the nations to lead an open investigation into the incident. N Korea's official denial was enough cover for China and Russia to disagree that N Korea was involved in the incident. The ultimate UN statement on the attack was a condemnation of the attack, but no official party was declared responsible.
This gives N Korea the benefit of terrorizing the S Korean navy, while avoiding a direct military or economic response. It's a game of brinksmanship where they want to push their actions as far as possible to convince the world that their threats are serious, while still minimizing the negative repercussions that often follow from such actions.
They've frequently done similar attacks and been completely open about it and suffered not much in the way of a response.
>This gives N Korea the benefit of terrorizing the S Korean navy, while avoiding a direct military or economic response. It's a game of brinksmanship where they want to push their actions as far as possible to convince the world that their threats are serious, while still minimizing the negative repercussions that often follow from such actions.
Alternatively there was an almighty fuck up on the part of some part of the South Korean navy and blaming the North Koreans helped them escape any fallout.
http://www.koreatimes.co.kr/www/news/nation/2010/10/116_6582...
The theory that North Korea was upset about a crappy movie and hacked Sony is such a naive nonsense, it cannot be considered seriously. In is HN, after all.)
Less naive could an idea that some guys hacked Sony (for money, what else?) and used this as a "cover story". How does this happen? By a chance, like most events in Universe.
The hack itself, probably, was due to neglected security, like WEP hot-spots, unpatched Windows crap, everyone has Administrator privileges, updates disabled - everyone knows how it is.
And in order to "save the face" everyone jumped on that naive story - it is highly sophisticated hack by foreign intelligence, not an "admin" (or "fuck") password on some hotspot or Windows domain. It was a media division, btw, not a "techie" department.
I am exaggerating a bit about passwords, but the idea, I hope, is clear.
I'd be inclined to agree with you if the North Korean government didn't officially condemn the film last June and threaten retaliation if it was released.
http://time.com/2921071/kim-jong-un-seth-rogen-the-interview...
I can't quite understand the allegation that NK is behind this because I don't see a motive.
This is after all a country that in the past has kidnapped Japanese citizens for purposes including producing movies for the NK film industry:
http://en.wikipedia.org/wiki/North_Korean_abductions_of_Japa...
How would a member of Kim Court know where to find hackers?
I'm not sure what percentage of people here know where to find those kinds of hackers, and we're supposed to be IT experts.
So the idea that some underling in the world's one surviving Stalinist state, which happens to have barely any Internet, knows where to hang out on DarkNet, and also has a suitably impressive stash of BitCoins, and knows enough about corporate politics to understand how to cause Sony Pix maximum humiliation - all that sounds just slightly unlikely, no?
China? Maybe. Russia? Possibly. 4Chan and/or LulzSec? Uh huh.
But North Korea? Possibly not.
The motive is that a company that straddles the two countries that North Korea hates the most created a movie obviously designed to be a gross insult to their leader.
I'm sure there could be ancillary benefits to the hack too - technology they could copy, etc.
The motive is definitely there, but all the evidence still points to a disgruntled ex-employee.
Like DRMs?
Jokes aside, I have no idea what's going on with this whole story.
http://time.com/2921071/kim-jong-un-seth-rogen-the-interview...
Because the military is likely angling for extra funding for its 'cyberwar' divisions and they would like for that pesky torture stuff to be yesterday's news.
I can easily see the American government blaming NK because that would (and has) generate media attention and push the torture report out of the spotlight.
That torture report is one of the best gifts they could have given the terrorists. They now have undeniable proof that America tortured people. Even if we put that aside, torturing people is what America prosecuted other war criminals for, and here they are flaunting their own rules. Consequently, they've lost all credibility and moral high ground.
I think being wrong about blaming NK is much easier to brush off than being caught red handed violating the ethics that your own country established just decades prior.
Think about it, if they're wrong about NK, everyone who suspected that is just going to go "I knew it." and everyone else will wonder how they could have blamed NK without being certain. Repercussions? None. Benefits? The People have forgotten about that whole torture thing. Win Win for the WhiteHouse.
I won't pretend to be an expert on information security but surely this isn't anywhere close to being unique enough to point blame at North Korea?
But I share some of your skepticism.
</sarcasm>
http://www.dailymail.co.uk/news/article-2565240/Voices-damne...
http://www.theatlantic.com/international/archive/2014/02/nor...
http://www.theblaze.com/stories/2014/02/19/eight-sketches-of...
https://en.wikipedia.org/wiki/USS_Pueblo_%28AGER-2%29
They really have zero reason to deny culpability if they actually did do it.
Maybe it's because I missed original news. Can somebody provide link or explanation why the heck it's so important that even completely non-technical people buzz about it all the time?
The amount of data compromised is unparalleled in any other previously reported hack, and the response by Sony (canceling the distribution of a movie) is also unprecedented.
http://www.amazon.co.uk/The-Making-Casablanca-Bogart-Bergman...
That's just perfect way to put it! Possibly! Possibly aliens from Alpha-Centauri did. Or possibly they didn't.
After comments like this it really starts to look like pretty successful excuse to start a war or something and completely made-up topic overall.
1. Does NK even have the capability to pull something like this off? They seemingly fail at every other intimidation stunt they pull off & now they have a massive success out of nowhere? Hm...
2. Why would they deny it if they did it? It's very out of character for them to not pounce on the chance of something being very embarrassing to the US.
3. With all the talk of it being so complicated to pinpoint exactly where the attacks came from, what info is the US gov using to pin this on NK (besides the very easy narrative around the context of the movie). They have to have a bit more intel than they're letting on...or something is fishy here.
North Korea routinely provides much better reasons to intervene.
With that said--whether or not they were involved is entirely up for debate.
Having access to the internet doesn't mean you can automatically hack a multi-billion dollar company.
1) Yes, probably. They have some sort of a cyber military organization, and it wouldn't even have to be _that_ sophisticated to pull this off. In brief see http://www.telegraph.co.uk/news/worldnews/asia/northkorea/11...
2) They're afraid of the repercussions given the massive public reaction to the hack. This isn't a fully persuasive line of reasoning, but it seems like a possibility.
3) You can see some of the evidence explained here: http://www.fbi.gov/news/pressrel/press-releases/update-on-so...
There would be no repercussions for NK admitting that they did it.
Few things to remember: 1. The instruments of dictatorship is working well. They are not bunch of idiots. They outlasted the Soviets! 2. NK launched a medium range ballistic missile. It was a rather crud one (basically bolted together from parts from multiple missiles). NK may be poor and a backward country but they did build and launch the rocket(although it broke up in mid flight). How many nations have actually launched rockets as NK did? 3. We all know 'hacking' isn't some rocket science. It can be done by any reasonably intelligent person with a lot of time on their hands. And NK obviously has reasonably intelligent people who have the aptitude for programming/coding/hacking with a lot of time on their hands.
NK's only internet connection is via link through China. But I can also see NK posting hacker-soldiers in China too.
(Nudge nudge, wink wink, you know what I mean, know what I mean?)
The future of the internet is changed as a result of this event, thats the true meat of this situation.
Or the equivalent in their home country; that's just as well, given that the people I've met all over the world who work in their country's foreign service department are generally good people.
If you haven't seen, "A Beautiful Mind," it's a great film and the math literally helps explain why North Korea, despite evidence, might be a, "Sock puppet," used by...well, let's see.
What country is having a really, really crappy time with economic sanctions right now?
Maybe, just maybe, a bit of experience at interacting with the folks who (gasp) make these kinds of decisions would make the whole situation easier to explain. Or if most of us simply revisit kindergarten in the US, eg, the game of, "Tag." Remember how to claim a cookie that you're not supposed to eat?
Touch it. "If I touch it, I own it," because nobody wants to eat the cookie you touched after you liked your finger, right? So, Russia perhaps, "Licks their finger," tunnels through, and then when we discover the breach, "Look, it's the North Koreans!"
If not them, I'd say Luxembourg is behind it all. We know most American companies that have operations overseas use them to launder (I mean, mitigate) tax burdens in Europe, right?
Okay, I met the former ambassador to Sri Lanka and had tea with snacks when we hung out. Present was a Vice President of the country I lived in - great guy.
I can't confirm nor deny, because I don't know, the exact status and titles of the various members of the legislature I met while overseas because, frankly, it wasn't my intent to keep a log then post it publicly.
To whit, I've also been listed as a reference for a prosecutor who became a judge in California. However, none of this should be needed to, "Trot out," in a response about foreign politics, which I have ample experience in personally through multiple visits to many countries.
Thanks, though, for deflating my karma count - I need to remember, I'm sharing here because it's fun, not because I'm winning a game. ;)
I've started to think of conspiracy theorizing as some kind of base human instinct