Analysis of some of the IP addresses in the Sony hack
krypt3ia.wordpress.com
krypt3ia.wordpress.com
> Like I said on Twitter last night, I can see my way to saying that DPRK was behind this. I can use Occams Razor to apply the logic of who had motive, look at their actions on the face of it, and say “most likely” it is them.
I don't know if my brain is stuck on some self-reinforcing loop with this, and feel free to call me Mr. Pedantic here, but I don't think Occam's Razor can take you that far. The simplest-explanation buck stops at "someone who really wanted to hurt Sony"[1].
Given that tons of groups would have axes to grind with Sony (anti-piracy, losing customer data regularly, general "Golliath" image & behaviour), you'd need to have a reason why the simplest choice is NK in particular. I may have missed something, but I just don't see it.
* Would you have needed super-l33t 0-day APT ninja bullfrogs (that only a state actor could have afforded?) No, the reports make it seem that Sony's networks were (still!) much akin to a merry-go-round[2]. So, from a "capabilities" perspective, I don't see a state actor as a more obvious choice than a disgruntled ex-sysadmin + his friends.
* Would NK have any motive to deny involvement? By my read of their past PR patterns, they'd own it loud and clear ("we own you with nuclear, we own you with cyber! fear us, fear us").
[1] Could still be someone counting on one of the side-effects of this FUD shitstorm. That's what our favourite razor "rejects".
[2] "But it is moving! Nobody will be able to get on or off while it is moving. It have perfect securities."
This is because Ockham's Razor says nothing but: "The proposition with the highest prior plausibility has the highest posterior plausibility after updating based on evidence that increases the plausibility of all propositions about equally."
"When you hear hoofbeats think horse not zebra" simply reflects the fact that horses are--all else being equal--more likely than zebras, and hoofbeats are just as good evidence for zebras as horses. They do nothing to differentiate between the possible explanations of the hoofbeats, so you go with the prior.
The "simplest" explanation in Ockhamian terms--if it means anything at all--is just the proposition with the highest Bayesian prior. This doesn't mean it's wrong to use Ockham's Razor, but it also isn't right, and if it's the best argument you've got then you need a better argument.
Your reduction of the Ockhamian "simplest explanation" to "someone really wanted to hurt Sony" is a lovely example of this principle, and makes explicit that the evidence fails to differentiate between the minions of the twit in charge of North Korea and the minions of various other malicious organizations around the world. I was disappointed with the Ockhamian post-script to the article, as the actual analysis is making precisely this point.
I agree the evidence is weak, though. Probably not smart of the US government to publicly point fingers at this stage.
> On December 1st, NBC News aired a segment reporting that the FBI were investigating the breach and the possibility that North Korea was involved. While this may sound far-fetched at first, North Korea has a clear motive in attacking Sony.
That was the first NK link.
> (December 8) Unlike previous disclosures that were straight-forward, this group of files comes shortly after the appearance of a Pastebin link (now 404) that purports to be from the GOP, and gives a reason for the attacks on Sony Pictures, linking it to the now controversial movie, “The Interview”. There is speculation that the new announcement may not be authentic as it did not get sent out via the previous channels, and suggests an almost afterthought of blaming the movie for their actions.
That was the first time the GoP (if that was them in the first place) mentioning any of this.
Two likely possibilities (imho):
* Someone else did it purporting to be them, and the GoP didn't deny it for the extra lolz (+ it didn't hurt their cause/objectives)
* They did it themselves to reinforce the media frenzy (by that time, the NK link was almost presented as a fact in many media sources)
Think about it this way: If this is an independent group of hackers, completely unrelated with any states (through funding or otherwise), through the NK link they "leveled up": Convincing the World that this was NK, we're in cyberwar, the world is ending (etc) far outweighs "hacked Sony for the nth time".
Qutoes from: https://www.riskbasedsecurity.com/2014/12/a-breakdown-and-an...
/s
http://en.wikipedia.org/wiki/2013_North_Korean_nuclear_test
(Unless I misunderstood your question)
I'm having this strange feeling of déjàvu....
"NK which wants to be included in the investigation"
It is incredible that people are actually falling for this. North Korea said "let us in on the investigation or we will attack you". Who is going to say yes to this, even if one were so naive as to think the request were truthful (which it most certainly is not). It amazingly achieved its goal, however.
It's going to suck if the internet becomes a state sponsored battleground. gods know we fight enough on the grounds of personal preference and loose affiliation.
If anything this is a reason for the US to increase spending by the NSA and make a nation wide firewall. takes off tinfoil hat
I mean, Obama has straight up said that he plans to attack NK. At least to me that seems a very reasonable interpretation of the fuzzy political language of: "we'll have a response at a time, place and method of our choosing".
I don't dispute that NK comes off loopy. Or that a joint investigation seems unlikely. That doesn't automatically follow that the FBI report is faultless though.
He said absolutely no such thing, and it is rather incredible if people think this. The US has warned that they will respond, which will end up being a complaint in the UN.
Just to be clear, North Korea regularly warns the US of nuclear annihilation, imminent attacks, and so on...and people think the thing that will put the US over the top is a minor Sony hack?
I didn't mean to imply that there'd be a body count attached to the "response" BTW. That's (hopefully) far-fetched. But an attack in the same way that hacking some computers and releasing some embarrassing information is an "attack"? Absolutely.
Isn't that the entire point of the quote? (And yes, I reproduced Obama's words pretty faithfully I believe. They were playing on repeat on the radio.)
I mean, if you don't think "response" means "attack" in a gimmicky "cyber-warfare" way, what does it mean? A strongly worded letter?
If I run over my neighbor's cat, and he says to me: "I'll respond all right. At a time, place and method of my choosing." Any rational person would have to interpret that as an explicit threat of an impending attack.
Just because politically it may be weaseled out of does not mean it's in any way ambiguous in delivery or intended reception to Joe the Plumber.
NK hacks Sony. US uses technique x to attribute the attack to NK. In the course of a shared investigation NK learns what technique x is. NK changes their future operations to counter technique x. The US loses the ability to use technique x to attribute attacks.
Deleted comment
I wish I knew too, and Im not trying to convince you to blindly trust them (because I don't either), but you have to at least acknowledge the fact that they may very well have "something to lose".
My wife was in the Navy for six years and had a relatively high security clearance for an enlisted member. More than once she knew far more about a situation than was being reported on the news.
Let's assume that the Fed is telling the truth and that they do in fact have hard evidence. As they have not presented this evidence, we have to conclude that it is classified. So, they cannot present the raw intel, but they also cannot step back and do nothing as this is a hot, national issue which is now about more than a security breach at a movie company.
So, they come forward with the accusation and assure the public that a "proportional and appropriate" response will be dealt.
Of course, this scenario paints the best possible picture of the Fed. It may or may not be the case. However, short of evidence which in no way compromises a classified source, it would be their only option.
I just don't see the motive behind framing NK for this. Given, I/we don't typically have a clue about what actually goes on at this level of international relations, but there is no obvious motive at present time.
And to be clear, I don't think they've sunk so low that "the FBI is framing NK" is anything but a garden variety conspiracy theory at this point, but "the FBI is rushing a very complex analysis under heavy political pressure" is plausible to me, as is "the FBI has strong evidence that they are not willing to show us".
Ultimately, assuming they do have classified evidence, there's also a cost-benefit consideration to be made - it doesn't have to be a given that they can't release it. I don't think this describes the present situation, but depending on the scale of the response a situation calls for, compromising one or two classified methods or sources in order to get public support for the appropriate action may be the lesser of two evils.
"For example, the FBI discovered that several Internet protocol (IP) addresses associated with known North Korean infrastructure communicated with IP addresses that were hardcoded into the data deletion malware used in this attack."
Firstly, this isn't a statement of evidence, it is an generalized example of the type of evidence the FBI apparently has. Given the lack of any further clarifications on this statement, I don't see how you can make and presumptions as to what the actual evidence is. there just is not enough data here.
Secondly, the statement is carefully worded to say that the C&C IP's have communicated with known NK infrastructure. This is massively different than saying that the C&C IP's are associated with NK infrastructure. What the FBI is saying is that they have been able to apparently collect evidence that shows NK was communicating with the C&C IP's, presumably while the attacks were going on. With what we know about the state of internet surveillance, is it really that unrealistic to think that US SIGINT is collecting every single packet that transits known KN networks? Seems right in their wheelhouse.
Point is, the FBI aint telling us squat about what evidence they may or may not really have. Maybe this is because they are making the whole thing up, or maybe it is because they just don't want to tell us how much evidence they got, and how they got it.
If only a handful were used on both occasions, and the overlap is significant, then we have some fairly interesting evidence. But if, on one of more occasions NK used hundreds of IPs, and there are a handful in common between those two sets, then there's really nothing to see. I've had the impression it was the former, but perhaps I'm mistaken. Does anyone have an answer?
As an example, here is the Spamhaus entry for one of the IPs. Notice the references to articles about the Sony hack: http://www.spamhaus.org/sbl/query/SBL242808
It's a bit like saying "the attackers used malware which made DNS queries via the IP address 8.8.8.8, which has been used by NK in the past" - if anyone were really building a case on that key evidence, they should prepare to be laughed at.
When you're a hammer, everything looks like a nail.
Sony is trying to blame others for their security incompetence. The US is posturing with "We don't tolerate this."
Nobody really cares and nobody is going to war because Sony had their emails and some media stolen.
I mean it is inexpensive to develop an exploit hacking team but they would need training and the only two obvious sources would be China and South Korea and I cannot imagine south korea doing it willingly.
This all reminds me of how in 1993 that TV show seaquest was predicting countries assassinating other "elite hacking teams" - seemed crazy then.
Doesn't that indicate that they're perfect for (ab)use by anyone, since they're not linked directly to a single entity?
I don't see why it's outside the realms of possibility that e.g. North Korea always uses the same pool of "dirty" servers to launch their attacks.
The biggest surprise was the IP address traced to NY. Why wouldn't the FBI seize this system?
When the criminals on cops run through your back yard, do the cops turn the inside of your house into a crime zone? Obviously, no. Even if the bad guy runs inside your garage, they are not confiscating your car, lawn mower, etc.
Contrary to popular belief on HN here, police / FBI don't just seize everything whenever they want. It requires warrants and probable cause. Good luck getting a judge to sign a warrant to seize a victims computer...not going to happen.
And if someone went through your backyard or your garage while trying to escape from the police, the cops might want to look in your backyard or garage to see if the 2 Kg of heroin he was supposed to carry or the gun he used to shoot at them while fleeing didn't end up there.
The FBI should be looking at similar events for Sony. Greed is always something that you can count on.
Here are Sony's Options on Nov 25, 2014, the day after the hack. Note the same $17 put has actually lost a little Open Interest. No conspiracy here. http://i.imgur.com/dCRcvX9.png
Caveats: This was done with the US traded instrument (SNE). I don't have access to the Japanese exchange. Open Interest is reported after the day it is generated and reflects the secondary market of the previous day.
http://www.snopes.com/rumors/putcall.asp
Tl;dr -- A US institutional investor bought 95% of the suspect puts at the same time they bought 115,000 shares in a very standard hedging strategy.
https://github.com/scardine/random-writings/blob/master/text...