Did North Korea Really Attack Sony?
schneier.com
schneier.com
Also, as far as I know the codes didn't contain any Korean. Instead, what they found was that it seems to have used Korean text encoding, like EUC-KR. People have pointed out that this is a South Korean encoding, but North Koreans also use it since you hardly find any software that supports the official North Korean encoding. Again, if someone uses a British English locale, that isn't proof that it can't be an American. When it comes to text encoding and locale, you usually use whatever is available that lets you type in your own language.
This is a different hack, but I think they more reliably differentiated between North Korea and South Korea, due to the IP addresses? "Korea seeks U.S. help in reactor hacking probe" http://m.koreaherald.com/view.php?ud=20141222001202&ntn=0
Note that linguistic evidence doesn't come into this, just as one wouldn't usually be speculating about which English-speaking country a hacker was from simply based on the code.
More importantly, Italians will continue to write and be taught in Standard Italian, which was developed based on the Tuscan dialect long before our artificial division of the peninsula. It won't be as if they would start from scratch and create new standard languages based on the Milanese dialect in the North and the Roman dialect in the South. Even independent countries such as Germany, Austria and Switzerland find it useful to use the same standard German as each other, even if it's not necessarily based on a dialect spoken wothin their borders. There will inevitably be differences in vocabulary and spelling, but the differences will be far less than if we imagined a naïve model where each country creates its own standard (which is what basically happened in Scandinavia).
Confusingly, Italians would call Piedmontese or Lombard a “dialetto” as much as they would call Turinese a “dialetto”. The word basically means a dialect or regional language, depending on the context. There is also a political element to it—the Italian government has suppressed the regional languages for years, and even now does not recognise them as languages, against academic opinion.
To be clear, Italians would also (generally) refer to Welsh as a “dialetto” of English, despite the fundamental difference of Welsh and English. (In fact they would usually also often refer to the U.K. as “inghilterra”.) The word “dialetto” as currently used in normal Italian speech simply does not correspond 100% with the English word “dialect”, much like the word “camello” doesn’t correspond to “camel”.
The regional languages generally are not mutually intelligible, although this depends on which dialects two speakers speak, and how “stretto” (strong) the dialect is (I don’t know what the academic term for this is). So for example Vercellese (from Vercelli) is linguistically close to Novarese (from Novara) even though Vercellese is classed as Piedmontese and Novarese is classed as Lombard (despite being a Piedmontese city). The distinction is ultimately arbitrary—there is a gradation of dialects from Piedmontese to Lombard. Vercellese for example has many grammatical elements of Lombard (e.g. it uses the Lombard lü (meaning “he” or “him”) instead of the Piedmontese chiela).
Also, an older or more rustic speaker is more likely to speak a “stretto” dialect, because they’ll use more words and expressions originally belonging to that dialect (or to the regional language). Over the years, the regional languages have absorbed many words from Italian, replacing the traditional words. Now, the same thing is happening to Italian with English words (e.g. the word “goal” replacing “rete”, or “babysitter” replacing “tata”, or “shopping” replacing “spesa”—the English word in each case sounds more modern or cool to Italian speakers).
The linguistic situation is basically the same as with Catalan and Spanish. Catalan is as much a “dialect” of Spanish as Piedmontese would be a “dialect” of Italian. In fact, you could just as rightfully say that Italian is a “dialect” of Piedmontese. The difference is political, not academic.
The situation in Korean is not qualitatively different, either. For instance, the Jeju "dialect" (now sadly moribund) is definitely not mutually intelligible with other dialects of Korean some authorities would insist on classifying it as a separate language. Even the mainland dialects (as they are traditionally considered as opposed to distinct languages) are considerably different from each other, not just in lexical items but in the existence of different grammatical categories (e.g. distinguishing between yes/no and wh-questions), morphology (the conjugation of verbs and adjectival verbs is all different), and phonology (different consonant and especially vowel inventories, different stress/pitch systems), to the degree that I wonder how much communication would be possible if it had not been for the imposition of standard Korean.
I used Italy as an example instead of the U.S., because it is a stretch to say that the U.S. has different dialects as the speech is quite uniform across the vast country compared to what you see in Korea; or the U.K., where the existence of Scots complicates the analogy. I did not intend to minimize the diversity of regional languages in Italy.
However, it’s certainly possible for a country and a population to completely change language in a generation. The Italian generation of people that is now about 60 years old are effectiviely bilingual—they were taught in Italian at school, but (generally) spoke their regional language at home. The generation after that spoke only Italian, and the generation before that spoke only the regional language. (Obviously this is a bit of a generalisation.) So it’s quite straightforward for a country to change it’s language over the course of 20 years or so.
I have a colleague in the Netherlands who believes that the Netherlands will at some point adopt English as its official language. I personally doubt it, but it is nevertheless definitely possible. All it would take is for the government to decree that all schoolchildren be taught in English at school. Dutch people (and particularly Dutch school-teachers, which is the important thing) would easily be able to carry that policy out. The first generation of schoolchildren to pass through to adulthoold would probably choose to speak in English as their primary language, as has happened in Italy.
Also Brussels has changed from a Flemish speaking city to a French speaking one in a short space of time.
On top of this, you'll find that those English loanwords are almost nonexistant in North Korea. Where South Koreans will simply say "Ice cream", North Korea has the word "얼음보숭이" which literally translates to "ice fluffly thing".
There's also differences in the speech styles (a very complicated and extensive topic in itself) and verb endings. NK prefers some styles where SK prefers others-- But like it was said farther up, the difference really comes down to something like US/British English, obviously different but still very mutually intelligible.
The notion that North Koreans say 얼음보숭이 (ŏrumbosung'i) for "ice cream" is a bit of a myth. The authorities in North Korea did indeed introduce this word as a part of a linguistic purification effort, but it doesn't really seem to have caught on. A 1962 North Korean dictionary only has 아이스크림 (aisŭk'ŭrim) "ice cream", just as in South Korea. A 1981 edition of another dictionary and a 1984 encyclopedia introduce 얼음보숭이 (ŏrumbosung'i), but the official dictionary that appeared in 1992 again has 아이스크림 (aisŭk'ŭrim) "ice cream" and not 얼음보숭이 (ŏrumbosung'i). The 1992 dictionary also has 에스키모 (esŭk'imo) "eskimo", which in North Korea is a popular everyday word for "ice cream" which comes from a name of a brand that was popular there.
You have plenty of examples of South Korean language authorities introducing "purified" (often pure Korean) words to replace loanwords, which don't necessarily catch on. For "stapler", the official South Korean dictionary has the pure Korean translation 찍개 (jjikgae), for instance. But I have never seen this term in the wild—instead, people say 스테이플러 (seuteipeulleo) "stapler", or more commonly, 호치키스 (hochikiseu) "Hotchkiss". There is a limit to how much official language policy can dictate actual usage, whether it is in North or South Korea.
Would you happen to know anything about the usage of konglish in North Korea then, as in words besides 아이스크림 or 에스키모? Is it more frequent near the border or just as spread through as it is in SK?
However, there are often differences in the spelling of such loanwords between the North and the South. So you have 프로그람 (p'ŭrogŭram) in the North but 프로그램 (p'ŭrogŭraem) in the South for "programme", 텔레비죤 (t'ellebijyon) in the North but 텔레비전 (t'ellebijŏn) in the South for "television", and 미싸일 (missail) in the North but 미사일 (misail) in the South for "missile". This is due to the fact that the standardized spelling of loanwords (a problematic and much debated area of Korean orthography) was frequently reformed in South Korea, and probably in the North as well, so the principles of spelling have turned out quite differently between the two. Also, as North Korea uses a lot of loanwords from Russian, even loanwords originally from English tend to be absorbed in the Russian pronunciation, such as 땅크 (ttangk'ŭ) for "tank" or 뜨락또르 (ttŭrakttorŭ) for "tractor" as opposed to SK 탱크 (t'aengk'ŭ) or 트랙터 (t'ŭraekt'ŏ) which is closer to the English pronunciation.
The official language policy in both the North and the South tends to discourage loanwords from English, but it seems a bit more successful in the North, especially when it comes to post-1945 loanwords. If you only focus on the differences between the North and the South, then you see many cases where North Korea uses native Korean words whereas South Korea uses loanwords from English. But you can't extrapolate from that and conclude that North Korea doesn't use loanwords from English at all. This would be a misconception, just like the false notion that North Korea doesn't use Sino-Korean words.
Didn't know about the Russian pronunciation thing, is 도꾜/도쿄 also included in that?
There is no reason for there to be a difference in English loanword usage in North Korea between the border area and the far far North. Remember, the DMZ is a tightly sealed border and there has been virtually zero cross-border exchange that would influence the language since the Korean War. If we were talking about normal national boundaries with some cross-border linguistic exchange then there would be a gradient of linguistic features taken from the neighbouring state near the border and diminishing as you move away from it, but with the DMZ there is no such thing.
찍개 is a recent South Korean neologism for 'stapler'. There is no reason that North Korea would use the same word. I don't know what they call staplers in North Korea, though.
Once again, the point is that English loanwords were being used in Korean before the division of the peninsula, and afterwards, North and South Korea followed completely separate paths of linguistic evolution. There was no way for people near the border regions to be influenced by what people were speaking on the other side. You might flip the question and ask whether South Koreans near the DMZ are more likely to use pure Korean words due to North Korean influence, and again the answer is no for the same reasons.
도꾜 is the traditionally common spelling for Tokyo that is based on maximum phonetic similarity. In South Korea, the spelling was reformed to 도쿄 to conform to standardized rules about how to write Japanese loanwords, where all non-initial "k" sounds were to be mapped to ㅋ. So this is more of a phonemic spelling. Roughly speaking, "phonetic" refers purely to the sounds, while "phonemic" goes into the more abstract level of grouping the sounds that are considered mere variations of a single sound to the speakers of that language. However, due to widespread resistance, the South Korean reform didn't go all the way in making it phonemically regular—otherwise, we would be writing 토쿄 instead, using ㅌ everywhere for "t" (in concession to the traditional practice, we write ㄷ for initial "t").
This reform took place in the 1980s in South Korea, and didn't affect North Korea, which still writes 도꾜 for Tokyo. It has nothing to do with Russian pronunciation. If we imitated Russian pronunciation, it would come up as something like 또끼오 or even 또끼워.
In practice the orthography is sort of a middle step between the hanja spelling for many morphemes and their pronunciation. Multiple hanja end up mapping to the same hangul block because they're homophones, so there's some information loss, but spelling is morphemic enough that you can recognize the same morpheme in different arrangements. If you can guess what hanja it might be though you can often understand a word more deeply.
What's interesting about North Korea is that they force Korean words on everything. For example, a word will spell the same in South Korea and can only be differentiated by context, intonation and use of chinese characters. Newspapers in South Korea is a good example of this as it almost requires a basic knowledge of traditional Chinese characters. North Korea seems to have none of it and has a political agenda to "purify" the language and it leads to lot of weird looking Korean words and leads to confusion.
Kaesong was also the capital a long ass time ago during the Koryo dynasty which was overthrown in a coup and Chosun dynasty was created by a general (we'll see the same thing in 1960s creating the modern ROK). The longest reigning and oppressive regime. North Koreans still refer to themselves as Chosun people and much of modern Korean identity lends from this era. The word Korea also comes from Koryo or Coree in French.
> Both his forum posts and his comments in the bitcoin source code used such Brit spellings as optimise and colour.[1]
I am surprised that the article doesn't end here. Other press reports have highlighted that there is classified evidence that has not been disclosed, and it seems odd to me that Schneier would play this aspect down in a story involving cyberattacks, North Korea, the FBI and the US intelligence community.
If anything should be learned from the Iraq debacle, it's that.
Not sure if you heard the news, but Bush quickly invaded Iraq. I think it's safe to assume he was taken seriously.
> which may explain why some US citizen boycotted French products after we said we would create a worldwide axis against war.
Some US citizens just like to complain about foreigners to be more patriotic (as if that would help). I would doubt most people could explain anything about french foreign policy.
I didn't think Saddam was a serious threat to the west at the time, but the relentless hype did make me think it over one night: what if? And then I saw that anything asymmetrical he could do would quickly result in his destruction. Even if he had all the dirty weapons possible at his disposal, he wouldn't have been able to use them.
And, of course, what came out later makes governmental prognostications now from secret evidence almost impossible to believe. Western governments, in particular US and UK, lost their credibility. Secret evidence is used for political purposes, not for security. The case for covert interception of communications is severely weakened. Probably even our security is damaged.
Why would you blindly "just trust them" when there's enough history to show that skepticism is a much healthier attitude.
This doesn't change anything I said, though. Regardless of where it comes from, "hidden facts" from agencies with an agenda that don't necessarily align with citizens are not to be automatically trusted.
But they really, honestly had reason to believe that Iraq had WMDs (yes there were doubters and skeptics, and of course they get the bulk of the attention after the fact, but many actually believed it).
Aside from defectors and people trying to lie their way to something, add that Saddam himself wanted the world (particularly Iran) to think that the Iraq government had WMDs. Iraq believed that having WMDs was a good defense (a good example since then is North Korea), so they tried to play the middle ground where they could seem to have WMDs hidden away, and could act as if they had that ace in the hole, but they would play along with UN inspectors just enough to try to avoid an attack, adding just enough mystery to the whole thing that there were open doubts. Intelligence is tough when the person you're trying to prove is doing something is also trying to convince you that they're doing something.
The game of chicken didn't turn out well. But the recurring narrative that innocent Iraq was all along say no no no look where you want and the US invented the situation is historical revisionism.
Historical revisionism is polls showing a huge percentage of Americans still think Saddam was involved in 911.
USA had no business invading Iraq (nor practically any other country, for that matter) and using the excuse that "Saddam claimed he had them to look tough" in order to justify so many tragedies (mostly foreign but also American) is egregious.
When someone performs threat assessment they do it based on facts and not on posturing or they'd prosecute every internet troll out there.
ugh. I'm going to stop now because I'm pissed but I'm going to let you know that you're basically apologizing for crimes against humanity with what sounds like kinder garden excuses.
I don't think the US should have invaded Iraq for purely pragmatic and financial reasons. That does nothing to change the actual complex, convoluted reality that led to the decisions that were made, and then the long and fruitless, but very intense, search for WMDs after the attack.
President George W Bush led the US into war in Iraq on the back of assertions that Saddam Hussein had recently-built weapons of mass destruction, supplies that had only increased in the aftermath of the 9/11 terror attacks.
Yet all the chemical weapons found by soldiers were manufactured before 1991, the Times reported. They consisted largely of 155-millimeter artillery shells or 122-millimeter rockets – not designed for mass destruction, and produced in the 1980s during the Iran-Iraq war.
According to the Times, the reports were embarrassing for the Pentagon because, in five of the six incidents in which troops were wounded by chemical agents, the munitions appeared to have been “designed in the US, manufactured in Europe and filled in chemical agent production lines built in Iraq by Western companies”.
http://www.independent.co.uk/news/world/americas/iraqs-hidde...
The text you quote confirms chemical weapons but not weapons on mass destruction
In his evidence, the former Downing Street communications director rejected suggestions that he had been asked to "beef up" the dossier on Iraq's weapons of mass destruction and said its purpose had not been "to make a case for war".
But Major General Michael Laurie, who was the Ministry of Defence’s director general, intelligence collection, from 2002 to 2003, told the inquiry that making a case for war was “exactly its purpose”.
Maj Gen Laurie added that he and his colleagues were told that a previous intelligence dossier “did not make a strong enough case” and for months he was “under pressure to find intelligence that could reinforce the case” for war.
His evidence, which is the first time such a senior intelligence officer has directly contradicted the Blair government’s official line on the dossier, will restart the row over whether Downing Street “sexed up” the September 2002 document to persuade the public and MPs that the 2003 invasion of Iraq was necessary.
Maj Gen Laurie’s comments were made in private last year and have only now been published by the inquiry chairman, Sir John Chilcot, along with newly-declassified government memos and other evidence heard behind closed doors.
http://www.telegraph.co.uk/news/worldnews/middleeast/iraq/85...
edit - also note that this is from The Telegraph. Whatever else they are, they are definitely not conspiracy minded anti-establishment types.
Firstly, what the British government did or didn't do is not really relevant to conversations about the US government.
Secondly, even if the UK government were at all relevant to this conversation, telling someone to "read up" when providing information that doesn't remotely contradict what they're replying to is terribly boorish behavior. Note that I didn't say that the government had compelling evidence -- I said that they read the tea leaves and got the impression that there were WMDs. Yes, this overriding belief will make intelligence that might be a collage of coincidental and second-hand things perhaps seem more consequential than they should have been. But regardless, the overarching belief was that Iraq legitimately had a WMD program and stockpiles, courtesy of the Saddam regime trying to convince everyone that such was exactly the case.
If you actually think that regarding this subject, then you have not looked into the events leading up to the Iraq war at all, and you definitely should read up on it more.
Because the former was classified, when congress decided to go to war, they were not presented with the DOE's findings. Only the CIA's.
If not nefarious, what would you call this? Convenient?
However why don't you contrast your comment with mine. Are you actually countering anything I've said?
No, you actually aren't. But somehow in these sorts of black/white discussions people think they can find one sort-of thing and then say "aha". Hardly.
Since you seem to disagree, I wanted to know how you classify the hiding and twisting of this, and other pieces, of information.
Also, you need to realize that not everyone viewed the administration in the same light as you apparently did back then. My peer group was split close to 25/25/50 on them being: lying bastards, well intentioned but full of shit, and justified. But we were only in our early 20s. Older people seemed to be more accepting of what they were saying.
As usual, incompetent American intelligence was used instead since it was convenient.
This is a neat turn-around. Historical revisionism. That's good.
http://en.wikipedia.org/wiki/United_Nations_Security_Council...
Iraq's cat and mouse game with the UN, which was a condition of the ceasefire from GW I, had been going on for years. The UN had passed resolution after resolution authorizing force, any of which gave the US -- if they even decided that they wanted its mandate -- the legal right to remove Saddam. Yes, when it was apparent the US had had enough, Iraq started complying, but it was too late for the US administration. Tough, but this notion that it was all cooperation and the US just wanted a fight is pure absurdity, and has absolutely no basis in actual reality.
But it does appear in the black/white simplified story that so many tell.
For what it's worth, it's entirely possible that we were just exposed to different media narratives at the time. My parents remember it the same way too. The news about the reports from Hans Blix and Mohamed AlBaradei saying Iraq was complying with the requests of inspectors after Resolution 1441. Colin Powell's so-called evidence. These were front-and-center in The Hindu in India and there were editorials about it all the time.
Certainly the idea that the doubters were few is not particularly convincing in the face of that.
EDIT: Ah, you edited your comment to contain more than just the first line after I began replying. FWIW, I don't think it's US-Evil Saddam-Good. It's obvious to me that people were questioning the degree to which US military action was justified.
Quoting Resolution 1441 is a bit disingenuous since from the very day the US decided to attack Iraq there were people saying that it did not justify military action. In fact, I recall that they fell back on using it as justification after it became clear that any resolution asking for war would not pass.
It was actually the finest in British confectionery, with lashings of custard.
http://www.historycommons.org/timeline.jsp?timeline=niger_pl...
It's your choice whether to take these guys at their word in any particular instance. But some of us don't take their word alone as evidence for much, unless it's backed up by evidence which stands up to independent review.
NSA lies to senate about surveillance on U.S. citizens living inside the country: http://www.politifact.com/truth-o-meter/article/2014/mar/11/...
CIA lies about torture and it's effectiveness: http://www.nytimes.com/2014/12/10/opinion/the-senate-report-...
FBI lies to U.S. courts about surveillance records: https://www.eff.org/deeplinks/2011/05/fbi-chastised-court-ly...
To blanket dismiss any statement as untrustworthy is unwise and misguided.
They will claim this to get out of some clerical error. They will claim this for anything. It's unverifiable, it's unbelievable, it's a wonder any publication with some journalistic integrity left would read anything into it.
Here is attorney general Holder invoking state secrets to cover up what was eventually revealed as a lowly FBI clerk checking the wrong box:
http://www.wired.com/images_blogs/threatlevel/2014/02/holder...
This wasn't even an important case! Think what these people will do when the stakes are higher.
Moreover, basically what he's saying is there is more than one possible probable actor whereas the FBI discounted the rest. It's not that insightful.
Schneier is a pretty smart guy, but like everyone else has biases (I mean, tendencies). Not saying he's wrong here as I, as most everyone, have no first or second hand knowledge about this incident. Just saying that just because it's Schneier does not give him any more credibility in this than anyone else, unless he knows something about this incident most people don't know.
When someone talks about security, and links to Schneier, I give their argumet more credit. If they link to GRC I give them less credit, and sometimes I dismess their comment.
I realise this is a bad thing. Gibson is going to be right occasionally and Schneier is going to be wrong sometimes.
But is this a generally sound policy? Find the experts and "not-experts" and decide how much time to spend investigating what they say accordingly; or should I be evaluatin arguments equally regardless who makes the arguemtn (with exceptions for obvious trolls and wingnuts)?
But, to your question. I think we should question everyone one's assertions. Lots of experts, I mean true domain experts, will opine one way, just to be wrong down the road. So, maybe being an expert gives them an edge over a non expert but it does not make them automatically right.
The fallacy still applies when the authority gives an opinion on some topic they are knowledgeable about; the fallacy isn't about the relevance of the authority so much as the use of the appeal.
This is incorrect. An appeal to authority is when an argument is claimed to be true because someone of authority has stated it. It is a fallacy when the authority of the person has nothing to do with whether the argument is true or not. For example, if a maths authority makes a maths claim, that doesn't mean their claim is true since their authority in maths doesn't determine the validity of their claim. The truth of their claim is determined by looking at the maths itself.
> Citing Schneier on computer security is not an appeal to authority.
It could be, if you're arguing that it's true because Schneier said it. Obviously something relating to computer security isn't true because Schneier says so.
That said, appeals to authority are somewhat necessary in discourse, since we don't have the time to explore all arguments on their own merits. I believe that claims that Schneier has made in the past are truthful, and therefore conclude that I can place some trust in other claims he makes without fully exploring them, but that trust may be misplaced.
I'm just glad someone with credibility was able to come out and say it, I just hope (but doubt) that mainstream media will follow up on it and ask the right questions going forward.
> It's possible, but that employee or ex-employee would have also had to possess the requisite hacking skills, which seems unlikely.
Considering the number of laid off techies, I think it is somewhat "more than unlikely".
I don't know where you got the second part.
But I also think his skepticism is spot on. This "explanation" is too conveniently tidy for me to find it all that believable.
N Korea has the motive, means, and track record for this kind of thing. And please let's all agree such hacking is not some impossible rocket science. Any group of young teens/hackers with enough time could've pulled it off. Especially such a relatively easy target as sony.
Oh by the way, N Korea did launch a mid range ballistic missile (albeit a crude one).
In future, if some Hollywood studio makes a movie on Russia's Putin or on China and if hackers claiming from the injured country do similar cyber-attack on that studio and If USA retaliates and if Russia/china counter-retaliates and if this spills into physical world, then we can have nightmarish situations/tensions and may be full blown war. Worse, another country may do that sort of attack from some other country to hide its trail. Hope proper sense and calm minds prevail to prevent such nightmare. But such possibility exists in theory.
As solution, world needs an international, independent, competent panel/forum/group to investigate openly/transparently all cyber-attacks and find out culprits rather than doing mere guess work. Also, evidence of the crime need to be put in public domain to avoid conspiracy theories. This can be on the lines of international court of justice/United nations ...etc. Since parties involved are entities like Sony which are not connected to national defence directly, we need not fear national secrets leaking out ...etc i.e. it can be done without impacting the sovereignty of the nations involved.
Without such arrangement, stability and peace of the world will always be in question for any cyber attack on any major country such as USA/Europe/China/Russia ...etc.
TL,DR: Cyber-attacks on economic entities such as Sony or Google in the past involving several countries need to be investigated by international body rather than a single country and evidence of the crime need to be in public domain to avoid conspiracy theories.
I do agree its a good possibility the government has a lot more classified evidence it's not sharing with us, and we're trying to put together a puzzle with only half the pieces.
It seems like Sony is playing up the North Korea connection because it could only help them. They would lose more credibility (and potentially lawsuits [1]) if it's a 14yo hacker doing it for the lulz. State sponsored hacking is a Big Deal, and many would give leniency to Sony if that's a true story.
[1] http://abcnews.go.com/Entertainment/wireStory/sony-faces-4th...
North Korea was well aware of The Interview ahead of the hack. See this article from June: http://www.theguardian.com/film/2014/jul/10/north-korea-un-t...
I personally think this is a misinterpretation of what happened. Media began heavily speculating it was tied to The Interview about 1-2 days after the hack was initially reported, but the hackers waited until Dec. 15 before explicitly mentioning it. If they wanted to take advantage of the sensationalism, why continue releasing messages and threats that clearly acknowledge Sony and the media between Nov. 24 and Dec. 15 while not mentioning The Interview until the most likely motive essentially became obvious?
Second, I think the group name "Guardians of Peace" is a fairly obvious allusion to "guarding international peace by preventing Sony from releasing The Interview", and is in line with just about everything they've been saying. And of course they were using that group name on day 1.
I'm not saying North Korea necessarily did it, but I think the actors either intended to stop the movie from the beginning, or intentionally framed North Korea by using a pretext of trying to stop the movie. I don't think they're a group of hacktivists who only appropriated The Interview as a motive after media speculation.
There's nothing obvious to me at all in that name referring to the things we later learned. It's a really generically vague name, so it's easy to project onto it.
> This is the work of independent North Korean nationals.
Mr. Schneier doesn't clearly understand people who lived in a totalitarian country. If this national lives in North Korean, there is no way he will dare such an attack without being instructed by the government. This level of freedom doesn't exist in his mind. And it doesn't make sense for a North Korean still holding the same ideology to live outside North Korea, he would either completely abandoned that or go back to North Korea.
> This is the work of hackers who had no idea that there was a North Korean connection to Sony until they read about it in the media.
This doesn't explain the Korean language used in the code. It might be a South Korean, but from my knowledge, it's very hard to imagine a South Korean risking going to the jail either fighting for North Korean or even find it fun. (Hint - South Korean people don't like the people from north who are pointing Thousands of cannons and missiles to them). As for why this is not the same encoding as North Korean dialect, I know people from mainland China use encoding of Traditional Chinese from Taiwan. It is very easy for me the imagine that North Korean government offices use such settings so that they can access resources from South Korea (much more abundant and still without language barrier.)
> It could have been an insider
This hacker has been hurting regular Sony employees. From my understanding, only people with mental problems will direct their hatred towards a company to random regular employees (his own ex-coworkers). People with mental problems don't usually possess the hacking skills demonstrated in this case.
> The initial attack was not a North Korean government operation, but was co-opted by the government.
It is hard to imagine a hacker targeting Sony with the plan to profit from selling the information to North Korean government and then intentionally leave some trace towards North Korea (the Korean language in code). This attack must have originated from North Korea, and that's the conclusion FBI is suggesting.
Depends on the mental problem. The category is far too broad to make a sweeping statement like that. Anything from being slightly narcissistic to being a paranoid schizophrenic can be considered a "mental problem" under one definition or another. Most of these do not involve any diminished technical skills.
In addition, I could cynically retort that anyone who orchestrated such a reckless and damaging attack as this isn't exactly the most mentally stable.
On the other hand, historically the view of Japan as the important enemy is more strongly associated with the North. Fighting the Japanese occupation was probably a more important part of Kim Il-sung's political life than socialism and much of the divide between North and South was based on collaboration with occupiers than on a love/hate relation with capitalism...most Koreans in both countries at the time their civil war was hot were agrarian peasants.
25% of Koreans in Japan align politically with the DPRK - http://en.wikipedia.org/wiki/Chongryon
The rawdisk driver linked into Wiper is a reusable, publicly-available one, which has been used for many purposes including legitimate ones, and was written by someone from South Korea. That was compiled with a Korean locale (as you'd expect).
The result is a bit like saying Duplex Secure wrote Alcohol 120% because it uses the SPTD drivers - an invalid conclusion.
Unless of course they got a bargain on a VPS somewhere else..
It's well known NK had been complaining about the movie for months. And I doubt NK started hacking only 2 weeks before scheduled opening day.
Somehow I doubt that any supposed North Korean hackers would have followed the tenets of free software and distributed the original source to Sony along with the malware.
"strings is mainly useful for determining the contents of non-text files."
It's not. Sometimes, for international relations, things are classified, never released until much later. Having been party to a minor agreement, at least knowing about it, before the general media, gives you a ton of insight into how the USA operates.
To me at least, I came to the, "Business," operating model. In other words, the economic engine takes priority and the agreements I know of that were signed pushed that particular agenda.
Dollars, literally, make the world go round. The US dollar is the world, "Reserve," currency. There's a very good reason for that, and a very good reason the Secret Service is in charge of the US money supply.
Then again, perhaps I'm as much as insider as the author of the blog post. Eg, out of the loop.
* long sigh *
Happy festivus!
edit - looking at it again, jcd748 failed on accuracy as the earth does not lack inertia but rather possesses it in great quantities. 8.04×10^37 kg·m2, to give a rough figure.
My thought is we'll probably never know for certain unless perps reveal themselves, so saying NK definitely did it would be jumping to conclusions.
The real story is: Best. Marketing. Ever. And an international incident, to boot! (Well played, Sony. Even Obama was part of the story.). Seriously, the canceling the release was the story-making move. And the subsequent nonrelease release monetizes the situation. Couldn't have planned it any better. ;)
Satire - making fun of any alternative explanation that obviously isn't true.
Maybe I should be more literal next time.
Merry Xmasmukah and new year!