Personally, I think just mentioning that part of the evidence came from the Behavioral Analysis Unit proves that NK's ties to this are definitely shaky.
Personally, I think just mentioning that part of the evidence came from the Behavioral Analysis Unit proves that NK's ties to this are definitely shaky.
I understand knee-jerk anti-US comments are karma gold here, but I don't think you guys realize how ridiculous you sound to the rest of us. I think its pretty difficult to arm-chair analyze this stuff and come out with a definitive answer, especially considering a lot of this stuff will never be declassified, but the Alex Jones-like conspiracy thinking here really brings the discourse down to a reddit-like level.
Purely from an Occam's razor perspective, the country that attacked this film and warned of consequences if released-- consequences that actually happened, is probably at fault here. This analysis of how it must have been anyone but NKorea, especially considering NKorea's reputation, is highly questionable to the unbiased observer.
As far as consequences that actually happened -- Do you mean to say that theaters that showed the film were bombed? Or are you referring to embarassing email leaks which would have no doubt been released anyway?
Second, if you need to set up a fall guy, then implicating a nation state as historically secretive, aggressive, and isolated as the North Koreans is actually a pretty good idea.
"Do something bad and blame the weird kid" isn't a new idea.
I don't know who did it, but both arguments seem plausible.
Also now after Snowden everything the USG does is to be doubted (I'm guessing since his revelations affect the internet and this is the first issue that has directly affected people on HN), and now everything they do can somehow be traced back to trying to suppress, hamper, weaken and spy on you via internet.
Watching the theories that somehow we'd try to use N Korea who have zero value economic value to the USA, or actually posing a threat as some kind of scapegoat to hinder online speech is more entertaining than anything else.
That's where political discussions inevitably and invariably end up. Probably best to just flag these articles.
How can the US claim to be a republic when it doesn't even bother to justify its actions to its people and their representatives?
This is an oft-repeated claim that is sorely in need of justification. Especially in this case, where the attack is purely digital.
My wife worked in Navy intelligence for six years. She was privy to classified information. She, at times, knew where information was coming from, and it is obvious that the information itself would have implicated its source if it were to be released.
I'm not saying that's the case here. I'm pretty damn skeptical of my government as well. That said, the Fed is under no obligation to reveal all of the information it has. I think we'll be in the dark on this one for some time unless things change in such a way that would require more information to be released.
I strongly dislike this paternalistic approach, and I'm rather tired of the people being treated like children. We know things are complicated. We know geopolitics are more complex than "USA good, NK bad" or vice versa. They could say a lot more than they are saying without compromising their intelligence gathering capabilities.
If the US government wants support and trust, it needs to earn it from every new generation of citizens. If it doesn't care about support and trust, it has overstepped its bounds as a representative government and should be reeled in.
The correct response to "who was responsible for this" is "who cares". The FBI seems to think it matters, so people are refuting their evidence. And are reasons for that.
The government has no credibility in this area. Iraq didn't have weapons of mass destruction. This has the same ring to it. They have a lot of the same incentives. It doesn't even matter whether they're intentionally misleading us or just incompetent, the solution in either case is to disregard whatever they say.
And they can't actually tell where the attack came from. That's not how it works -- especially if the attacker is trying to disguise their true location as they have every incentive to do. Computers in North Korea are not immune from the myriad Java and Flash vulnerabilities, and once you pop one machine you can put ssh on a VM and stage your attack from it. Distinguishing that from the attacker being physically in the same room as that machine is not going to happen based on an analysis of network traffic or anything to do with IP addresses. Anyone who claims otherwise could be malicious or just wrong, but it's at least one of those.
None of that proves it wasn't North Korea. The point is that it doesn't matter. What are you going to do differently if it was, as opposed to being some troll in Florida? The only sensible things to do are the same in either case. Stop using ridiculously bad passwords, etc. What changes if it was North Korea? Are we going to invade? Should we give the FBI new powers of cyber warfare? That's what people are afraid of, because those are profoundly stupid ideas.
(Not buying "sources and methods" as a reason for failure to disclose in this case -- I may not know what IP addresses are conclusively tied to North Korea, but the North Koreans themselves certainly do, and they must assume that the NSA does as well. Particularly if, as Comey claims, the use of those addresses "unshielded" was an error that they immediately recognized as such, and rectified post haste.)
Everyone knew that North Korea had it out for Sony, what's to stop a network security enthusiast from stirring the pot by performing the attack and planting "evidence" that it was coming from North Korea. I don't think it's far fetched to think that many young security enthusiasts would get excited to think about causing such a stir.
I don't recall Occam's razor ever applying to politics.
Shaky evidence? You bet ya. (and it seems this is the only evidence offered as an explanation so far)
Also, if N. Korea really was behind this "attack" of a private company with no US Gov't ties, why would they not claim responsibility and tout their "Cyber Attack" skills? They do for just about everything else (even failed missile launch attempts). Fear of retribution? No way, this is/was a private company... the US Gov't could not respond with any kinetic weaponry attack and look good on a geopolitical scale.
N. Korea also offered to send personnel to help the FBI in the attack investigation, which is extremely uncharacteristic of N. Korea to say the least... normally they'd just praise the attack flatout.
What is _easy_, however, is determining which country is using a given IP address. Particularly when the searching party is a superpower and the country they're investigating is known for having very few links to the Internet. And what connections they do have are severely restricted. I imagine it would be very difficult to find a reliable, exploitable proxy server inside North Korea that is accessible across the public Internet.
They offered to help investigate the Cheonan after they sunk it. So it's really not uncharacteristic.
And why do you have attack in quotes? Do you believe Sony wasn't actually attacked?
No, I think it's plenty clear that they were. It's just that "attack" has a certain stigma to it, and what happened to Sony was not some grand attack, but rather a run-of-the-mill hack against a company with extremely poor security.
It's flat out wrong to blame some small and non-credible-threat country for something they likely had nothing to do with just to advance a political agenda.
North Korea is not a great country... but that doesn't mean a "global leader" like the USA can just pin something on them with zero evidence.
I'm not a fan of the US' foreign policy in some ways, and certainly place no blind faith in the declarations of the government, but, that doesn't exactly make North Korea the 'good guys'...
http://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?Ne...
http://en.wikipedia.org/wiki/North_Korea_and_weapons_of_mass...
Their nuclear program claims it has a range of 4,000KM, but to reach the USA it would take about 10,000KM. Not to mention their last missile launch test could not even escape their border.
That's what I mean when I say non-credible threat; they are incapable of inflicting meaningful harm to the USA. They are really all bark and no bite...
> oesn't exactly make North Korea the 'good guys'.
Of course not. Nobody said they are -- they just simply aren't the "bad guys" we are looking for in this specific case.
I don't think a failed experiment is evidence that they're incapable.
Did you know that a couple of years ago, NK launched their first satellite: http://en.wikipedia.org/wiki/Kwangmy%C5%8Fngs%C5%8Fng-3_Unit...
and the missile used (Unha 3) has a 10000 KM range and is capable of reaching the western US (with at least a 200kg payload): http://en.wikipedia.org/wiki/Unha
Regardless, the flight characteristics of a space-bound launch vehicle are far different from an ICBM, and are very easily detectable and intercepted by just about all countermeasures.
They would be more of a threat to South Korea of an attack than on US soil. To the US, they are a non-credible threat.
You seem to be awfully certain. Frankly, I have no idea and am quite skeptical of people who profess such certainty in the face of so few facts. Seems to be the kind of thinking where you have a conclusion and look around for facts to support it.
Perhaps I overspoke a tad. I'm awfully skeptical is better put.
We're largely a scientific community here at HN. Something is False until proven True. You may have a hypothesis, but it's just that, an educated guess as-to the result.
To prove something True you must present overwhelming evidence. We have none of that here... What we do have is a hypothesis being perpetuated as fact in the face of almost zero concrete evidence.
The FBI first says "there is zero evidence to suggest North Korea has anything to do with the hack". Then some "high level anonymous White House official" "leaks" to the NY Times that they believe it's North Korea, and it takes the FBI 3 full days to change their public announcement, yet present zero concrete evidence. This was a rudimentary hack against a private company, there's nothing that would be classified or kept top secret here. Sony should do a full disclosure. Until then, we can not be certain of anything.
If Russia et al had the ability to covertly do that...why attack Sony....why not big financial institutions or other such high profile targets....
This is the "secret sauce" that the FBI says they cannot tell anyone imo. Doing this is nothing new and I am sure they've been doing it for ages though.
The problem is that if you assume the FBI is doing this ( which any skilled hacker would assume ) then you can easily get around it by sending a sequence of instructions ahead of time, and then having them playback at what seems like a reasonable rate at a later time. ( making it seems as if you are on site and didn't set it up ahead of time )