North Korea’s Naenara Web Browser: It’s Weirder Than We Thought
blog.whitehatsec.com
blog.whitehatsec.com
They use the same tracking system Google uses to create unique keys, except
they built their own. That means the microtime of installation is sent to
the mothership every single time someone pulls down the anti-phishing and
anti-malware lists (from 10.76.1.11) in the browser. This microtime is
easily enough information to decloak people, which is presumably the same
reason Google built it into the browser.
Anyone know what mechanism this refers to?https://developers.google.com/safe-browsing/developers_guide...
Also, I kind of dislike the alarmist tone of this paragraph. Saying that google's anti malware blacklist (used by all browsers out there aside of IE) is a secret plan to de-anonymize people by using a microtime of a request timestamp seems... far fetched.
The per-user key does allow the entity operating the blacklist to easily detect any user who's moving between network access points. This is known. The feature is and was always stripped out in stuff like Tor browser for that reason.
There's good reasons to believe it wasn't malicious (it was necessary for secure updates pre-universal-HTTPS, and was removed as soon as HTTPS was deployed universally at Google), but it's also not really arguable it could be used for that purpose, either.
Uh, not really. Tracking users is at the heart of their business model.
Do they actually manage to make significant profit on retargeting or some other ad technique that requires tracking? What can they do beyond tracking?
I actually worked on a vacation rental site for some time, and as a result of queries I did for research, I ended up "only" seeing ads for one of the major companies in the sector for weeks on end.
But there is of course potential for abuse if someone gets hold of that data.
There was recently an article on using HSTS as a sort of super cookie. Yet it doesn't seem to actually be in use[1].
There is a lot of rumour around Google. For example that they use Google Analytics data for ranking. Yet it rarely comes with any proof.
Google makes a significant portion of revenue from their content network, which are ads that are displayed on other websites. They also offer remarketing, which allows an advertiser to display their ads across the content network to people who have visited the advertiser's website.
At the very least, remarketing requires tracking.
Furthermore, the API in question (https://developers.google.com/safe-browsing/developers_guide...) has been deprecated and superseded by a new one that doesn't contain any user specific data (https://developers.google.com/safe-browsing/developers_guide...)
eyeroll If they were above being sneaky and operating under false pretences they wouldn't have blatantly ignored "do not track".
I'm sure they will never feel like they have enough means of tracking users, either. Every means they develop helps improve their targeting, puts them ahead of their competition and has a direct impact on their bottom line.
https://bugzilla.mozilla.org/show_bug.cgi?id=368255
According to Mozilla this cookie is only used by the Safe Browsing client code and isn't sent to Google through regular web browsing (private mode or otherwise). However, the Lumber Cartel (there is no Lumber Cartel) wood be able to use this cookie to fingerprint web browsers and so track people as they move among Internet connections. Those of us who are double super extra paranoid disable Safe Browsing in order to prevent this.
According to Mozilla...
Firefox is open source, you know. Even if you can't read C++ or understand the Bugzilla comments, you can also just Wireshark it.
I spent two weeks traveling around in North Korea in August 2012. One of our visits were in a military museum that had computers available (actually running RedStar OS!), containing some CD/DVD with MOV files (as far as I remember) and some other things.
I remember the machine having a 10.x IP address but it was definitely not able to access any internet, but I wonder if it was connected to their actual intranet, or if they simply had some local network there.
* They apparently have something resembling a dating website.
* They can download computer games (my tour guide complained that his son spent too much time playing them).
I haven't been, but from what I've read/seen the tours are almost like an orchestrated front aimed at changing foreigners' perspectives.
I'm certain that part was sincere. There is a certain level of naive honesty among most of the North Koreans (similar to that of sheltered fundamentalist Christians). I could clearly detect this by seeing that some of them naively did or said the "wrong" thing a few too many times whereas others were clearly much more canny. The canny ones lied all the fucking time and probably knew they were lying. The naive ones let slip a few gems.
The 'dating' website is probably more like a website for arranging arranged marriages, incidentally. Just in case you were wondering.
>I haven't been, but from what I've read/seen the tours are almost like an orchestrated front aimed at changing foreigners' perspectives.
The tour is orchestrated and it is clearly partly aimed at changing foreigners' perspectives, but the parts which are just for show and the kernels of honest truth are actually pretty easy to distinguish.
Sometimes propaganda is embarrassingly terrible (e.g. just taking the number of actual US casualties in the Korean war and doubling it. facepalm).
I'm sure the years before I went were even more blatant and terrible, actually. I didn't see any fake shops like in the interview but I suspect they may have existed in the years prior to my visit. I think they probably figured out that that was an abysmal idea.
The North Koreans have very unsophisticated domestic propaganda compared to western domestic propaganda. They are NOT good at it. Getting better, but still terrible.
Interestingly, western propaganda about North Korea is equally facile. The isolation makes it easy for outright lies to be believed on both sides I guess. Provided you haven't experienced both.
Also there are certain things both sides refuse to talk about that the other side talks a lot about - propaganda that serves a purpose that is based in truth. North Korea doesn't talk about prison camps but every American knows about them. America doesn't talk about atrocities committed by GIs in the Korean war, but North Koreans schooled on them much like we are schooled on Nazi atrocities.
Weirdly, North Korea was pretty open about the famine in the 90s. I expected them to gloss over it. Western media glosses over the fact that it actually ended, of course.
>I was always under the impression they were just pretending that they owned large blocks of public IP space from a networking perspective, blocking everything and selectively turning on outbound traffic via access control lists. Apparently not
It was always public knowledge that NK has more or less one publicly routed /22. That's far removed from "large blocks of public IP space".
> This microtime is easily enough information to decloak people, which is presumably the same reason Google built it into the browser
I doubt that was Google's intention behind the Safe Browsing API (https://developers.google.com/safe-browsing/developers_guide...)
>So every time the browser fails for some reason they get information about it. Useful for debugging and also for finding exploits in Firefox, without necessarily giving that information back to Mozilla – a U.S. company
Or if could be that most of the users of the browser in question do not in fact have full internet access and thus no reports would be sent anyways. Also, FF 3.6 is long out of support, so by getting access to these crash reports, the people behind Naenara get a chance at fixing issues (I'm not saying they do or don't, but getting the crash reports directly is the only way for remaining crashes to actually be fixed)
>. Could the mothership be acting as a proxy? Is that how people are actually visiting the Internet – through a big proxy server?
very likely, but not because of the way the URL for the startpage is formatted. That's just a convenience thing I guess where they ran wget or any other crawler against the original site and then they could just prepend their internal server to to URL and keep the patch to Firefox minimal.
>it’s still very odd that they haven’t bothered using HTTPS internally
They just don't care if "normal" people could potentially sniff each other calendars. If the government wants access to the calendar, they just look the data up I guess and because this is all a big intranet, the traffic doesn't cross any non-goverment-owned routers anyways.
>This one blew my mind. Either it’s a mistake or a bizarre quirk of the way DPRK’s network works but the wifi URL for GEO still points to https://www.google.com/loc/json*
Likely none of the sites the browser is actually able to visit actually use the geolocation API, so they just forgot to change the URL. It's an interesting bug, but far removed from mind-blowing IMHO.
>That’s actually a good security measure, but given how old this browser is, I doubt they use it often, and therefore it’s probably not designed to protect the user, but rather allow the government to quickly install malware should they feel the need. Wonderful.*
I'm sure they have other methods of installing malware that then would run as a privileged account, not the unprivileged user account running Firefox itself (their OS doesn't officially allow root access as we've seen in yesterdays article).
>It is odd that they can do all of this off of one IP address. Perhaps they have some load balancing but ultimately running anything off of one IP address for a whole country is bad for many reasons.
when you have fewer than 10000 total users, that doesn't seem like such a bad idea - it's certainly convenient.
It was always public knowledge that NK has more or less one publicly routed /22. That's far removed from "large blocks of public IP space".
I think they meant that they were routing most IP addresses back to servers they control, even though they didn't officially "own" them.
Mark Lottor
[Original words and music by Jimmy Page and Robert Plant]
There's a hacker who's sure all that's coax is fast and he's buying a gateway to net ten. When he gets it he'll know if the ports are all closed with a SYN he can get what he sent for.
Ooh ooh ooh ooh, ooh ooh ooh ooh and he's buying a gateway to net ten.
There's an RFC on the wall but he wants to be sure cause you know sometimes words have two meanings. In a note on the page there's a warning that says sometimes all of our code is broken.
Don't ya know, it makes me wonder.
There's an error I get when I send to the net and my packets are lost and retransmitting. In my logs I have seen loops of mail thru the machine, and the screams of those who are hacking.
Oooh, it makes me wonder.
And it's whispered that soon if we all fix and tune then the packets will reach their destinations. And a new day will dawn for hosts that stay long and the telnets will echo quite faster.
Ohhhhh, it makes me wonder.
If there's a bustle in your cisco, don't be alarmed now it's just a quick ping for the NIC machine. Yes there are two paths you can route by, but in the long haul there's still time to change the protocol.
Yowwww, it makes me wonder.
Your host is loaded and it will slow in case you don't know, the unix's are asking you to join them. Dear hacker, do you see the overflow, and did you know your gateway is still under development.
And as we wind out more coax, and gateways slower than our hosts, There goes a message we all know, it updates routes and wants to show how everything still turns quite slow. And if you listen very hard, the bits will come to you at last. When all are ones and ones are all, to be a rubout and not a null.
And he's buying a gateway to net ten...
See this talk from 31C3 a couple of weeks ago: http://media.ccc.de/browse/congress/2014/31c3_-_6253_-_en_-_...
Not to be negative or discredit you, but you use word like "apparently" "probably" and "very likely" which is immediate indicators of hearsay or fear mongering.
Not that I have any idea what NK is like, never been there. But I do live in a country that suffers from huge misconceptions about the conditions here, hearsay and fear mongering. The entitlement to judge other absolutely astounds me sometimes, not to be applied to you yourself off course.
It's pretty interesting.
Had the OP shared a link such as this I would probably not have responded, and I didn't quite get the following vibe from the talk:
"and for every computer there is a government official sitting in a room next door seeing what the person using the computer is seeing....and probably taking notes."
http://www.bbc.co.uk/news/world-asia-25945931
As for "personal experience": I come from a country which used to be communist, and when you wanted to make a telephone call, you had to go to a nearest post office, ask for access to the telephone, and first they would connect you with an agent who would listen in to what you were saying, and only then you would get connected to where you needed to call. Everyone knew about this surveillance. I have absolutely no reason to suspect that NK doesn't do the same thing.
Sorry no offense meant, but then in fact you are just repeating the party line.
"As for "personal experience": I come from a country which used to be communist."
My sincerest apologies if you yourself suffered, might I enquire as to which country? I am genuinely interested.
But I am very skeptical of anything reported in any of the big media outlets[1]. Off course you have to get your news somewhere, I am just very sensitive to the background narrative, be it Western, Russian or Korean.
So the "party" line I am speaking about is how certain countries are always branded as the "bad/corrupt/terrorist" countries, but from first hand experience many of these countries are inhabited by people just going their own way. And the Western / Russian / whatever media very quickly forgets their own transgressions and that of their countries.
[1] http://themindunleashed.org/2014/10/german-journalist-blows-...
Also - you are linking an article that uses RT as its only source? RT being so pro-Russian and pro-Russian propaganda it's not even funny - and that's the only source?
This one blew my mind. Either it’s a mistake or a bizarre quirk of the way DPRK’s network works but the wifi URL for GEO still points to https://www.google.com/loc/json*
Maybe they just don't have Wi-Fi.Mozilla/5.0 (X11; U; Linux i686; ko-KP; rv: 19.1br) Gecko/20130508 Fedora/1.9.1-2.5.rs3.0 NaenaraBrowser/3.5b4