5 ms·
I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been
by huntsman 4y ago
I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years.
(Disclaimer: I am head of TAG)
- dna_polymerase 4y ago
- thematrixturtle 4y agoHere's the report which associated Clear Sky with NK, and it's not from Google: https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...
- dna_polymerase 4y agoYeah, still waiting for something to substantiate the headline. This report isn't it. A lot of hand-waving about other people's hand-waving.
- nl 4y agoAttribution is hard, but by no means impossible. https://www.justice.gov/opa/press-release/file/1092091/download https://www.justice.gov/opa/press-release/file/1092091/downl... has a bunch of evidence that the Justice Department collected when charging some people associated with ATP38 around the Sony Pictures and WannaCry hacks (and other campaigns) I'd note that things like shared encryption keys and shared TLS passive tables are very indicative of shared resources. The use of North Korean IP addresses is indicative, but never enough on its own. However, the use of domains controlled by North Korean IP addresses is interesting as well. Combine that with passwords largely shared with another North Korean attack, devices signed into from NK IP addresses under multiple accounts setup from N Korean IP addresses you start seeing a pattern of behaviour. And then you find that the person who controlled accounts used by these attacks was a North Korean national (pg 134) who worked for a well known North Korean front company (paragraph 269, pg 136) and the evidence becomes pretty good.
- thematrixturtle 4y agoAPT38/Lazarus has been around for years and has been investigated by many professional groups across the world (Kaspersky, McAfee, Mandiant, etc), many not connected to the US government. Are you alleging that they're all wrong and this is all some vast conspiracy to frame an innocent North Korea and protect... who, exactly?
- harry8 4y agoThink of all the big, serious and sensible news organisations that independently reported WMD in Iraq while not being connected to the US government. Are you alleging they're all wrong and this is some vast conspiracy to frame an innocent Iraq and protect.. who, exactly? Evidence is evidence. After WMD (which totally took me in, btw, you too?) Claims that evidence is "just over there" and "here are multiple different people reporting they've spoken to someone who saw it." Count for zero. Maybe they always should have but there's not doubt this stuff happens anymore. We watched it. (Hopefully) in horror as it unfolded without us objecting.
- nl 4y agoI thought the WMD "evidence" was BS, and actually there was only one piece that was presented publicly (the UN presentation by Colin Powell), and that was based on CIA secret intelligence. And the UN Weapon Inspectors were saying the opposite. OTOH, the evidence linking APT38 to North Korea is pretty compelling. For example, there is a bunch of evidence collected independently identifying individuals associated with APT38, and these people worked for the North Korean company Chosun Expo. See https://www.justice.gov/opa/press-release/file/1092091/download https://www.justice.gov/opa/press-release/file/1092091/downl... for the evidence in depth.
- thematrixturtle 4y agoThere's a huge difference between news organizations reporting on US govt claims, and investigators on the ground actually digging into the evidence on their own. Your assertion is basically the same as claiming that Iraq did have WMDs, but UNMOVIC etc were covering up and hiding the evidence. For what it's worth, quite a few people were skeptical about the WMD "evidence" at the time, and even more cynics like myself figured that true or false, it was mostly an excuse for George W to Do Something(tm) after 9/11 and at the same time finish off the war his dad started.
- actuator 4y agoRather than attacking him, you are free to discuss on how it would be hard to attribute or reach to a source. Just because you might not know what techniques the researchers here used to reach to that conclusion, doesn't mean they would have used dubious methods. It is better to ask than attack a person.
- dna_polymerase 4y agoThe United States reserves the right to react to cyber attacks with force [0]. Instead of asking people to be nice on the internet you should hold those accountable that are in a position to manufacture a narrative. The linked report in the sibling comment here has no valid proof of North Korean involvement but the headline is chosen in a way to paint a picture of an impoverished nation as an aggressor. If you just accept that Google can make up facts to pave the way for physical warfare you are complicit in the eventual deaths of thousands of innocent people. To be precise. After the CIA made up reports of WMDs in Irak people should ask for receipts earlier. [0]: https://www.reuters.com/article/us-usa-defense-cybersecurity-idUSTRE7AF02Y20111116 https://www.reuters.com/article/us-usa-defense-cybersecurity...
- saagarjha 4y ago> Instead of asking people to be nice on the internet you should hold those accountable that are in a position to manufacture a narrative. Nope, Hacker News is the place where you be nice to each other on the internet rather than assuming they’re trying to manufacture consent. This is quite literally spelled out in the site guidelines.
- azinman2 4y agoHow do you know what country is actually behind any of this? I’d imagine that would be very difficult given nation states can host content anywhere in the world and will want to make it look like it’s coming from elsewhere.
- saagarjha 4y agoI don’t work in this field, but my impression has been that groups tend to share techniques and code patterns that can help tie them back to where they came from.
- azinman2 4y agoBut how do you know the origin?
- jasonwatkinspdx 4y agoBy connecting multiple details such as ip addresses, connection/flow logs, known CnC servers, etc. You seem to be expecting some magic simple answer but the reality is the same as other investigative work: doing the work in the details as a professional. Just because this work is difficult and inherently has some ambiguity doesn't mean you can just dismiss every attribution from your armchair.
- rtpg 4y agoStaring hard at a all the details and figuring it out? The thing with trying to hide yourself is you have to do everything right to guarantee some false flag operation will work but if you make enough mistakes in this process there will be reasonably high-confidence links between some action and some person. An example that I _have_ seen in some write up: some snippet of malware code showing up in a stack overflow question (with the shape and user variables being the same). At one point it's like... probably that person. Of course maybe there are other indicators to the contrary but that's data for you. Gotta use your noggin a bit.
- xtian 4y agoHere’s a question I expect you’ll never answer: is it within the capabilities of any groups within the West (state-sponsored or otherwise) to fabricate the information you’re using to make those assessments? And if so, how have you decisively eliminated this possibility? I ask because it’s broadly accepted that there are extremely powerful and wealthy entities in the West who benefit from an aggressive US foreign policy and heightened geopolitical tensions.
- boomboomsubban 4y agoThere are several sections of the Vault 7 leaks that showed the CIA had tools that could be used to fake the attribution of attacks. Some argue there's other uses for those tools besides faking the source of an exploit, but knowing they have the capability makes it impossible to eliminate as a possibility.
- jamesmishra 4y agoWhy do you have to prefix your question with, "Here’s a question I expect you’ll never answer"?
- xtian 4y agoI don’t have to, it just makes me look good when he never answers.
- jasonwatkinspdx 4y agoNo, it does not.
- xtian 4y agoAgree to disagree
- throwawaylinux 4y agoProbably, but even more simply they have the capabilities to just direct intelligence agencies, politicians, and news corporations, and big internet and social media companies to put the blame wherever they like. There is no need for a perfect technological solution. Hack something shoddy together, go to war/regime change/etc, and worst case if it does come to light that the "intel" was wrong, a well-placed "whoopsie-daisy" is enough to wash hands of all responsibility or scrutiny.