7 ms·
Hunting for North Korean Fiber Optic Cables
- superducktoes 9mo agoThanks for sharing my site. Happy to answer any questions
- monerozcash 9mo agoDon't have questions, but your blog is very cool. A bit over a decade ago I used to spend a lot of time hacking North Korean web infrastructure, I mostly found that they tended to have firewalling around almost all boxes exposed to the global internet and usually had pretty impressive reaction times if you tried to access the country intranet through a compromised web server. I've always wondered how successful NSA and the likes have been at infiltrating DPRK networks, as it would inherently be fairly easy to detect any sketchy traffic from the outside. I wonder if the recent NYT story essentially confirms that difficulty. Regarding the NSA and DPRK, there's this document from 2007 least https://www.eff.org/files/2015/02/03/20150117-spiegel-fifth_party_access_-_when_the_targeted_fourth_party_has_someone_under_surveillance_who_puts_others_under_surveillance.pdf https://www.eff.org/files/2015/02/03/20150117-spiegel-fifth_... I guess I have a question after all: I'm not exactly clear on how NK treats end-user devices. Do you know if the endpoints used by NK based remote workers have internet and intranet access at the same time? If they do, such an endpoint could offer an easy and stealthy channel to access the intranet.
- superducktoes 9mo agothanks really appreciate that! I've seen that doc before and it does really make me wonder. part of the leaks from the NSA tools years back had some references in there for detecting north koreas ant-virus silivaccine https://github.com/b30wulf/Malware-collection/blob/4f5906c93314757e85f3e764d07c6b0466befbd8/malware/malware-master/Fuzzbunch/Resources/Ep/Scripts/PSP/silivaccine.eps#L22 https://github.com/b30wulf/Malware-collection/blob/4f5906c93... There was also the hacking team leak from years ago and they were selling exploits for north korea's red star OS: https://nkinternet.wordpress.com/wp-content/uploads/2025/12/portfolio.pdf https://nkinternet.wordpress.com/wp-content/uploads/2025/12/... I assume they've been on their networks in the past but i think North Korea has also done a lot over the years to secure their side. it used to be a lot easier when they left everything as an open directory and didn't realize what they were doing.
- monerozcash 9mo ago>There was also the hacking team leak from years ago and they were selling exploits for north korea's red star OS: https://nkinternet.wordpress.com/wp-content/uploads/2025/12/ https://nkinternet.wordpress.com/wp-content/uploads/2025/12/... South Korean NIS was in fact a hacking team client, so it would make sense. Especially considering how terrible Red Star OS was at the time, a HT engineer could probably have whipped those up in a couple of days. https://web.archive.org/web/20180302155452/http://english.yonhapnews.co.kr/news/2015/08/04/0200000000AEN20150804000900315.html https://web.archive.org/web/20180302155452/http://english.yo... >I assume they've been on their networks in the past but i think North Korea has also done a lot over the years to secure their side. it used to be a lot easier when they left everything as an open directory and didn't realize what they were doing. I'm sure they've had some success, but I'd expect it to be a really difficult environment to operate in. Even for the NSA. I suppose eventually there'll be a better leak and we'll get to find out just how well it's been going.
- superducktoes 9mo agothe end user devices are also really interesting. as far as i know they require a piece of software called netkey or oconnect as it's recently been renamed. that's for getting access inside the country and then for anyone outside they have software called hangro that is similar to a vpn for connecting back to north korea and getting messages
- anonu 9mo ago> this document from 2007 Interesting document - confirming "everyone spies on everyone". Is this from some sort of corporate NSA chat room?
- monerozcash 9mo agoIt's like the NSA Reddit, they've got memes and up- and downvotes. Some excerpts from a seemingly unreleased Snowden leak (from Dark mirror: Edward Snowden and the American Surveillance State): > “Why is a scoop of potatoes larger than a scoop of eggs in the cafeteria?” a contributor named Michael wondered one day. Paul jumped in to play the troll. “Let me be the first to down-vote you,” Paul wrote, naming several pedantic reasons. A side debate erupted: should Michael’s post be down-voted, flagged, or removed? Clyde returned to the topic at hand with a facetious theory that scoop volume is proportional to the relative size of potatoes and eggs themselves. In that case, Scott replied, what would happen if “we served eggs that were bigger than potatoes, like of an Ostrich?” Someone proposed a uniform system, “One Spoon to scoop them all,” an homage to Lord of the Rings. Punsters demanded the “inside scoop” and lamented the waste of time on “small potatoes.” Gotta say, it's pretty disappointing that Gellman, Greenwald, Poltras et. al. have been so stingy with these documents. It's definitely starting to have been long enough for them to just dump everything.
- metadat 9mo agoImpressive sleuthing! It's interesting to discover the reality that packet routing ends up following political affiliations. I didn't know North Korea only has 1,024 IPv4 addresses. Do you know why so few IPs? How did they get them?
- monerozcash 9mo agoDPRK can certainly get however many IP addresses they want, DPRK just doesn't have that much infrastructure that they want externally accessible. As far as I know, end-user traffic from within North Korea usually does not originate from those few IP addresses. Or at least not visibly so, they might be connecting to a proxy from a DPRK IP address.
- lukan 9mo ago"DPRK can certainly get however many IP addresses they want" IP4 is quite limited as far as I know and not given out freely since a long time, or what do you mean here?
- jauer 9mo agoIPv4 continues to be available to entities that have a need that fits a particular policy shape, just most people don't. Specifically, you can get IPv4 /24s for IPv6 transition purposes. This includes anycast DNS, MX, etc for legacy clients on other networks, v4-side of CGNAT, etc. E.g. I was able to get a /24 in the ARIN region in 2021 and could justify 2 more for a _logical_ network topology similar to what NK presents to the world. APNIC similarly has a pool available for IPv4 allocations: https://www.apnic.net/manage-ip/ipv4-exhaustion/#the-situationin-apnic https://www.apnic.net/manage-ip/ipv4-exhaustion/#the-situati...
- eqvinox 9mo agoIPv4 is a question of money in almost all cases at this point. You can get what you can pay for.
- 9mo ago
- apercu 9mo agoWhat a great read. Thanks.
- NedF 9mo ago[dead]
- eqvinox 9mo ago> … 2.5 GB per second between all the provinces. What's your source for that number? Is it GBit or GByte? Are they building out OTU1?
- liversage 9mo agoMy understanding is that there are three mobile networks in North Korea: the normal one used by the citizens (they have smartphones made specifically for North Korea), one used by the government/military and one for tourists (requires a local SIM card only available in a specific hotel in Pyongyang). The last one is connected to the internet and this is why you can see (or at least before the pandemic could see) Instagram posts from North Korea. I have no idea if this information is still or ever was completely true though. There's a somewhat dated but very interesting AMA on Reddit by an American teaching computer science in Pyongyang: https://www.reddit.com/r/IAmA/comments/1ucl11/iama_american_who_spent_the_fall_teaching/ https://www.reddit.com/r/IAmA/comments/1ucl11/iama_american_... Reading about the internet knowledge possessed by North Korean students, I'm always surprised how they supposedly also manage to be some of the most cunning and evil actors when it comes to hacking.
- tehjoker 9mo ago[flagged]
- bigfishrunning 9mo agoHow cunning and evil it is that America funded the internet and then allowed it to spread around the world. If you're worried about "absolute control over digital systems", notice how many standards get published describing how those digital systems work -- you're welcome to reimplement them if you'd like more control.
- tehjoker 9mo ago“allowed” is doing a hell of a lot of work for monopoly capitalism backed by us state diplomacy you may want to read this book about the military history of the internet originating in counter insurgency strategy in vietnam. https://www.amazon.com/Surveillance-Valley-Military-History-Internet/dp/1610398025 https://www.amazon.com/Surveillance-Valley-Military-History-... another way to look at american internet penetration is as “radio free asia dot com”
- 9mo ago
- mikkupikku 9mo agoDo those small utility boxes alongside the tracks make sense for fiber optic? I expected things like that to be larger, if only because fiber has a minimum bend radius. Edit: Good article though, I enjoyed it a lot.
- adamcharnock 9mo agoThe min bend radius isn’t that large in my experience. On the order of 10cm IIRC, possibly even less.
- st_goliath 9mo agoMuch smaller than that, some might even say a utility box is overkill: https://old.reddit.com/r/techsupportgore/comments/nvwcuh/the_fiber_line_coming_into_my_village_in_korea/ https://old.reddit.com/r/techsupportgore/comments/nvwcuh/the...
- Lukas_Skywalker 9mo agoEven less is correct: outdoor fibers (G.652.D) have a minimum bend radius of about 30mm. The indoor counterpart (G.657.A1 and A2) have 10mm and 7.5mm.
- lesuorac 9mo agoThose are more of a technically no? Like I have fiber to the house and you really need to pinch it and whatnot to cause an internet outage.
- oarsinsync 9mo agoA small bend radius means it can have a tight bend. A large bend radius means it has to be a big bend. A 7.5mm bend radius is really small. You can bend that stuff pretty tight before you create a problem.
- eqvinox 9mo agoThe larger cables tend to have strength members with higher physical bend radius restrictions, i.e. you can't bend the steel or kevlar elements that tightly without breaking things.
- deleted 9mo ago[deleted]
- codedokode 9mo agoIsn't it easier to hang optic cable on the poles? It seems that burying the cable requires more work. As for utility boxes along the track, it could be something railway-related, for example, some railway control or monitoring equipment.
- samus 9mo agoThey are too vulnerable to the elements there.
- actionfromafar 9mo agoA few inches of dirt protects against cables darkening from nuclear blasts, if you care about that sort of thing.
- bigiain 9mo agoIf you hang your fibre optic cable from poles, you will inevitably evolve flying backhoes.
- eqvinox 9mo agoToo late, already happened, it's called squirrels. cf. CCC NOC logo: https://events.ccc.de/camp/2019/wiki/Static:Network https://events.ccc.de/camp/2019/wiki/Static:Network — it's an in-joke about rodents chewing through the (air/tree-strung) uplink fibre multiple times at the 2015 event.
- bigiain 9mo agoThat campground info hooks back into the old joke I was referencing. What's the most important piece of camping gear you can take with you? A meter or so of fiber optical cable. So that if you get lost of injured you can bury it and wait for the backhoe to show up and dig through it, then get a ride back to civilisation with the operator.
- AngryData 9mo agoIt is easier, but it is also far more vulnerable and won't last nearly as long.
- dboreham 9mo agoI found the railroad part of the article unpersuasive. Optical repeater stations are fairly large and therefore wouldn't show up as random small underground vaults or little boxes on poles. These look like a collection of pictures of train tracks with no particular indicators of optical cables therein.
- petcat 9mo agoCan we back up and just recognize how insane North Korea is? I think that future generations will look back on our history and wonder why nobody ever did anything about the incredible atrocities that took place in that country for decades.
- VWWHFSfQ 9mo agoIt will definitely go down as one of the biggest failures of mankind. Especially since it was so easily preventable if MacArthur was permitted to just take the whole peninsula.
- antonymoose 9mo agoThink how many tens of millions could have been saved if we had ended the Soviet Union as Churchill advocated, before the world got nukes.
- denkmoon 9mo agoThink how many tens of millions would have died in such a war. Just for some other evil to pop up anyway.
- etc-hosts 9mo agoYou mean when Churchill wanted to hire 100,000 "former" Nazis to invade the Soviet Union?
- TheBicPen 9mo agoDoes any serious historian believe that fully defeating the Soviet Union after WWII would have been possible? Even with the advantage of nuclear weapons, I doubt the US would have made it very far.
- jojobas 9mo agoIt was way too late, look up Operation Unthinkable.
- edm0nd 9mo agoa random interesting fact: North Korea is responsible for adding the hot beverage, umbrella with raindrops, and lightning bolt emojis https://en.wikipedia.org/wiki/KPS_9566 https://en.wikipedia.org/wiki/KPS_9566
- deleted 9mo ago[deleted]
- metalman 9mo agohigh voltage transmission lines can and are built with a glass fibre core, and would be essentaily invisible also a ditch witch and couple of support vehicles could run cable through most terrain, and in agrairian areas , not needing permits and such, would be indistinguisashable from other activity ,happen very quickly, and leave no trace humanity has reached the point where our comunications net is a given for 90%+ of the population centers in one form or another, and if not for the slop, would have an order of magnitude, excess capacity. throw in peer to peer ,and the soon to be blanket coverage from sattelite swarms, and well, what? sonar relays for underwater, and seizmo transmitters