6 ms·
In fact, if anything, the following quote indicates an insider is just as likely to be the source The common narrative in discounting any involvement of North
by personZ 12y ago
In fact, if anything, the following quote indicates an insider is just as likely to be the source
The common narrative in discounting any involvement of North Korea is that they're too famished and uneducated to perform such an operation. Your angle is that the attack isn't sophisticated enough?
The evolving story is that a single IT worker with significant right grants was targeted by the group, and once that single user was exploited, their privileges were used to compromise the network. If you have the privileges of a superuser, your attack doesn't need to be sophisticated.
And ultimately this is exactly how I would expect these sort of attacks to go, especially when hitting targets in free and open nations. Why go through the trouble and effort of trying to winnow in from the outside when you can just exploit the kink or vulnerabilities of individual people -- who you can now discover via LinkedIn -- and then work your magic from the "inside". Sending out a group policy to disable all security software is a couple of lines. This "virus" seemed to be a simple efficiency measure, as with those rights they could do pretty much everything, though mass malice would probably be too labor intensive minus some helpful tools.
The defense against this is of course that even admins should have limits on their access and flags on their activities. Of course, the admins are the ones who normally implement this, so...
- Reebles 12y agoMost people I've seen question the North Korea angle absolutely acknowledge that they have the capability to do things like this. They usually argue that this does not fit the style and MO of a state sponsored attack, that The Interview was never mentioned by the hackers until after the media starting running with the story, and that there simply isn't enough public evidence to justifiably attribute it yet, among other things.
- personZ 12y agoThere is no MO regarding an attack from a country like North Korea. That country says bombastic things with regularity, and has seemingly little concern for blowback. How a country like Israel or the United States might do an attack like this has no relevance to what North Korea might do, whether directly or through a hired proxy. The Interview was never mentioned by the hackers until after the media starting running with the story North Korea threatened war over this movie - http://www.bbc.com/news/world-asia-28014069 http://www.bbc.com/news/world-asia-28014069 Now again, North Korea's words are kind of cheap, but they were talking about as big as you can get before this hack, and then specifically warned Sony to "obey" them. We have absolutely no idea what communications happened between the group and Sony and then law enforcement, so the whole what the media reported angle seems rather spurious. Sony/Law Enforcement, people who know more than us, seem to believe it was related to the movie.
- eli 12y agoThat's a fair point, but how many times a year does North Korea threaten war over something or other? A dozen?
- revscat 12y agoThere is no MO regarding an attack from a country like North Korea. Actually, there is. They tend to huff and puff about American military exercises that occur in cooperation with the Japanese or the South Koreans, or to complain to the UN about various things (e.g.: the CIA torturing people). But their MO, such as it is, is to complain and threaten, almost exclusively. Occasionally they will perform a missile test that causes concern, but those missiles land in the Sea of Japan or some other body of water, not anywhere that causes actual harm. No, this goes against the DPRK's MO up until now. If they are responsible then it is a shift in their tactics from "loud and threatening, but basically harmless to other nations", to "actively and publicly committing acts of economic espionage." That would be quite a departure for them.
- personZ 12y agohttp://www.cnn.com/2014/12/18/world/asia/north-korea-hacker-network/ http://www.cnn.com/2014/12/18/world/asia/north-korea-hacker-... North Korea is suspected in a number of similar attacks. Because really, what is anyone going to do? Attack them? They have nukes. Isolate them? They can't possible be more isolated. Sanction them? As an aside, the regular threat of using nuclear weapons is an act of extreme violence, and I doubt North Korea's neighbors treat it so flippantly. The threat is unlikely, but extremely real.
- sabertaylor2 12y agoI read the "War Nerd" claiming that NK lands kill parties on SK soil. Which seems to contradict your statements.
- junto 12y agoMore importantly, who else could the USG blame? China are somewhat too important a "partner". Venezuela, well Chavez "happened to die". Cuba, friends again. Iran, bringing them slowly in from the cold. Russia, well... It would have been more convenient for the USG to blame ISIS but nobody would believe that. I still don't buy the N.Korea angle. They would just love the propaganda. They are quite happy to provoke the US with missile tests publicly, you don't think a hack like this they are going to want to keep quiet? Doesn't make sense to me.
- eat 12y ago> The common narrative in discounting any involvement of North Korea is that they're too famished and uneducated to perform such an operation. This is the common narrative? Every narrative I've read bases their skepticism on problems with the language used by attackers.
- afterburner 12y agoHired guns?
- revscat 12y agoOr someone who is intentionally writing in "broken" English.