Hacker News new | ask | show | jobs
by cgb223 1424 days ago
> wiki page has many links to the full book

The netsec person in me says we probably shouldn’t be downloading PDFs/epubs from the servers of literal North Korean Government sites…

2 comments

The post you're commenting on is a PDF file hosted on cia.gov, how is that any better? Or are you assuming that all readers of HN 1) are American citizens, and 2) that American citizens shouldn't care about possible threats from the CIA?
just to be clear are you implying that the CIA is hosting malware on their clearnet servers so every one can get infected ?
Are you implying that injecting malware into specific targets is not the CIA’s job?

Nobody said they infect “everyone”, it’s most likely not even in their interest to do so.

Yeah, hosting malware is NSA's job.
Maybe just a few specific MAC adresses?
hacking provides a significant portion of the North Korean economy. the same cannot be said for the USA.

besides, the CIA has a lot more to lose. if you get a virus downloading a PDF from North Korean servers, that's The Scorpion and the Frog. you're not gonna get much sympathy. if you get a virus downloading a PDF from CIA servers, that's near enough an international incident

Doing things that may cause international incidents is, while avoided as a matter of priority, literally the CIA’s job.
something directly provable like a trojan pdf on their website would be doing that job extremely poorly
Are you creating a false equivalency between North Korea and American? If so, Noam Chomksy in the house!
I think analogies can be taken too far, but "both North Korea and the US are probably interested in compromising the computers of their adversaries, and may intentionally or unintentionally infect others in the process" doesn't seem too far-fetched to me. It's not the same as saying "North Korea and the US are functionally and ideologically the same."
Respectfully, what do you imagine the attack vector would be?
A zero day bug in the pdf parser or javascript engine of your browser. Such bugs are common enough that the North Korean military is believed to use them to gather intelligence and for theft, but also are rare enough that they're going to use them on just anyone.
Did you miss a "not" in the last part of that?
yup :P
I thought North Koreans don't know how to use computers? Remember the Kim Jong Un memes around that?

I'm frankly getting tired of all the hysteria. If that is indeed the attack vector just use a sandbox and a pdf viewer with low featureset. Is all we do nowadays mindless hysteria?

EDIT: comical. the response to the advice to use a PDF viewer with low featureset is to list Acrobat exploits. Seems like in the hysteria about how terrible "our enemies" are, all sarcasm and absurdity is lost

Saying the inverse of what you actually believe but with a tone that suggests insincerity isn't comedic. It's just obnoxious.
I can see why calling out the hypocrisies of the hysteria of people like you would seem obnoxious to you.

EDIT: Comical indeed that MichaelCollins feels the need to come to muruculas rescue. The thread didn't start with murucula, it started with people saying they should not open NK PDF's because they're dangerous. The mindless hysteria could only have been trumped by people accusing one of China and Russia stoogedom in the comments below.

I was merely referring to the memes that were so popular in HN circles just a few years ago about how Kim Jong Un was too stupid to use a computer[1].

I have no skin in the game, but if the HN crowd is not able to read a PDF with basic Opsec to protect itself from malicious Acrobat exploits, we don't really deserve to be called hackers.

[1] http://www.slate.fr/sites/default/files/styles/1200x680/publ...

Pay attention to usernames, rjzzleep.

Anyway, muricula didn't say North Koreans don't know how to use computers, so there was no hypocrisy in his suggestion that North Koreans might have competent computer hackers. You're raging at numerous strawmen at once.

So many strawmans, so little time. Viewing the history of rjzzleep is fascinating. He loves china and russia but can't say a nice thing about a western country. He constantly points to a collapsing west.