Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I watched a presentation of these guys at SHA2017 and someone asked the same thing. Here's the full presentation in case you're interested: https://media.ccc.de/v/SHA2017-120-hack_north_korea

As far as I recall their answer was that a USB drive can store much more. Video, entire books, etc. However leaflets are also done.

Personally I don't know if it's worth the risk knowing that their local OS ("Red Star OS") can fingerprint files. But I guess they know what they're doing.



Fingerprinting files would be the least of my concerns. When you plug a USB stick, you potentially plug a keyboard and handover control of your computer to the stick.


Most people in the western world wouldn't think twice before plugging in a found USB stick into their own computer because they are curious, people simply don't know the risk. I'm sure even fewer people in North Korea know basic computer hygiene.


Idk it’s basic workplace trading now, I think most people plugging in a random usb here are at least doing it in an isolated VM or something.


Maybe in San Fransisco, US it's basic workplace training, but outside of very technology focused cities, people definitely don't know how easy it is to be compromised by a USB is.

Most computers in various places like hospitals, veterinarians, shops, gyms and more all have exposed USB ports where it'd be trivial to plug something in when the clerk/assistant is looking the other way, just as another example.


In a isolated VM? No way. Most people don’t know what a VM is. Hopefully most people wouldn’t plug a random USB into their computer, but I suspect that (# of people who would plug in a random USB) > (# of people who know about VMs)


Even among the people who "know about VMs" how many of them could confidently plug in a physical device to a physical machine and be sure that it was somehow isolated to the VM? I must have a dozen ways to run VMs here, but I couldn't do that.


What is the most common attack vector to fear? I thought maybe auto-run had been disabled by default, in most modern versions of Windows, for the past 10-15 years at least.


If you plug a USB keyboard, windows will automatically set it up. All the stick needs to do is emulate a keyboard, then it can send keystroke to the OS as yourself, no need for auto-run.


But then again, why would anyone connect their computer to the completely censored national LAN, only to be spied upon by the state?


Because it will contain entertainment as well and it's the way to communicate with friends. Despite being censored, it's all they have.


In my (lack of) knowledge of North Korea, I don't think most people even have computers, and it's not like the government's built infrastructure to just connect their computer to the LAN. (It's different if you're part of the government elite living in the compounds for sure...).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: