A North Korean imposter was uncovered, working as a sysadmin at Amazon U.S., after their keystroke input lag raised suspicions with security specialists at the online retail giant. Normally, a U.S.-based remote worker’s computer would send keystroke data within tens of milliseconds. This suspicious individual’s keyboard lag was “more than 110 milliseconds,” reports Bloomberg.

Amazon is commendably proactive in its pursuit of impostors, according to the source report. The news site talked with Amazon’s Chief Security Officer, Stephen Schmidt, about this fascinating new case of North Koreans trying to infiltrate U.S. organizations to raise hard currency for the Democratic People’s Republic of Korea (DPRK), and sometimes indulge in espionage and/or sabotage.

top 50 comments

sorted by: hot top controversial new old
[–] 255 points 9 months ago (7 children)

Sounds much better than "Amazon surveils keystrokes of its IT workers"!

  • source
  • hideshow 7 child comments
  • [–] 29 points 9 months ago (4 children)

    This was also my takeaway. Sounds like a security nightmare if they are logging any data.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 7 points 9 months ago

    Normal ass websites will monitor user inputs to do things like profile users. I’m pretty sure those “click to show youre not a robot” captchas actually capture how your mouse moves to the box, for example. It’s not that crazy honestly.

  • source
  • parent
  • load more comments (3 replies)
  • [–] 154 points 9 months ago (4 children)

    How am I the first person to ask why they're measuring the latency on everyone's keystrokes?

  • source
  • hideshow 4 child comments
  • [–] 80 points 9 months ago (34 children)

    I'm never quite sure how to feel about this. On one hand, if the person just wants to make some money and they're doing the job, why bother them. On the other hand though, I know that anybody who has consistent access to an internet connection in North Korea is almost certainly working for the benefit of the great leader and they aren't actually seeing any money or benefit for themselves. I just hate that the citizens of North Korea have to suffer and be punished because of their asswipe of a leader.

  • source
  • hideshow 34 child comments
  • [–] 70 points 9 months ago (15 children)

    When you look at the ISS pics of NK during the night, you get a sense of how bad it is for most of the population.

  • source
  • parent
  • hideshow 15 child comments
  • [–] 47 points 9 months ago (10 children)
  • load more comments (8 replies)
  • [–] 15 points 9 months ago (2 children)

    It kind of amazes me they don't have better infrastructure. It's not like they're shy about forced labor.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 43 points 9 months ago (5 children)

    They’re also a security threat. Any opportunity to exfiltrate potentially profitable or leverageable data will be taken. I’d bet they’re used to sniff out vulnerabilities for ransomware attacks too. I definitley identify and agree with the healthy sympathy (I guess empathy if you’re in the states, our leader more than qualifies as an asswipe) for the citizens of North Korea

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (5 replies)
  • [–] 19 points 9 months ago (1 child)

    I know that anybody who has consistent access to an internet connection in North Korea is almost certainly working for the benefit of the great leader and they aren’t actually seeing any money or benefit for themselves.

    Eh, this doesn't sound like the job you would give someone in a prison camp. You're talking about people that you're allowing to interact and work regularly with foreigners outside the country. That does not sound like the type of position you trust to a political prisoner. That sounds like a position you put someone of high trust. It's probably a pretty cushy job as the standards of North Korea go. Sure beats scratching at dirt or working in some godawful arms factory. It's probably the type of job you need some good family connections in the Party in order to get. Sure, the government takes all the direct monetary benefit of the work, but that is just kindof how Communist systems work. I imagine the people working those jobs have some of the highest standards of living available to people that aren't senior party leadership.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (5 replies)
    [–] 36 points 9 months ago (3 children)

    On one side I feel like "cool, they managed to find a spy on this sophisticated way"

    On the other side I'm thinking what kind of intrusive keylogging malware did they install on all their employees laptops...

  • source
  • hideshow 3 child comments
  • load more comments (2 replies)
    [–] 34 points 9 months ago (1 child)

    North Korea got better ping than mine ahahaha...

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 24 points 9 months ago (8 children)

    I guess this is inevitable at huge companies. Nobody cares about the actual person you're hiring, it's just another position to fill. Of course there will be fakes of all kinds.

  • source
  • hideshow 8 child comments
  • [–] 20 points 9 months ago (7 children)

    It’s not that, it’s that they are incredibly sophisticated in their techniques. I just had to sit through 90 minutes of training about how to spot fake applicants.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 9 points 9 months ago (3 children)

    I don't get why companies can't solve this problem entirely by just flying out applicants for in-person interviews towards the end of the hiring process. Or hell, maybe only even ask the candidate to fly out for a visit after they've already accepted the job offer. Just one minimal and relatively cheap step to confirm the remote worker you're hiring is who they claim to be. For the cost of a flight, a night or two in a hotel, and some meal vouchers, you can verify someone's identity. Sure, maybe not for freelance work. But for any well paid technical field? This is a trivial expense.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 8 points 9 months ago

    I feel this can be bypassed the same way remote interviews have been passed, you have a talented dude A actually trained to pass whatever verification is needed, and whenever there's privacy, it switches to dude B, while dude A moves to another recruitment process. I think I have heard about this kind of dude A offering his services online for anyone ready to pay.
    Anyone else has never seen the face of one of their full remote colleague? I have one in my team, he does a good job though, however many they may be behind him.

  • source
  • parent
  • load more comments (2 replies)
  • load more comments (3 replies)
  • [–] 18 points 9 months ago (2 children)

    I don't like Amazon but I will admit here I got to respect both the fact that they disclosed this instead of hid it and the fact that they are actively looking for this instead of burying their heads in the sand.

  • source
  • hideshow 2 child comments
  • [–] 7 points 9 months ago

    I wonder how many they've missed over the years, this kind of thing has been occuring since at least 2012.

    Reminded me of the 'critical infrastructure company' (I presume utility) software developer who handed all his credentials over to a worker in China, including mailing them his RSA keyfob, and wasn't discovered for months until the company security team noticed VPN logins coming from China.

    https://arstechnica.com/information-technology/2013/01/worlds-most-industrious-lazy-man-outsources-all-of-his-work-to-china/

    Apparently it's become even easier for malicious remote workers to fake resumes and identities to gain jobs via AI, so I hope all major companies are monitoring their remote access very closely.

    https://au.pcmag.com/security/106436/security-firm-discovers-remote-worker-is-really-a-north-korean-hacker

  • source
  • load more comments
    view more: next ›