miglmj | 4 years ago | on: Restaurant menu tricks (2020)
miglmj's comments
miglmj | 5 years ago | on: Marbles (2016)
miglmj | 5 years ago | on: Coinbase Announces Listing Date of Its Stock on the Nasdaq
miglmj | 5 years ago | on: Coinbase S-1
miglmj | 5 years ago | on: Blur Tools for Signal
miglmj | 6 years ago | on: The Anti-Amazon Alliance
miglmj | 6 years ago | on: Proof of concept: end-to-end encryption in Jitsi Meet
miglmj | 6 years ago | on: Things I wish I knew about state management when I started writing React apps
miglmj | 6 years ago | on: Hackers acting in Turkey's interests believed to be behind recent cyberattacks
There's more to it than that, and often attribution is the result of the "bigger picture" of multiple clues, rather than a single smoking gun. Group operations develop patterns over time that are much greater than just a timestamp somewhere. Also, identifying a 0-day exploit somewhere often allows you to discover previous deployments of the same exploit, which have their own blast radius of evidence, contributing to these patterns that are identified over time.
>but surely a competent hacker could pull of a hack and trivially modify the evidence to implicate any nation/state who's modus operandi are known in hacking circles, no?
>Deliberately engineering your attack to mimic one from another group is an excellent way to keep people off your trail...
Yes, misdirection is the name of the game here, all bets are off and nothing is off limits. But covering your tracks leaves tracks of its own, and again, even when an attacker thinks all their bases are covered, they will never be sure there wasn't something somewhere they left behind that points back to them.
> and these are hackers we're talking about, after all.
Who do you think "hacker-hunters" are, if not hackers themselves?
miglmj | 6 years ago | on: Why New York City Stopped Building Subways (2018)
miglmj | 7 years ago | on: Nations of the Amazon are seeking “shared governance” of the .amazon TLD
In this case, I could see AWS hosting being useful to them (maybe even something along the lines of GovCloud like AWS runs for the US Government)