back to article SURPRISE: Norks' Linux distro has security vulns

Well, that didn't take long: mere days after North Korea's Red Star OS leaked to the west in the form of an ISO, security researchers have started exposing its vulnerabilities. According to this post at Seclists, the udev rules in version 3.0 of the US and the rc.sysint script in version 2.0 are both world-writable. Both of …

  1. JassMan
    Trollface

    Impressive computing power shown in that picture

    http://regmedia.co.uk/2014/02/04/kim_jong_un_computer.jpg?x=648&y=429&crop=1

    Being a nork computer it probably has the processing power of a Raspberry Pi.

    Maybe Lady Ada could produce a matching cabinet for the Pi. Should leave plenty of room for expansion!

    1. Anonymous Coward
      Anonymous Coward

      Re: Impressive computing power shown in that picture

      The Raspberry Pi starts at 700 MHz clock. Ain't nothing in that cabinet going faster than 2 MHz.

      1. Stuart 22

        Re: Impressive computing power shown in that picture

        "The Raspberry Pi starts at 700 MHz clock. Ain't nothing in that cabinet going faster than 2 MHz."

        True but then my old 2Mhz Z-80 did Supercalc spreadsheets faster than LibreOffice on a 1.6Ghz machine.

        "It's how you code 'em;-)"

        1. John Arthur

          Re: Impressive computing power shown in that picture

          Ah! Supercalc and Wordstar. Those were the good old days. Who needs a mouse?

    2. Voland's right hand Silver badge

      Re: Impressive computing power shown in that picture

      If it is a computer at all. Based on the console style it looks like a verbatim clone of some piece of old Russian military equipment.

      Some of these are analogue. Also, while (even if it is a computer) it may have a fraction of the computing power of a Pi it will probably be alive and kicking after the EMP from a nearby 300Kt airburst. The Pi will not be.

      All of this if they Norks did not f*** it up while cloning. The way they did trying to clone RedHat (or whatever else they cloned for their distro).

      1. Wzrd1 Silver badge

        Re: Impressive computing power shown in that picture

        Ah, but it's using a quite modern trackball.

        Perhaps he's merely playing Missile Command.

        1. TechnoTechno
          Mushroom

          Re: Impressive computing power shown in that picture

          @Wzrd1

          Global Thermonuclear War

    3. Anonymous Coward
      Anonymous Coward

      Re: Impressive computing power shown in that picture

      Cool, I have the same quirky mouse he's using. I use a piece of blu tack and a match on the red ball to use as a joystick when I'm playing my simulator flying around in my mig-21 fighting the real terrorist nation that is the USA.

    4. Anonymous Coward
      Anonymous Coward

      Norks Linux disto has security vulns

      Just like our distros then...

    5. harmjschoonhoven

      Re: Impressive computing power shown in that picture

      Impressive is not the computer in the cabinet, but the battery of Leclancé cells (model 1866) it contains as a power supply.

    6. DrGoon

      Re: Impressive computing power shown in that picture

      I didn't know that the Microsoft Trackball was compatible with a Mellotron.

  2. Destroy All Monsters Silver badge
    Trollface

    Not along the lines of Charles Stross

    Instead of "Big Brother Iron", Small Versatile Juché Bird.

    But still stalinistically centralized.

    And the ISOs leak! TREASON!

    1. Robert Helpmann??
      Childcatcher

      Re: Not along the lines of Charles Stross

      And the ISOs leak! TREASON!

      Not to take the troll bait, but yes, it most likely is.

  3. Anonymous Coward
    Meh

    Kim-Jong-Unix?

    Because I was seriously considering wiping out my Fedora 21 install and replacing it with this POS (not).

    But now that I know rc.sysint has 0666 permissions I think I'll just wait until Red Star 4.0.

  4. Mark 85

    What El Reg Really Needs

    is a caption contest for Dear Leader (the II?) photos. "See... American Invaders... move little gun at bottom and shoot down all the American missiles. Fun? Yes?"

    1. Zimmer
      Linux

      Re: What El Reg Really Needs

      Too late for that-

      ..and in any case Scaryduck would win every time...

      http://scaryduck.blogspot.co.uk/search/label/Kim%20Jong-un

  5. Matt Bryant Silver badge
    Stop

    WTF?

    To all those security "experts" bragging about the security holes they are finding in the Norks' Linux - STFU! Seriously, you're doing free bug-testing for a repressive regime, put your egos back in the box and leave Kim Jr and co in ignorance, please. You are not protecting "the people" as the few users in North Korea are going to be Kim Jr's thugs and scientists.

    1. Sir Runcible Spoon
      Meh

      Re: WTF?

      And if this happens to be the only OS someone in NK can get hold of, and they might be unfavourably disposed to the NK regime, shouldn't we give them a hand in securing their OS from their spying government?

      After all, we are doing the same to try and stop our own government.

    2. Stuart 22

      Re: WTF?

      Maybe the vulnerabilities were introduced deliberately so their security services could control their population.

      Perhaps I shouldn't have written that. It might give NSA/GCHQ ideas - oh, wait ;-)

  6. Irongut

    first seen in February

    Been looking into the crystal ball again guys? You really should have put a year on that one.

  7. Oldgroaner

    Where is it?

    Nice picture of Fatboy being helped to find the 'Any' key.

  8. wolfetone Silver badge

    Does it support Flash?

  9. Anonymous Coward
    Linux

    Attention US security researchers

    Clever move by the Norks - they 'accidentally' release their linux to the world, tricking 'despised western capitalists' into doing the security analysis work for them. They also get to appreciate the irony of the same 'despised western capitalists' turning into communists by doing the work for free. ;-)

    US security researchers better look out as Uncle Sam might decide that you're breaking sanctions by helping the regime. :-(

  10. Pez92

    Docky!

    Funny to see they use docky...apparently my XFCE Mint installation looks shockingly like Red Star.

  11. JamesTQuirk

    Yeah, also funny is HOW a twerp like him, can organize his nation into Linux users .... Hope they keep the security vuln's up, they are so insular, they will ...

    HOWEVER, if UK, Europe, Australian Governments, Made a Linux dist standard @ all Schools & Uni, in a few years, NO MORE MS royalties, wonder how much that would save TAXPAYERS, BANKS, Business in General ?

    1. Matt Bryant Silver badge
      Facepalm

      Re: James T Quirk

      "....HOWEVER, if UK, Europe, Australian Governments, Made a Linux dist standard @ all Schools & Uni, in a few years, NO MORE MS royalties, wonder how much that would save TAXPAYERS, BANKS, Business in General ?" I think you'll find that the Penguinistas have been trying to uproot MS from schools for years with very limited success (see http://en.wikipedia.org/wiki/The_Linux_Schools_Project for an example). Even leading lights such as the City of Munich have backed off Linux (http://www.theregister.co.uk/2014/08/19/munich_dumping_linux_for_windows/).

      1. JamesTQuirk

        Re: James T Quirk

        So schools back off, while MS uses Linux for it's clod drive "Azurb", makes sense, I suppose if you know wheather they receive grants from MS, Like CrApple they infest schools for same reason, Next gen Clients who think it's the only way to do it ....

        It amazes me, when I pass a CrApple shop, 50 people in red shirts, helping Crapple owners, lucky they are so easy to use, the advertising said so, & the ones in que waiting, still believe it too ...

      2. Teiwaz
        Devil

        Re: James T Quirk

        That Munich article was clickbait. As well you know

        The whole more IT in the curriculum thing would be far better served with Linux in the classroom. Years 1 and 2 cover the user basics and a little theory/history. Then RE-begin the course at 3rd year by having the students roll their own distro. That would sort out the real It techs and give them something to aim for, Free 1st class scholarships if you can hack a major business of gov of your chice...and other prizes for lesser achievements. Then you could give the finger to the 266 or whatever...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like