North Korea's homegrown Red Star OS computers watermark all documents and media files on inserted USB sticks, to track underground sharing
Context & Ripple Effects
This finding completes a picture that started earlier in 2015, when a hands-on with North Korea's Naenara Browser showed Red Star OS shipping its own Firefox variant for the state intranet. The new reporting shows the same homegrown OS also treats removable storage as a monitoring surface: any document or media file written to an inserted USB stick gets watermarked, tying copies back to the machine that made them.
That matters because USB sticks are the main channel for media that circulates outside North Korea's controlled networks — the same offline-sharing culture that later coverage of the Chinese-made Woolim tablet and defector interviews about heavily monitored phones describes the state trying to close from the device side.
First-order effects
- North Koreans using USB sticks to share films, music, or documents can now be traced through watermarks embedded at copy time, raising the personal risk of what was previously an anonymous offline exchange.
Second-order effects
- The state's surveillance perimeter expands from networked access points like the Naenara browser and intranet-connected phones to physical media, so circumvention efforts shift toward defeating or stripping the watermarking rather than just avoiding online connections.
Third-order effects
- If every layer of the computing stack — OS, browser, tablet, handset — ships instrumented by design, North Korea becomes a working model of surveillance-first consumer computing; the later UEFI firmware malware Kaspersky found targeting diplomats suggests the same state's tooling eventually reaches beyond its borders.
The trend: State-controlled computing environments are converging on instrumenting every layer of the stack — operating system, browser, mobile device, and now removable media — so that no user action sits outside the monitoring surface.