11 ms·
Hackers Are Targeting Nuclear Facilities, Homeland Security Dept. And F.B.I. Say
- watertorock 9y agoI'd imagine every piece of infrastructure is targeted that can be. What's going to be done about it is the real question.
- nthcolumn 9y agoTrue but a wind farm taken over by hackers is still just a wind farm not a thermonuclear weapon.
- DennisP 9y agoA nuclear plant taken over by hackers isn't a thermonuclear weapon either.
- emiliobumachar 9y agoThe implication is that, once it's taken over, the hackers could intentionally trigger a Chernobyl-scale spill. Not quite as bad as a nuclear weapon detonated in a big city, but still very bad.
- DennisP 9y agoIt's unlikely that hackers could manage even a Chernobyl-scale problem on a modern nuclear plant. Chernobyl had several horrendous flaws. For one, it had a positive feedback: as the fuel got hotter, the reaction sped up. With modern plants the opposite occurs. Also Chernobyl had no containment dome. Even the old GenII designs in the U.S. have much better inherent safety than Chernobyl had. There's no way to hack away physical barriers. Even TMI, our worst accident ever with a full meltdown, did not breach the containment barriers. And of course with any commercial plant, there's absolutely zero chance of an actual nuclear detonation, much less a thermonuclear one as mentioned in the comment above. The fuel just isn't enriched enough to work as a bomb.
- packetized 9y agoThis might be the most top-heavy title I've ever read, given the economy of words. "Hackers Are Targeting Nuclear Facilities, Say Homeland Security Dept. and F.B.I." would be much more balanced - or am I just off my rocker?
- milkytron 9y agoThis made me wonder if articles purposely place more meaning words closer to the front to get attention of viewers sooner. I'm no expert in journalism by any means, and I guess this comment has nothing to do with the article itself, but it did spark some curiosity.
- nthcolumn 9y agoIndubitably any facility of sufficient complexity or strategic value will draw more or less continuous unwanted attention from foreign state actors. 'Targeted by hackers' could include port scans and phishing attempts. What with the recent, perhaps only perceived, upsurge in activity it is hard to know whether this is complete bunk, nsa-script-kiddie open season or something even more sinister. It is sad that the agencies in question no longer enjoy the level of trust by the public they once had.
- narrator 9y agoWhenever I see (nytimes.com) after a URL I know that there's some big long bill that's been sitting in a drawer somewhere that's going to suddenly get pulled out of that drawer and will be voted on next week and this is just setting the stage for it.
- late2part 9y agoThanks for posting this. Reminding us of correlations like this is important. Sometimes we can't see the forest for the trees. Thank you.
- pgwhalen 9y agoInteresting, can you point to previous examples of this phenomenon? Would love to see the correlation.
- CodeWriter23 9y agoThe most obvious would be The Patriot Act, some 342 pages presented to Congress just 6 days after 9/11.
- aaronbrethorst 9y agoOnly one example from 16 years ago?
- mirkules 9y agoTrying to look around, it's actually pretty difficult to support or disprove this retroactively. For one, NYT's archive is kind of behind a paywall. My searches only net me some NYT blog entries usually not related to anything of relevance. Secondly, even if I were to find an article that is related to some piece of legislation, it would only be speculative and wouldn't prove that it is a "hit piece" in support for or against it. Thirdly, off the top of my head, I can only think of a few things: SOPA from January 2012, Patriot Act (as mentioned earlier), the iPhone/FBI encryption fiasco (which did not result in any legislation yet, afaik), Net Neutrality, and Snowden/Wikileaks stuff (again, did not result in legislation afaik). More examples are always welcome, but as I said, it is really tricky to speculate on the existence of a conspiracy based on a few articles and some hindsight - you really open yourself to confirmation bias, subconsciously. And for the record, I'd love to prove this is true.
- protomyth 9y agoSince May, hackers have been penetrating the computer networks of companies that operate nuclear power stations and other energy facilities, as well as manufacturing plants in the United States and other countries. Wolf Creek officials said that while they could not comment on cyberattacks or security issues, no “operations systems” had been affected and that their corporate network and the internet were separate from the network that runs the plant. Good, I'm glad they are not insane, but I also hope they have pretty stringent rules to keep personnel from plugging in unverified devices. Stuxnet should be a lesson to all.
- dreamcompiler 9y agoThey're not insane; they're just lying. 15 years ago it was believable that control networks were airgapped from the Internet. But today, the likelihood that some low-level tech has plugged a wifi router into the control network for his own convenience approaches 100%.
- jerrylives 9y agohttps://arstechnica.com/security/2015/10/report-finds-many-nuclear-power-plant-systems-insecure-by-design/ https://arstechnica.com/security/2015/10/report-finds-many-n...
- dreamcompiler 9y agoThank you. The downvote is amusing given the abundance of evidence in support of my comment. Did the downvoter think I was being sarcastic?
- protomyth 9y agoAnyone working for a Congress person might want to heed dreamcompiler's comment and introduce a bill to ban WiFi at all nuclear power plants.
- 9y ago
- astrodust 9y agoThe US administration is under the impression that they can wage a conventional war against an adversary like North Korea, yet this is the same nation-state actor that is claimed to have hacked into Sony. If North Korea is attacked militarily expect hell to be unleashed online. What we've seen is just experiments, not actual attacks. A full-out war could be vastly more damaging.
- thehardsphere 9y agoPlease. "Hell online" is going to be trivial compared to the thousands who will die in the first hours of the conventional artillery shelling of Seoul. Let's not pretend that some leaked emails are in any way going to be as bad as that. And frankly, hacking into Sony is not that hard to do.
- cmurf 9y agoThe casualties will, and should, stun people. The Korean War, 1950-1953, total civilians killed/wounded: 2.5 million (wikipedia), and cost $341 billion in 2011 dollars (Congressional Research Service). And then there will be a massive refugee problem on both sides.
- deleted 9y ago[deleted]
- thehardsphere 9y agoAnd since then, South Korea's population has gone up. There are something like 20 million people living in the Seoul greater metropolitan area. A future war here might make every war we've had in the sandbox lately look like a summer barbecue.
- astrodust 9y agoSo long as the planet of the population keeps going up and the population density of cities increases the chance of multiple millions of people being killed in a single military exchange keeps escalating. I'd like to think we can keep a lid on things and work it out in a more civil manner, economically it makes more sense, but you know, dictators don't really care about economics as much as they do ego.
- thehardsphere 9y agoAren't hackers always targetting Homeland Security and nuclear facilities? Hasn't this been the plot of 24 for over a decade now?
- daxorid 9y agoYes, but it becomes a much higher media priority when the entire intelligence community begins to agitate for WW3 with Russia. I knew before clicking that there would be a baseless nod to *Bear attribution in this article, and it certainly didn't disappoint.
- tree_of_item 9y agoWhat makes you think they are "agitating" for WW3 and not simply responding to actual aggression by Russia?
- CodeWriter23 9y agoBecause the US has clearly stated it wants Assad out of Syria, and Russia has clearly stated it wants Assad to remain. And nobody gets away with telling the US how it's going to be when it comes to oil supply.
- knowaveragejoe 9y agoIs the implication that oil supply has much to do with Syria? I understand Russian natgas companies have some pipelines that traverse the country into Turkey and their eventual customers and Europe, but I'm failing to see what that has to do with oil and the US. The US gets most of its oil from Canada.
- CodeWriter23 9y agoLooks like the US gets most of its oil from home. 62.1% https://www.google.com/amp/s/www.forbes.com/sites/rrapier/2016/04/11/where-america-gets-its-oil-the-top-10-suppliers-of-u-s-oil-imports/amp/ https://www.google.com/amp/s/www.forbes.com/sites/rrapier/20...
- oldandtired 9y agoAs long as the systems controlling infrastructure (of any kind) are network accessible, they are internet accessible. Hence, they will be attacked. Convenience always works to the attackers gain, and convenience is the name of the game for engineers and managers and support staff. Unless the system is physically isolated and protected and there is no kind of networking available, it is effectively crackable. Even if physically isolated, staff can still be bought.
- crb002 9y agoI translate that into contractors aren't required to warranty their embedded components. Rewrite the contracts.
- ams6110 9y agoMost US nuclear plants were built in the 1970s. How much "computer networking" do they really have?
- cocoablazing 9y agoNon-safety-critical components in the steam plant are likely to have networked PLC control. While nuclear probabilistic safety assessments support that licensed reactors can safely endure casualties involving such components, the safety system is subject to failures and crippling the plant and causing a reactor transient is likely a good enough result.
- topspin 9y agoEvery nuclear power plant in the US has an NRC mandated Safety Parameter Display System. These were retrofitted after the TMI-2 meltdown. The SPDS is supposed to provide a concise view of critical parameters to avoid the sort of confusion that led to the TMI-2 incident. In 2003 Davis-Besse had its SPDS disabled by SQL Slammer, a worm that congested the network on the site. So in answer to your question, yes these 1970s plants do indeed have devices interconnected in the contemporary manner, and compromises of these networks have already produced reportable events. The core components of our power reactors are not at the mercy of software; operators have authority over reactor protection systems that are deliberately independent of complex digital controls. Nevertheless, a clever attacker could probably engineer enough confusion or interfere with ancillary systems badly enough to produce a notable incident such as a SCRAM. That would certainly make headlines and lead to a prolonged investigation. Is it possible that greater damage could be done? Anything is possible. If so I'd imagine it might involve cooling pools, their circulation and alarms... who knows. Given enough time, knowledge and planning it might be possible to cause a serious problem.
- tbihl 9y agoIf a power plant scrams, how long is the subsequent startup? Do they have any sort of fast recovery procedure?
- 9y ago
- dsfyu404ed 9y agoMaybe I won't have to wait for sea level rise to wipe my hometown off the face of the earth, some jerk in Russia will pop the nuclear plant that's up-wind and it'll be uninhabitable.
- dilemma 9y agoOf course they are. They hate your freedom. So long and thanks for the propaganda, NYT.
- jpitz 9y agoThere must be subtext here that I don't understand.
- fatbird 9y agoThe NYT was one of the chief cheerleaders for the Iraq War, both through Judith Miller being an outright mouthpiece for Bush administration propaganda, and more generally through being a friendly media outlet of "balanced" thinkpieces that set the stage for popular support for a non-declaration-of-war (the AUMF) that allowed Bush to invade Iraq based on some nebulous threat of a WMD attack in the U.S. that was never real.
- 3131s 9y agoThey also had an editorial policy of not referring to any action committed by US forces as "torture" until 2014.
- Animats 9y agoI'm worried. I've been following the Maersk outage. The world's biggest shipping line still hasn't fully recovered. Their less automated ports were down for several days. LA and NJ finally came back up about two days ago, but operations are still partially manual and they're running longer hours trying to cope. Their most automated port, Maasvlakte II in Rotterdam, is still processing imports only; no exports. Some containers there are stuck in the stacks; they have a list of which containers can be reached. They're requiring paper customs forms and a paper commercial release, instead of their usual paperless system. Earlier, they were so down that the automated cranes could not unload ships. This is what Maasvlakte II looks like in normal operation. There are no people on the quay at all. All those cranes and AGVs are automated.[1] Maersk's financial side is still down. They're not sending out invoices, which means zero revenue. They just announced a price cut, to keep shippers. Some of their phone and email systems are still down. The booking side is now up, so they can take new shipping orders. This is the first time we've seen real-world outages of this magnitude. It may not be the last. (Where's the Flexport guy who posts on here? He has to deal with all these problems. Flexport is a freight forwarder, which means that when something goes wrong with freight they are forwarding, it's their problem to fix it.) [1] https://www.youtube.com/watch?v=zm_rlLyelQo https://www.youtube.com/watch?v=zm_rlLyelQo
- flukus 9y agoHow is this not bigger news? I assumed the lack of coverage meant that everything was back to normal. Had this been several of the big shipping companies at once the world would be reeling by now, especially economically.
- heartbreak 9y agoSmaller than global shipping, but I purchase pet food for veterinary clinics and Royal Canin (subsidiary of Mars) is still not at 100%. Their order fulfillment and accounting were hit. I suspect this hit many B2B companies that we're not hearing about because they're small and we aren't customers.
- Animats 9y agoMaersk has been emphasizing that they're back up at most of their ports, but not emphasizing that the really big automated ones, Elizabeth NJ, LA, and Rotterdam were hit hard. The mainstream press gets their info from press releases. Most of the press coverage reads "Maersk says". I have yet to see an article where someone went down at the docks to find out what's going on, or called a union rep, or talked to truckers. There's coverage on gcaptain.[1] Mentions on Reuters.[2] There's lots of coverage on the sites that cover container shipping. Most of the people in that business are probably working overtime right now. With Maersk down, cargo all over the world had to be re-routed. All the status info is on line, but not in a journalist-friendly form. Maersk has a temporary "Operational Update" page.[3] You have to read through a lot of material to see what's up and what's down. As of late today, almost everything is at least limping along except at Maasvlakte II in Rotterdam. Their web site for booking and tracking has a banner which says "Submit Shipping Instructions and Booking are available but without email confirmation. Tracking, Online Quote and Binder are unavailable. Schedules last updated 27th Jun so may be inconsistent." This is not "back to normal". Here is the Port Authority of New York and New Jersey's latest alert page for truckers: [4] That's a good read, because it's a no-bullshit source of info. Somewhere at the Port Authority, there's someone with a clue who gathers that info and gets it out. Staying open late and operating Saturday is not normal. Maersk APM's status page for LA is totally bogus; it hasn't changed in the last week.[5] The online gate webcams at Maersk's port in LA are still down. (I've followed this subject because I'm interested in mobile robots which do something useful. Maersk's Maasvlakte II terminal is one of the largest mobile robot operations in the world. Probably the biggest by tonnage. Downtime on this scale is a major event in robot history.) [1] http://gcaptain.com/maersk-hopes-full-cyber-recovery-early-next-week/ http://gcaptain.com/maersk-hopes-full-cyber-recovery-early-n... [2] https://www.reuters.com/article/us-cyber-attack-maersk-idUSKBN19R24D https://www.reuters.com/article/us-cyber-attack-maersk-idUSK... [3] http://www.maersk.com/en/operationalupdate http://www.maersk.com/en/operationalupdate [4] https://www.paalerts.com/recentmessages.aspx https://www.paalerts.com/recentmessages.aspx [5] http://www.apmterminals.com/en/operations/north-america/los-angeles/daily-terminal-information http://www.apmterminals.com/en/operations/north-america/los-...
- strictfp 9y agoGovernment warfare is really the worst thing that has ever happened to the internet. I wish they would leave this old-fashioned territorial thinking to rot in the material world.
- skepticaldrunk 9y agoI hate to be that guy, but you know that the internet as we know and love it today started out as ARPAnet, right? The internet was domesticated, not weaponized.
- IIAOPSW 9y agoI'm skeptical that there's a real threat to nuclear facilities. I've visited reactors before and seen first hand that the control rooms are all still based on analog components. The reason for the analog components is precisely because they are reliable and unhackable. When it comes to physical security, I can't think of a harder place to break into than a nuclear power station. You're not going to sneak in that's for sure. This reeks of manufactured consent. Are you afraid of hackers yet?
- kuschku 9y ago> You're not going to sneak in that's for sure. Wasn't one of the IS terrorists of Paris employed in Belgium at a nuclear powerplant?
- IIAOPSW 9y agoI literally do not know anything about this. Didn't even know Belgium had a nuclear power plant. Source please? I can't speak for Europe, but I know in America even if you worked at the place you're not pulling off an attack. You're not going to sneak a gun past the check point. If you do somehow sneak in a gun or a knife, you're not going to live very long before the guards kill you. You're not going to get into someplace where your keycard/job status doesn't let you. Overall the most likely outcome is you trigger an unscheduled reactor shutdown and throw your life away. I can't imagine anyone making a 6 figure reactor job salary throwing their life away. Money > religion.
- kuschku 9y agoApparently he left the powerplant and went to Syria to do jihad there, but still: http://www.brusselstimes.com/belgium/1154/belgian-jihadist-former-worker-at-doel-nuclear-plant-dies-in-syria http://www.brusselstimes.com/belgium/1154/belgian-jihadist-f...
- IIAOPSW 9y agoI'm genuinely surprised. Too bad we can't interview him. He certainly doesn't fit the profile of the typical jihadist. Still I stand by my point. Attacking a nuclear power-plant as an inside job is virtually impossible. There's enough physical security and mechanical fail-safes that nothing bad would happen. Edit: also what the other guy said. He was a weld inspector. Nevermind, everything makes sense now. Sensational scare article is sensational.
- coldtea 9y agoSorry, why are "Nuclear Facilities" on the internet in the first place? Or the FBI for that matter... If they mean they are targeting some public facing BS server for some website they keep, OK, who cares... But anything functional and touching controls should be very well out of bounds...
- notspanishflu 9y agoRubén Santamarta is going to talk about vulnerabilities that affect widely deployed radiation monitoring devices in nuclear facilities. "The purpose of this talk is to provide a comprehensive description of the technical details and approach used to discover multiple vulnerabilities that affect widely deployed radiation monitoring devices, involving software and firmware reverse engineering, RF analysis, and hardware hacking." That will be July 26 at Black Hat USA 2017. Go Nuclear: Breaking Radiation Monitoring Devices https://www.blackhat.com/us-17/briefings/schedule/index.html#go-nuclear-breaking-radiation-monitoring-devices-6829 https://www.blackhat.com/us-17/briefings/schedule/index.html...
- dmix 9y agoIf this was the 50s or 60s the government would never allow a talk like this to happen. Anything to do with nuclear was kept as a black art. Fortunately that paranoia has lifted so we can have safer systems.