10 ms·
Stuxnet was embarrassing, not amazing (2011)
- ahartmetz 7y ago> Stuxnet does not use all advanced malware techniques the author can think of Why use (and give away) any more capabilities than required to do the job?
- coretx 7y agoStuxnet carried a irresponsible overload amount of 8 zero days. The US asked the Netherlands to implant it at the Iranian plant. TL;DR Whoever was responsible for Stuxnet within the US indisputably is mentally challenged / not a rational actor.
- deleted 7y ago[deleted]
- PostOnce 7y agoWho are we armchair generals to determine what is the needed amount? For all we know, they have a stockpile of thousands of zero days, or more! Plus, if "attempting to prevent nuclear war" isn't a responsible use of these zero days, then I would love to hear what you think calls for deploying them.
- coretx 7y agoOfficially, as in - what has been stated via formal public channels - Stuxnet was implanted to delay Iran's inevitable ability to use sufficient amounts of weapon-grade isotopes c.q to decrease the production by means of sabotaging centrifuges. Not to prevent nuclear war. If there are other or more reasons in play regarding why Stuxnet was implanted, it is something we're not likely to ever find out. What we do know for a fact is that it's atleast very risky and irrational at best to risk handing over a single let alone eight zero days to a adversary you deem to be bonkers enough to go nuclear since the reluctance to apply them is significantly lower compared to conventional or nbc weapons. To further answer your final question i'd say it depends on a multitude of factors among them the nature of the 0day, the theater of deployment down to the most mundane operational details and much more. Surely a analysis you do not want to be done by a armchair general indeed, but from the looks of it this might actually exactly be what occurred.
- blix 7y ago> What we do know for a fact is that it's atleast very risky and irrational at best to risk handing over a single let alone eight zero days to a adversary you deem to be bonkers enough to go nuclear since the reluctance to apply them is significantly lower compared to conventional or nbc weapons. Only two nuclear weapons have been deployed ever. This single 8 zero day attack already quadruples it. There is absolutely more relectance for nuclear. the "n" is not like the "bc" in nbc. Delaying Iran's enrichment program and preventing nuclear war are very similar goals. A near-nuclear Iran would likely foment a war in the region, involving at least one other nuclear capable state. Preventing Iran from obtaining weapons is a tactic to prevent the possibility of nuclear exchange in the region. I don't think the distinction you are drawing is valid.
- JadeNB 7y ago> Only two nuclear weapons have been deployed ever. … intentionally; if you want to feel a stark sense of wonder that we ever survived the height of the nuclear-weapons age, you could do worse than to read Schlosser's "Command and Control" (https://www.amazon.com/Command-Control-Damascus-Accident-Illusion/dp/1594202273 https://www.amazon.com/Command-Control-Damascus-Accident-Ill...).
- blix 7y agoOh yeah, it's miracle the USA didn't accidentally nuke itself. There are a lot of scary stories out there. However, I dont think that necessarily means nukes are taken less seriously than zero-days.
- JadeNB 7y ago> However, I dont think that necessarily means nukes are taken less seriously than zero-days. Sure, I didn't mean to argue that; only to point out that saying that only two nuclear weapons had been deployed, even if true in a perfectly reasonable sense, required at least some qualification.
- gdy 7y ago"if "attempting to prevent nuclear war" isn't a responsible use of these zero days" What on Earth are you talking about?
- manigandham 7y agoHow is it irresponsible? Because it gives away the exploits? That only happens if it gets reverse engineered. The main objective of stopping the nuclear arms enrichment was a more important goal and the security bulletins could be published anytime after the payload was delivered.
- pizza234 7y agoIn fact, there's no need at all. Some of the most complex malway (viruses, to be specific) every written (Zmist, MetaPHOR), which the post author would "appreciate", never had any wide diffusion; Stuxnet accomplished its task. All in all, the post author just wanted some attention.
- rafa1981 7y agoExactly. If it did the job why showing the enemy (and the world) all your cards, so they can learn your most advanced tricks? It's better to keep some advanced techniques for the next target than to expose them with no need.
- saagarjha 7y agoI mean, why obfuscate at all? Their malware did its job; after that what does it matter what happens to it? Is not adding additional obfuscation "run-of-the mill" or "amateur" as the author puts it?
- FakeComments 7y agoEquation Group seemed to hide their malware pretty well, after the first few times. Though, Shadow Brokers did steal a bunch, which led to problems. https://en.m.wikipedia.org/wiki/Equation_Group https://en.m.wikipedia.org/wiki/Equation_Group
- petjuh 7y agoBut Stuxnet did use obfuscation. The last payload was decrypted by concatenating two environment variables on the host and Symantec never managed to decrypt that one. Did author not read the Stuxnet report?
- m0zg 7y ago"The best minds are not in government. If any were, business would steal them away." -- Ronald Reagan
- pizza 7y agoIsn't that dependent on the best minds thinking they could perform their best performance in business?
- ci5er 7y agoOr money.
- golergka 7y agoDepends on motivation. Business probably pays better, but defending your country can give a person a sense of purpose.
- soVeryTired 7y agoNASA scientists are pretty well respected, you know.
- mattkrause 7y agoThe NIH, CDC, DoE, NOAA, the various DoD labs (ONR, ARL, AFRL, etc)--and more too. The NSF doesn't have a ton of intramural research, but they have very smart people on staff evaluating recent research and figuring out what to fund next; ditto for DARPA and several other agencies. It's not just technical stuff either. The FAA has made being shot through the air in a metal tube (i.e., flying) almost absurdly safe, so much so that driving to the airport is more dangerous than the flight itself. I feel comfortable eating food from the supermarket, thanks to the USDA and FDA. The Library of Congress's work is used in libraries around the world; their collections (and the Smithsonian's) are also useful for researchers and fun for the public. But sure, the real problem is that renewing your driver's license sometimes sucks.
- segfaultbuserr 7y ago
- zokier 7y agoOne thing that I've grown to understand is that the difference between enthusiast and professional is not the quality of goods they produce, but the economy of producing the goods. I feel like that is applicable here. If we want another example of high-profile security incident that was more embarrassing than impressive, Wannacry fits the bill.
- mettamage 7y agoMy English is too limited to be a 100% sure about the following: "economy of producing the goods" What does this mean? The amount of time it takes to produce another extra good? E.g. Enthusiast: 1 good per 5 hours -- quality level 85% Professional: 1 good per 0.5 hours -- quality level 80% Or something else?
- huffmsa 7y agoCorrect. The professional produces goods which are actually used in real life conditions, with real life delivery dates. The enthusiast produces goods which look pretty, but often don't work correctly, or need a lot more hours of work to surpass the professional.
- wizardforhire 7y ago... and the amateur produces goods out of love that end up powering the internet
- icegreentea2 7y agoI think it's a bit more subtle than that. Professionals are able to create output that more precisely solve the problem at hand. That means that they will often create output that does less. In the context of Stuxnet, the professional identified that the problem at hand was to shutdown the Iranian nuclear enrichment facility. They ended up with a piece of code that executed that, but was not maximally obfuscated, because more obfuscation does not solve the problem at hand.
- praptak 7y ago
- upofadown 7y agoIt's hard to be good when you work in complete secrecy. A typical malware creator can talk to anyone in the world. If they talk to white hats they just pretend to be on the side of good. The job of a government spook is much harder because of that lack of communication. You are always on the outside looking in...
- manigandham 7y agoThe Wired article on Stuxnet remains one of the best long-form stories I've ever read: https://www.wired.com/2011/07/how-digital-detectives-deciphered-stuxnet/ https://www.wired.com/2011/07/how-digital-detectives-deciphe... The criticism here seems to be mostly academic about not using the most advanced obfuscation while completely ignoring the actual objective and just how many obstacles were overcome. The mission used several 0-days and stolen signing keys to get into a secret foreign air-gapped nuclear arms laboratory under a deadline and ruin the machinery while it kept reporting everything was fine. I dont see how this is anything short of amazing.
- kqr2 7y agoKim Zetter's article evolved into the book Countdown to Zero Day https://smile.amazon.com/Countdown-Zero-Day-Stuxnet-Digital/dp/0770436196/ https://smile.amazon.com/Countdown-Zero-Day-Stuxnet-Digital/...
- emilga 7y agoHere's a good documentary about Stuxnet as well: https://www.youtube.com/watch?v=TGGxqjpka-U https://www.youtube.com/watch?v=TGGxqjpka-U
- abbadadda 7y agoYeah this definitely read to me like a click bait title and article. The shortfalls seem trivial in the grand scheme of what was accomplished.
- anaisbetts 7y agoYep, I worked in Windows Servicing at the time it came out, there were at least 4 separate completely unknown-at-the-time exploits in Stuxnet. They most likely stole the signing certs by dropping USB keys in an office park in Taiwan, all of the stolen certs were from companies which shared a particular parking lot
- pharrington 7y agoYeah, with a headline like that, I was expecting an article about the international implications regarding why/how something like Stuxnet is even created and deployed in the first place. The technical merits of the operation are the absolute last thing to be embarrassed about.
- CapitalistCartr 7y agoThis is juvenile Monday-morning quarterbacking. Stuxnet was the first (as far as we know). It was revolutionary at the time. Of course its authors didn't know how agressive antivirus researchers would be, agressive largely because of the fascinating complexity of the code. Almost all malware gets a cursory glance and thrown in the bitbucket after processing. The first one of anything is always the crudest. Getting away with industrial, state-sponsored cyber-sabotage is a huge step.
- blotter_paper 7y ago> The first one of anything is always the crudest. Getting away with industrial, state-sponsored cyber-sabotage is a huge step. I know the claim is disputed, but if the CIA did cause the Trans-Siberian pipeline to explode in the '80s then that would count as prior art. Even if true it was nowhere near as complicated as Stuxnet, of course.
- huffmsa 7y ago> "But this isn't academically good code." As others have said, the only real metric of whether or not something is good is if it works in live production.
- eternalban 7y agoNo, that's a metric for "something is working". Ease of maintaining, extending, or fixing bugs in the same software are not informed by that metric.
- chris_wot 7y agoExcept in this case, where it was a one-shot, very specific objective. Once this thing was released, it could not have been easily updated.
- huffmsa 7y agoIt's a classic misunderstanding between "academically viable" and "operationally viable". The military doesn't need to get an A+. It needs to win. Anything else is a bonus. Which is why the A-10 is a better plane than the F-35. One shows up and BRRRTs the opposition into a fine red mist, when you need it to. the other makes it pilot motion sick as soon as they put the helmet on.
- GhostVII 7y agoThe A-10 and F-35 are completely different planes for completely different purposes. The F-35 attempts to be able to perform most of the things the A-10 does, but you can't just say one is better than the other overall. The A-10 is probably better at shooting ground targets at close range. The F-35 is better at bombing them from 5 miles away.
- huffmsa 7y agoThat's the problem though. The F-35 tries to be good at too many things. It has the latest sensors and stealth and armaments. But it's taking forever and a day to get the damn thing out the door because it's too academically excellent.
- gzer0 7y agoI will suggest another alternative. The authors weighed the risk of not being successful vs the risk of someone analyzing the worm. The latter was inevitable but the former would have been disastrous. Those protections would have only slowed down malware analysts. If this was normal malware that would be the goal, exist for as long as possible without being detected. ‘Normal’ malware has a high tolerance for failure. In this case the goal appears to be ‘break some sensitive equipment before a particular deadline hits’, with a razor thin margin for error. But your points are not lost, good post.
- allworknoplay 7y agoDid you really just copy/paste the top reply from the article, without attribution or comment?
- voldacar 7y agoI've seen bits and pieces of disassembled stuxnet code around the web, does anyone here know where I could get my hands on the original binaries?
- throwaway3Nov19 7y agoBe careful what you wish for. Research a Windows registry key with a value of 19790509. Read up on why. To help validate any code, search for the string 2WSXcder
- onetimemanytime 7y ago>>Stuxnet was embarrassing, not amazing (2011) Stuxnet worked. Deal with it. Of course, for obvious reasons, it would be traced back to US/Israel and not to a kid in his mom's basement.
- deleted 7y ago[deleted]
- heelix 7y agoWhile some hiding is required to get past the virus scanners... Once it trashed the centrifuges, there is huge value in letting the target know they were pwned. There had to be a huge internal "who's the internal spy/saboteur" hunt that planted it - even if it was accidental - and the weapon grade target of the micro controller to let them know it was no accident.
- DuskStar 7y agoI'd think a witch hunt is exactly what you'd want if there were no internal saboteurs, though. Getting the enemy to waste time, effort and loyalty like that would be the perfect cherry on top of the physical disruption.
- heavenlyblue 7y agoThere are so many system configuration parameters you can collect to encrypt the payload. If you did so, it should not be too hard to enumerate all of them. Moreover, the virtual machine-based code obfuscation is being regularly pwned by software cracking teams so I can imagine that obfuscation would only postpone the publication of the tool’s code for a week max.
- Vaslo 7y agoThey literally found a way to trash an enemy’s weapons of mass destruction equipment without bombing cities and hurting people, but somehow that’s an “embarrassment.”
- gdy 7y agoEnemy's? Are the US and Iran at war? Were they ever? Imagine somebody did that to the US in the peace time. Oh, I forgot, Iran wants to take away your freedom.
- casefields 7y agoAttacking infrastructure is an act of war. In 2011 the Pentagon took this stance on cyber warfare: “For the first time, the Pentagon has decided that cyber attacks constitute an act of war, reports The Wall Street Journal. The U.S. military drafted a classified 30-page document concluding that the U.S. may respond to cyber attacks from foreign countries with traditional military force, citing the growing threat of hackers on U.S. infrastructure such as subways, electrical grids or nuclear reactors.” https://www.theatlantic.com/technology/archive/2011/05/pentagon-cyber-attacks-act-war/351239/ https://www.theatlantic.com/technology/archive/2011/05/penta...
- MaupitiBlue 7y agoIt delayed nuclear proliferation without harming a single soldier or civilian. If that’s an act of war, then I guess I’m a war monger.
- paulie_a 7y agoYet it worked. Just like the NSA Cisco exploit chain. According to armchair programmers it was ugly. But it worked it could take over every Cisco router. it doesn't have to always be pretty if it gets the job done.
- dblotsky 7y agoWe often forget, but even the world’s top professionals get tired, cut corners, and make mistakes. But also, what substantial gains would have come from adopting the techniques in this article?
- nathanvanfleet 7y agoThis reeks of "I could have done it better" but if they accomplished it with what they had what can you really say? Nice to know there were myriad of other "better" ways to do this. But it's not an embarrassment.
- tobbe2064 7y agoThe book recommendation at the end, Surreptitious Software, seems interesting. Does anyone know if it is still relevant, or there are newer more relevant books on the market with the same goal?
- hn_throwaway_99 7y agoRandom question for HN: How to articles like this get upvoted so much? Virtually all the top comments talk about how this is an amateurish, Monday-morning quarterbacking effort. Is it just spam upvoters?
- oxide 7y agoNo, it's just the people who vote and the people who comment are very different.
- Bendingo 7y agoIt's OK if USA/Israel does it, otherwise it's an act of war. More hypocrisy from the "good guys".
- arpa 7y agoWhat did Bulgarian teenagers do in the early 90s? all links to the story are dead.