14 ms·
How Stuxnet was deciphered
- losethos 15y agoGod says... instruction Luxury recount benefits exhorting track helpful experience fresh exhortation undid discoverable during disorder Milanese beholdeth tenderness duller gnawing separateth every
- sambeau 15y agoAs software now sits between pedal and brake and cars are beginning to be increasingly connected should we expect to see more assassinations performed this way? Google now has a fully-functional driverless car and at least one US state has approved their use on the road. Who needs polonium when you can send a virus out to seek a car?
- nekitamo 15y agoThe potential to murder with computers has been around for a while already. Governments are just waking up to it. To use the classical example: imagine hacking into a hospital network and changing a patient's blood type...
- munin 15y agoscary thing (imo) is that computer hacking is (compared to what you would otherwise have to do) so low cost and low risk that now "unknowable" assassinations (i.e. difficult or impossible to tell if the death was an accident or not) are within reach of everyone ...
- trebor 15y agoI disagree. One, you must have the knowledge of how to hack that specific car's ECU. You must know the make, model, and exact ECU of the car. Two, you have to actually be familiar with reverse-engineering ECUs to begin with. Three, you need special equipment to connect to an ECU diagnostically, let alone in a way to reprogram it. This adds up to a lot of hassle, and greatly limits the number of people who have the skills to pull this off. Who would develop this method but a government with the time/manpower to create and test it? And, if the government wants you assassinated, why would the government allow a real/accurate investigation anyway? It would be far simpler to create a small microcircuit to play havoc the the ECU, than to hack the ECU. But, even then you'd primarily just lose mileage (and a mechanic would quickly locate it).
- sambeau 15y agoThat requires physical access to the car.
- gcb 15y agolike script kiddies doesn't learn all that to just deface websites already....
- trebor 15y agoUnlike a website, a car requires access to a physical, proprietary interface to embedded components. You must craft an attack to the interface and ECU. And there are chips that can have their memory permanently burned into them (I don't know if ECUs use them, however). Patches are impossible, but there's no risk of infection either. Just test it rigorously first.
- owenmarshall 15y ago>Unlike a website, a car requires access to a physical, proprietary interface to embedded components. That's not necessarily true. For example, my car's ECU can be reprogrammed using the instrumentation bus. The instrumentation bus can be accessed using the wires that interface with the CD changer. That means that the audio system is on the same network as the ECU -- and if I had a Bluetooth adapter, that'd likely be on the same network as well. Indeed, researchers can disable electronically controlled brakes via Bluetooth: http://www.technologyreview.com/computing/35094/?ref=rss&a=f http://www.technologyreview.com/computing/35094/?ref=rss&... >Patches are impossible I've had to take my car in for patches a few times. Where there is software, there will be patches required. At the end of the day, I doubt we will be seeing assassinations via car hacking. But I wouldn't call it impossible.
- gcb 15y agoexactly. and even more worrisome, on-start shenanigans is tied to all kinds of sensors on your car. and it has a data connection. 24/7.
- AndyJPartridge 15y agoYou know, that's the first good reason I've ever heard for me getting a tattoo.
- rcxdude 15y agoAFAIK a bedside test is always done before a transfusion, simply because the records cannot be trusted even without malicious intervention (and a test is pretty easy to do).
- mkr-hn 15y agoIt's a complex attack vector for a simple problem. If you have enough access to tamper with the software, why not just remove the cap from the brake fluid reservoir? It's faster than figuring out how to access the PCM [1] (to tinker with the throttle code) and less likely to fail. And it would be catastrophically poor planning on the part of car designers to make car firmware remotely modifiable. We're not talking about general purpose computers here. [1] http://en.wikipedia.org/wiki/Engine_control_unit http://en.wikipedia.org/wiki/Engine_control_unit
- trebor 15y agoExcept that the target may discover the leak, and the lack of ability to brake; newer cars will warn when the fluid pressure is low. Switching the car to first gear to slow could get the driver out of immediate danger. I think the emergency brake uses a wire that is directly connected to the brakes. However, I do presume that the victim is paying attention to their vehicle and not in a sudden emergency condition.
- sambeau 15y agoIt's a vector, however, that needs no physical access to the car. It can be launched remotely from another country. Who would have thought a centrifuge could be attacked in this way?
- FaceKicker 15y ago> It's a vector, however, that needs no physical access to the car. Are you sure about that? I can't imagine they'd put these autonomous driving systems on the network... Didn't Stuxnet itself require at least physical access by proxy in that it was propagated through USB drives being physically used in the victim's systems?
- owenmarshall 15y agoMany cars have Bluetooth support. All it takes from there is the engineer putting the powertrain bus/ECU on the same network with the Bluetooth adapter. As I posted below, my Saab's engine control unit can be reprogrammed by splicing a few wires onto the CD harness. That means the audio network can at least access the ECU. I don't have a Bluetooth adapter on my car, but if I did, I'd wager it can access the audio network...
- funkah 15y agoThat's not what bothers me about software being used in important physical systems like the brakes of a car. What bothers me about that is not knowing anything about how that software was developed or tested, the amount of rigor that went into it, etc. All software has bugs but the laws of physics don't.
- bshep 15y agoVery interesting read. Although I would have preferred if they hadn't said the ending at the beginning of the article.
- hardy263 15y agoThe difference between stories and technical papers is that stories leave the conclusion for the ending and technical papers put the ending at the beginning. The article seems to share a bit of both.
- ugh 15y agoI always liked this talk by Bruce Dang at 27C3 (December 2010), telling (part of) Microsoft’s side of the whole Stuxnet saga: http://www.youtube.com/watch?v=73HlkCI-GwA http://www.youtube.com/watch?v=73HlkCI-GwA
- namank 15y agoThe whitepaper: http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf http://www.symantec.com/content/en/us/enterprise/media/secur...
- hammock 15y agoI dislike these magazine articles posted online that are some 8 pages long and the entire first page is simply the hook, no real info. Sorry, I am not going to read you, espeically if I came to you not for a feature story, but for a piece of specific news info, e.g. "how stuxnet was deciphered." Am I the only one who feels this way? edit: not sure why opinion = downvoted.
- rsingel 15y agoBecause it's lazy tldr; thinking. It's an extremely well-written article and there's a easily found view-as-one-page button at the bottom.
- hammock 15y agoDude you are a writer for Wired.com. I'm not surprised that you would bristle at my criticism.
- OWaz 15y agoYou should look in to Instapaper if you find multi-paged articles distracting. There are other alternatives as well such as using the print page to see all of the text on one page.
- pnathan 15y agomultipage articles are annoying due to the multipage. usually there's a print option. but don't think tl;dr.
- tzury 15y agonext time try this http://www.readability.com/articles/1fyqqx1d http://www.readability.com/articles/1fyqqx1d or instapaper. the design sucks indeed, suites paper format, not web.
- TeMPOraL 15y agoI just finished reading the article via Instapaper on my Kindle. It's much nicer this way (sans photos).
- Roritharr 15y agoThis is easily the most interesting article i've read in the past 6 years.
- funkah 15y agoI really enjoyed it as well. It provides enough technical detail while still being accessible. Some of the analogies are a bit of a stretch, but you'll have that. I was disturbed by the implication that the researchers should stop investigating Stuxnet (or refrain from publishing) because of the possibility that it was a US or Israel covert op. There are so many problems with that reasoning, and I'm glad they weren't swayed by it.
- nutjob123 15y agoWill you still hold that opinion if Iran develops and uses nuclear weapons?
- adolph 15y agoThat would moot the point, no?
- 3pt14159 15y agoNot sure if this is a username troll, but at this point many people had the stuxnet code, so all that would have happened if they didn't publish their findings is that it would have increase the risk to our power plants because it made it more accessible to the people that are actually in the position of defending our power plants, whereas enemy clandestine intelligence agencies would have the motivation to analyse the code anyway and re-purpose it for an attack. Furthermore, even if Iran does make WMDs, they do not pose a serious threat to Israel or the United States. Their delivery systems (missiles/rockets) are very antiquated and can be reliably intercepted and a suitcase nuke has extraordinary low yield. And even if they somehow gain the capability to effectively use their WMDs they would not do so due to MAD.
- felipemnoa 15y ago
- aorshan 15y agohttp://vimeo.com/25118844 http://vimeo.com/25118844 is a really cool video that helps explain a lot of the same information about the virus. Not as technical, but it is still very interesting.
- joshstrange 15y agoI saw this video back when it was first uploaded, very interesting video and well done
- yread 15y agoThe article made me remember of this virus I've heard about. Supposedly, it was accessing a rotation media (harddisk, floppy disk? I don't remember) in different patterns and monitoring the failure rate for each pattern. Then it would keep accessing it in the pattern that caused most errors which would kill the hardware device - as the errors were supposedly from resonances caused by movements of the reading heads and would cause physical stresses in the device. Anybody else heard about that?
- Create 15y agoCommodore 1541 FDD, but it was serviceable. ps: also similar was setting "unfriendly" scanrates for unprepared CRT-s, Samsung notebook HDD "click of death". memoryhole: https://secure.wikimedia.org/wikipedia/en/wiki/Commodore_1541#The_drive_head_misalignment_issue https://secure.wikimedia.org/wikipedia/en/wiki/Commodore_154... though my all time favourite is the ping
- Steko 15y agoWasn't that the sort of thing Tsutomo Shimomura specialized in? I remember it being hyped as part of the danger of Kevin Mitnick's hacking into his systems.
- deleted 15y ago[deleted]
- landhar 15y ago"On June 17, 2010, Sergey Ulasen was in his office in Belarus sifting through e-mail when a report caught his eye. A computer belonging to a customer in Iran was caught in a reboot loop — shutting down and restarting repeatedly despite efforts by operators to take control of it. It appeared the machine was infected with a virus." I am curious as to what in Stuxnet code and/or the client computer caused this. From the rest of the article, Stuxnet went to great lengths to stay undetected. Anyone has clues ?
- deleted 15y ago[deleted]
- nikcub 15y agomost worms have an 'installed' marker somewhere on the system. the loader will check the mark and if not present, will install and reboot. my sense is that the marker wasn't being set properly resulting in this bug. I had the same bug in a worm I wrote. I was storing the marker in the local user part of the registry, which was being loaded from the domain controller, so the bit wasn't being retained.
- deleted 15y ago[deleted]
- pnathan 15y agoThis is a particularly well-written article by Wired.
- cesar 15y agoThis is an extremely well put article. The series of events and the way that it was written kept me reading it to the end. It was a very interesting article.
- evilswan 15y agoHave to agree with other posters - Best article I've read on Stuxnet - good job.
- Amincd 15y agoIt's funny that the US is spending so many billions of dollars trying to sabotage Iran's economy and nuclear plant, when the country poses zero threat to the US, and the US faces enormous fiscal challenges. When I write funny, I mean utterly tragic, wasteful and a result of a relentless propaganda campaign which has resulted in every political candidate falling over themselves to prove how committed they are to facing down the menacing Iranian threat.
- Swannie 15y agoI enjoyed reading along about this on the Langner blog during late last year and early this year. He was often the first to break news about new understanding in the PLC related code, and at the time was given very little credit for it. Yet without him it would probably have taken a LOT longer to get to the bottom of this. If you want an example of an interesting post from his blog: http://www.langner.com/en/2011/02/22/intercept-infect-infiltrate/ http://www.langner.com/en/2011/02/22/intercept-infect-infilt... Here he talks about a nice attack vector, that seems obvious if you have access to bits of the postal infrastructure in Germany... And: http://www.langner.com/en/2010/11/15/417-attack-code-doing-the-man-in-the-middle-on-the-plc/ http://www.langner.com/en/2010/11/15/417-attack-code-doing-t... Here he talks about the man in the middle attack, which meant that the PLCs reported back correct frequency/speeds to the operators, whilst doing something nasty underneath. I'm waiting for a good book to come out that details all of the stuff in this attack. It's pretty stunning work.