4 ms·
24,000 Pentagon Files Stolen in Cyberattack
- ck2 15y agoI don't understand why it's not a crime to have sensitive information on computers attached to the internet (or having usb ports for that matter). Imagine if nuclear silos were built today and powered by Windows and attached to the internet - insane, right? Well at what level is anything else that would cause headlines if hacked, okay to be attached to the internet?
- cryptoz 15y ago> Imagine if nuclear silos were built today and powered by Windows and attached to the internet - insane, right? As Stuxnet shows, it doesn't really matter if the machines running Windows are connected to the internet or not. They'll be compromised one way or another if someone wants to badly enough.
- ck2 15y agoThose had usb ports and were compromised by thumb drives. Government spec motherboards shouldn't even have usb headers. Sure it's possible to program a mouse or keyboard to inject code but way way way more difficult than a thumb drive or internet connected PC.
- dexen 15y ago> Government spec motherboards shouldn't even have usb headers. The first military to try to order such custom, extremely expensive (no alternative market for it!) gear will be flogged and quartered alive by the press. For spending 10 or 100 times as much as CotS hardware would cost. Good luck finding a soldier brave enough to risk his career and family's income for mere USB ports.
- pak 15y agoWhy not just order regular boards, cut the USB headers off with wire cutters and fill the ports with epoxy? That should prevent any casual thumbdrive usage. The only hangup I see with that is that most boards don't have PS/2 anymore and you might need to connect a keyboard/mouse. To solve that you might need to epoxy a wireless transmitter into one of the ports and pair it with mice/keyboards as needed. But for situations where wireless devices are not allowable, I can't see any cheap solution short of soldering the USB wires to the motherboard. Damn USB for being so... universal.
- sorbus 15y agoEpoxy the wires you absolutely need into place, fill the rest of the ports with epoxy, and put the computer in a locked metal box, with only the power button revealed. If someone is so committed to getting access that they would try to strip the wires apart to connect a USB drive through them, then search everyone for USB drives before they enter and check the state of the wires (and metal box) before they're allowed to leave. Or just throw some software at it so that a very, very loud alarm goes off if a new drive is mounted or detected, search people for USB devices before they enter, and keep regular backups (if you make it impossible to get data out undetected, the only thing you could do with software on a USB drive is corrupt or delete data).
- thret 15y agoI don't see why a special spec would be necessary, you could just physically disable the usb drive.
- deleted 15y ago[deleted]
- dexen 15y ago> I don't understand why it's not a crime to have sensitive information on [[vulnerable]] computers (...) Easiest question under the Sun: it's legal and considered perfectly OK because the software, network gear and configuration comes with the right documents. As long as the documents say the right procedures were applied during development and deployment, it's considered OK. What do you expect, particular software and network gear being declared too vulnerable merely because everybody with relevant experience know and have experienced how vulnerable it is? Bureaucracies don't work that way; never did and probably never will. We may want to have a way to counter such useless documents to make our countries' infrastructure safer, but that's not the easiest quest under the Sun anymore...
- rdtsc 15y agoGood insight. A lot of security breach management just involves having someone else to point a finger too. It is about hiring contractors that have paper credentials and then when shit hits the fan they can point to them and say "look we hired the best, if they can't do it, nobody can." In the government world is it about passing the security script test, having the right stamps on your cerificates that consist of random 4 letter words.
- asciilifeform 15y ago> Imagine if nuclear silos were built today and powered by Windows and attached to the internet - insane, right? You are in for some surprises: http://www.wired.com/science/discoveries/news/1998/07/13987 http://www.wired.com/science/discoveries/news/1998/07/13987 The US military-industrial complex isn't really there for national defense, or even for the conquest of weaker nations. Rather, it is a massive wealth transfer scheme. Microsoft fits right in.
- dexen 15y agohttp://www.theregister.co.uk/2008/12/16/windows_for_submarines_rollout/ http://www.theregister.co.uk/2008/12/16/windows_for_submarin... Blighty's nuclear-missile-equipped submarines, now running MS Windows. BSOD anybody?
- ck2 15y agoAfter I read that I was hoping to discover the post date was April 1st - that is really scary stuff.
- timjahn 15y agoI'm confused what this has to do with Mashable. They truly do just report on anything that will gather page views at this point, don't they?
- zrail 15y agoOT: Is the Pentagon the only major group to have unironically adopted the words "cyberspace" and "cyberattack"? Because I don't see anyone else using them in 2011.
- DanHulton 15y agoThey also don't disclose how the files were stolen - SQL injection? Social engineering? Compromised email account? I mean, obviously they don't want to draw specific attention to what methods were effective to sneak into the freakin' military, but I suspect it was something simple like that. It seems to always be the case these days. It interests me though, because I just launched a startup to help mitigate broken-into email accounts: http://www.emailambush.com/ http://www.emailambush.com/ I wonder if it WAS a hacked email account, with someone just sitting there, slurping down emailed Word and Excel files. Further, I wonder how the heck I'd even begin to approach them about my service, should that turn out to be the case. I've never dealt with large-scale procurement-style folks before.
- mathiasben 15y agoAny word on who the contractor was? Coming on the heels of the Booz Allen & Hamilton break in, this has been a bad week for infosec in the MIC.