20 ms·
US and Israel created Stuxnet, lost control of it
- derrida 14y agoAnonymous scooped everyone last year: http://crowdleaks.org/hbgary-wanted-to-suppress-stuxnet-research/ http://crowdleaks.org/hbgary-wanted-to-suppress-stuxnet-rese...
- ewillbefull 14y agoYou should actually read that link; the emails indicated HBGary were interested in using Stuxnet (probably the framework or exploits it used), but not that they had any idea who actually made Stuxnet. So no, Anonymous didn't "scoop" anything.
- derrida 14y agoAaron Barr talks to Defence Intelligence Agency and DoD about StuxNet in 2010, they had a copy given to them in 2009 that they claim was a US produced binary. Keep in mind stuxnet was 'discovered' in 2010. First reference to Stuxnet being U.S. government produced? You decide.
- slurgfest 14y ago"You decide" a convenient way to avoid providing evidence of strong claims while still making them? You decide.
- derrida 14y agoYes. Exactly, sorry, it's a lazy cliche, but I do think the evidence is there in the HB Gary emails that enables one to conclude beyond some reasonable level of doubt it was U.S. produced. However, the NY Times piece does provide evidence from the mouth of the source, and has far more detail.
- eli 14y agoThere were many previous references, but zero previous confirmations.
- eli 14y agoStuxnet was widely assumed to be a US and/or Israeli venture simply because those are the only countries with the apparent resources and motivation to pull it off. But this NYT story is indeed a scoop. It confirms that belief and provides quite a bit more detail.
- Fizzadar 14y agoThis feels similar to the Megaupload case; America desperately throwing its weight around outside it's borders, with a total disregard for the law. And, just like the Megaupload case, they have fucked up big time. Why does the American govt. feel it has the right to choose who can become a nuclear power or not anyway?
- xaa 14y agoThe original nytimes article implies that the U.S. started this program as a way to prevent Israel from responding in a military way to Iran's nuclear program. But yes, it certainly does seem that nary a geopolitical snafu goes by without the U.S. being involved.
- Cacti 14y agoThat's because you hear about the snafus, not the successes. There is much more incentive inkeeping the successes black, classified, and burried. Snafus are, almost by definition, just the things you hear about---otherwise, whos's to say?
- slurgfest 14y agoThe things you hear about aren't limited to snafus. They also include propaganda and mistakes. Blaming the US for essentially everything, with or without evidence, is a mainstay of many countries' politics.
- netcan 14y agoSome things are a question of right, some things are a question of need or interest. The US has enemies and it doesn't want them to have nuclear weapons.
- jacobr 14y agoIs there any proof that the facility in question deals with uranium enrichment for military purposes?
- ars 14y agoarstechnica is taking the NY Times article and extrapolating too much. Confirmed? No it's not. It was suspected before, and it still is. And lost control would imply they could not control what it did to the target, which is incorrect. It did escape to the wild, but that's not really loosing control when it was designed to do nothing harmful on non target machines. Better to read the original, and the discussion on it: http://news.ycombinator.com/item?id=4052330 http://news.ycombinator.com/item?id=4052330
- forza 14y agoIt got discovered, I would call that loosing control.
- zxcvb 14y agoYou're wrong. You can still be in control of a botnet (for example) even if it gets discovered and you can't spell 'losing'.
- forza 14y agoAnd you don't understand the different meanings of control. Controlling as in "issuing commands" is different from controlling an event. As far as I know there were no actual commands being given to Stuxnet. It was made for private networks how could there be?
- abrahamsen 14y agoUnless David E. Sanger is a new Jayson Blair, I'd say the connection is confirmed, not just suspected. There are no weasel words in the article, meaning both the journalist, his editor, and NYT are putting their reputation at stake. This is as strong as a newspaper story gets.
- slurgfest 14y agoIs it really true that "someone published in a newspaper said so, therefore we can rely on its being true"? I don't think so. Hard data, credible sources are what make a strong newspaper story - not a convenient message from someone who would be embarrassed if the story were untrue (something which is at least as hard to disprove in this case as it is to actually prove)
- antonioevans 14y agoIf Israel had physically bombed the Iranian plant would that not started another major war in the Middle East? I am not saying this is an elegant solution to cross border conflict but war was avoided. Everyone in the hacker community knows this was coming. This is going to get much worst before it gets better. Power outages in Brazil, China/Google event last year, and stuxnet. As the article says: "Stuxnet is old news by now. Even the newly discovered "Flame" malware was developed some time ago. While details about these two targeted attack packages are finally emerging, the next generation of attack tools has no doubt been developed and likely deployed."
- tzs 14y ago> If Israel had physically bombed the Iranian plant would that not started another major war in the Middle East? Who would be the combatants? One of the few actually interesting things that came out of the leaked diplomatic cables was that many of the major Middle East countries want Iran's nuclear program stopped, with Saudi Arabia actually repeatedly urging the US to attack. In light of that, I'd expect that if Israel attacked it would be publicly condemned by the rest of the Middle East countries, but most would secretly be relieved.
- brown9-2 14y agoIran and Israel have probably the largest militaries in the region, so if Iran responded to Israel's attack things could escalate into a shooting war quickly.
- antonioevans 14y agoIran (and a few other countries we know) is historically known for fighting war by proxy. Suicide bomber here, assassination there, dollars flowing to multiple heavily armed anti-Israel groups. Also on top of this what would be Russia + China's reaction be to a physical attack on one of their allies. Heck what would be the price of oil? $150 a barrel?
- jgrahamc 14y agoIt's amusing that they 'lost control' of it because a simple bit of code along the lines of "if www.google.com resolves then shutdown" would be effective at detecting whether it was on the Internet or not.
- elithrar 14y ago> It's amusing that they 'lost control' of it because a simple bit of code along the lines of "if www.google.com resolves then shutdown" would be effective at detecting whether it was on the Internet or not. Not really. The code would need to rely on or implement additional network (or DNS) code, and then also make a network connection; making it much more easily traced. Either way, I think the "lost control" headline here is a bit much. Stuxnet, from the analysis performed, was harmless beyond the target network.
- ajuc 14y agoSuch mechanism would make it very easy for Iranians to defeat the purpose of this program.
- zxcvb 14y agoWhat if google.com isn't resolvable from the host? The quality of person on HN has gone down hill.
- forza 14y agoYou might want to have a look at your own comment history...
- forgotusername 14y agoFrom the NYT article: > American, European and Israeli officials involved in the program, as well as a range of outside experts. None would allow their names to be used because the effort remains highly classified, and parts of it continue to this day. Convenient. Not only was the reporter able to secure one reliable, anonymous, highly privileged source to confirm the story, but he found multiple!
- eli 14y agoThe NYT would almost certainly not have run the story with a single source backing it up.
- forgotusername 14y agoThere is too much wishful thinking going on around Stuxnet, both on the part of the security industry and the general public who'd rather believe their own country originated it. If you were a world super power, wouldn't it be in your interests to claim responsibility for a first of its kind, extremely high tech attack? I believe any government wouldn't mind this kind of attribution. I'll wait my 50 years or whatever for the relevant documents to be declassified, in the meantime this is all just drama and guesswork, no matter how many anonymous, totally reliable sources crawl out of the woodwork.
- eli 14y agoDid you read the NYT article? I found it to be pretty convincing. Who do you suggest as an alternate culprit?
- sigzero 14y agoIt makes it more plausible that way. ;)
- voodoochilo 14y agoif this info is correct then it's an outrage. control lost or not.
- Morg 14y agoHIV (just to be clear, I have no clue wether HIV was assisted by some military programmes, but I can safely say such "mistakes" have been made in the past by the same army, like when they used to test nukes for example) Luckily this time it's a simple pc virus we can easily disassemble and counter - I think cyber war's still miles better than the alternatives.
- dpark 14y agoNo, you can't "safely" say that. You've no evidence that the US military has ever been involved in creating a wide-scale biological pandemic. This is just conspiracy theory bunk. I'm not sure how you can reasonably compare testing nuclear weapons to the supposed propagation of HIV, either. These two things have nothing in common.
- Morg 14y agoAlright, you want details ? During the testing of nuclear weapons, the US had no problem testing the secondary effects of nukes through radiation far beyond the blast zone, by putting boats with soldiers to watch the thing. It was widely known at that time that radiation was bad for you mkay, and that nuclear fission bombs were nuclear fission bombs, i.e. accelerated nuclear degradation bombs and drained all their explosive power from radiations, that kill mkay. In the past, biological, chemical, explosive weapons were tested on rocks, plants, prisoners, personnel, unsuspecting local populations, etc. by the nazi regime, the US govt, the USSR and France - that are widely confirmed. I wouldn't put it past THOSE people to do such a thing, would you ? So really, if you want to say it's IMPOSSIBLE or UNLIKELY that they would've done that too, without knowing the consequences - I suppose you must be right.
- Symmetry 14y agoYes, the US has done bad things, and AIDS is a bad thing, but it doesn't follow that the US caused AIDS. After all, nature has had no trouble creating pandemics without any deliberate human help over the centuries.
- ck2 14y agoIt's a new cold war. Eventually Iran will write viruses in return to attack US power grid. All fun and games until Homeland Security Theater is given new powers to raid your home and shoot your dog if they think your computer is being used as part of a botnet.
- hieronymusN 14y agoThis isn't nearly as terrifying as the Cold War with the USSR. We're not threatened with nuclear war, nor having the near misses that could trigger it (Cuban missile crisis). No one is building bomb shelters in their backyards, because right now the balance of power is very much in the United States' favor. Could things get there with another nuclear enabled power like China? Maybe, in time. Iran is not an existential threat to the US, not anywhere close to what the Soviets were. The Israelis see things differently I'm sure, but this is far from the situation in 60s - 80s.
- ck2 14y agoJust like the TSA it's our government that is far more terrifying than any imaginary threat they are supposedly protecting us against. And don't underestimate the Iranian government, they are not a third-world country like some people imagine out of ignorance - I really feel sorry for the Iranian people getting caught up in this mess.
- davidw 14y ago> imaginary threat Err... while I'm not stepping in to defend the TSA, I think that to call the threat imaginary ignores recent history.
- fghh45sdfhr3 14y agoThe threat is absolutely imaginary. Obviously we have real threats, but that is NOT what the security theater is about. The security theater is mostly about purely imaginary threats. And is in fact worse at stopping the few real threats we have. Original security theater idea is from Bruce Schneier, Wikipedia link: http://en.wikipedia.org/wiki/Security_theater http://en.wikipedia.org/wiki/Security_theater
- ascendant 14y agoI'm going to take the contrarian view here. If Iran had gotten to the point of enriching uranium to weapons-grade levels and Israel had done a pre-emptive strike, that would have gotten messy real fast. More messy than this. Disabling their centrifuges in a way where presumably no one died doesn't sound so bad to me considering the alternative. Again, just the contrarian viewpoint.
- eli 14y agoI don't think that's contrarian. If your choices are between allowing Israel to start a new war in the middle east, or work with Israel on this risky new cyberweapon, I think most people would pick the cyberweapon.
- moron 14y agoJudging by what I've read, this is far from contrarian.
- bilbo0s 14y agoWhat concerns me is the lack of evidence that all of their centrifuges were actually knocked. At the start of this they were enriching to 5%, now they are at 20%. That indicates to me that they have been progressing, not repairing knocked centrifuges. I realize it is still a LONG way from where they need to be for a workable weapon. I'm just wondering if stuxnet did nothing but a tiny bit of damage and a whole lot of 'show our hand'. A little like the whole drone debacle.
- tomjen3 14y agoThats is because Obama is a pussy. He doesn't have the guts to put Osamas head on a stake, dipped in pigfat, and he doesn't have the guts to tell Israel no. Just remind them that we are the reason you exist and we can and will withdraw that support when we want to.
- nicholassmith 14y agoYou know what's most surprising about this? That the developers, knowing fine well it was for a single target and the damage it could do in the wild, didn't implement a kill switch. Quite frankly cowboy coding like that is why we'll end up with Skynet becoming self-aware.
- 46Bit 14y agoHow do you put a kill switch in? The entire point was for it to be on an offline system, and the traffic for it checking for Internet to in turn check for an order like that might have given the game away. It sounds like they had something to check it wasn't outside and someone just screwed up.
- nicholassmith 14y agoYou engineer a solution. Quite frankly if you can't think of how to put a kill switch into something like this then it shouldn't be getting written or allowed into the wild. You can't add that to Bugzilla and hope to fix it later.
- wpietri 14y agoI think the obvious thing would be to look for Internet activity on the machine. E.g., recent files for popular sites in a browser cache directory. Or live network traffic for public netblocks.
- Symmetry 14y agoBut it has to start out on machines connected to the public internet before spreading to the secret facility via USB drive. If it didn't spread when connected to the Internet, it wouldn't work. And it already doesn't blow up centrifuges when it's not on the target network.
- MartinCron 14y agoit already doesn't blow up centrifuges when it's not on the target network I can verify that. None of my centrifuges have been blown up.
- bobsy 14y agoWasn't the US all up in arms about how China was increasingly using cyber-warfare on both foreign government and corporate interests? Then it turns out they are doing it themselves? Tut Tut. Though not really surprising. I do feel though that with the success that lolsec had last year very few companies / governments are prepared against a concerted attempt to access their data.
- mtgx 14y agoThis doesn't seem to be a very good day for the US Government: http://www.reuters.com/article/2012/06/01/us-china-usa-espionage-idUSBRE8500IH20120601 http://www.reuters.com/article/2012/06/01/us-china-usa-espio...
- philiphodgen 14y agoThe fact that the NYT published this piece is interesting. Assume all details are true. Why did the dog bark rather than choose to be silent? And the sources. Assume all of this is true? Why feed the info to the NYT? When coupled with recent revelations that Mr. Obama personally approves every killing of militants (for certain strained definitions of that term), the upcoming election springs to mind as a motivation. There may be alternate and contradictory reasons, all of which may be true. Many players, cross-purposes. This could have remained hidden. Indeterminate. Who benefits from this revelation?
- elarkin 14y agoLikely the person(s) who spoke out now feel a burden lifted from their conscience. If the information is true, it surprises me that it has stayed hidden for so long.
- deleted 14y ago[deleted]
- deleted 14y ago[deleted]
- dantheman 14y agoThis is the standard practice of the Obama administration - prosecute only those who leaks don't help the president. Glenn Greenwald at salon.com has been writing about this a lot, here's his piece about stuxnet: http://www.salon.com/2012/06/01/tough_guy_leaking/singleton/ http://www.salon.com/2012/06/01/tough_guy_leaking/singleton/
- ruttingchimpanz 14y agoFormer election strategist here. This is part of the Obama-Is-Tough roll-out, clearly done with current admin participation. Timed release to follow the "kill list" story and maybe even pre-empt the terrible jobs report. All the same, it's pretty stunning that the Obama administration would trade its (public) plausible deniability on Stuxnet in order to "look tough" on America's enemies. Playing fast and loose with foreign policy...great plan, guys.
- dantheman 14y agoHow is this not an act of war? Doesn't congress need approve military actions of this sort?
- Symmetry 14y agoNo, the president would need Congressional approval to have military units in Iran for more than 90 days. In practice presidents almost always ask Congress for advance approval, since having to pull out in the middle of an invasion would be rather embarrassing. The only exception that comes to mind is Reagan's invasion of Grenada, where the US military was in and out easily under the time limit.
- discordance 14y agowow... the turn around on confirmation of conspiracy theories these days is a year, rather than the decades of past.
- alan_cx 14y agoPeople, it is said, do "stupid" things on the internet in the belief that they will remain anonymous. Have the US and Israeli governments made the same mistake?
- gavinlynch 14y agoConsidering that Iran is very well aware the US and Israel have a vested interest in dismantling their nuclear programs and that both countries are using cyber warfare to achieve their goals... Why would the US care if they remain anonymous? Do you considering setting back the Iranian nuclear program a "stupid thing someone did on the internet"?
- guelo 14y agoIf the UN security council was a fair body Stuxnet would be judged to be an unprovoked act of war and the US and Israel would be sanctioned in some way. But of course the US gets to have it's thumbs on the UNSC scales. But the question is, if the US is going to blatantly abuse its privileged position like this how long is it going to last? There has been a Western consensus on a liberal framework for international law going back to WWII which was based on the idea that we are the good guys, democratic, moral, law abiding, etc. GWBush and Obama have been doing their best to destroy that because of lobbying by our war mongering Israeli "friends".
- gcb 14y agoMilitary power is a requirement for international politics. Do you think counties summit to laws because of what? If no one can over power then, they have to abide to no law. UNis just to cut costs for the dominating military powers. Want something done? It costs less to send some talker to tell about the power you can mobilize than to mobilize that power at once.
- guelo 14y agoThat's a very cynical point of view that was the cause of much death before the creation of the UN. There used to be this ideal about what the UN meant including respect for international laws. How can we credibly complain that Iran is violating a UN resolution at this point? If we're moving back to a might-makes-right world we are doomed to a future of new world wars and untold carnage.
- gavinlynch 14y ago"If we're moving back to a might-makes-right world we are doomed to a future of new world wars and untold carnage." In my view, we never left a "might-makes-right world". It's the underlying reality of human existence and human nature. And yes, that absolutely does mean that our future holds new world wars and untold carnage. Is it a particularly happy thought? No, not really. But it's part of the human experience.
- azernik 14y agoSecurity lesson from the article: "It turns out there is always an idiot around who doesn’t think much about the thumb drive in their hand."
- bitwize 14y agoWas true before thumb drives. Fun fact: President Carter once sent his suit to the dry cleaner's -- with the nuclear launch codes in the pocket.
- jackpirate 14y agoMore fun fact: nuclear launch codes meant nothing in Carter's time. There was literally a group of Admirals/Generals who were physically capable of pressing the button at any time without presidential authorization.
- dpeck 14y agoIt is anything but confirmed. Arstechnica writes an article about an article in the NYT (a paper that doesn't have the best track record reporting about cyber events and control system security issues to begin with) that cites no credible sources. Also, you don't "lose control" of something like this, it was designed with many ways to spread. If control was lost it was during the spec/coding phase, not after deployment.
- gavinlynch 14y agoThe sources aren't named, but it would be a pretty major, major slip-up to specifically claim to site NSA advisers if it were made up out of whole cloth. As in, career ending for the writer. For example, "...according to members of the president’s national security team who were in the room." Journalists don't drop phrases like that lightly, and you don't have access to several NSA members and high-ranking US officials unless this leak is 100% sponsored by the Administration. It clearly was: one can tell by the quantity and range of officials that were interviewed who demonstrate, at points, first-hand knowledge of the situation. Now, the question of whether these NSA advisers are -lying- as part of a propaganda campaign is a fair question. I wouldn't be shocked if they were, but everything that I have anecdotally read about Stuxnet and just using common sense, tells me--a layman on the outside looking in--that there is a pretty decent probability this is true, or at least pretty close to the truth. Clearly, the timing of this is politically relevant. The President wants to take credit for it to boost his domestic stock in the runup to the election. He can repeat these two key points whenever he is questioned on foreign policy: 1) I killed Bin Laden 2) I'm the guy who set the maniacal Ahmadinejad's nuclear ambitions back. The guy who is preventing the destruction of Israel. Regardless of your political persuasion, these are potent points that have a chance to resonate with the electorate. (fwiw: I'm not particularly in love with the NYTimes. I don't have an affinity for any particular newspaper anymore. I'm not defending the newspaper, just pointing out the likely reality as I understand it)
- tptacek 14y agoWhen the New York Times prints: “Should we shut this thing down?” Mr. Obama asked, according to members of the president’s national security team who were in the room. It is generally safe to assume, whether you admire the NYT (like me) or don't (like 'patio11), that there's an actual source with a credible claim to have been in the room with the President who did in fact tell David E. Sanger that this happened. People have accused the NYT of bending the truth in lots of ways, but misreporting a White House meeting is not one of those ways. I'm annoyed to have to write this, because I'm one of the people who thought the Stuxnet thing was marvelously overhyped and unlikely to be true. Friends of mine who are much smarter than me thought the worm might have just been a cover for direct sabotage. Nope; it seems like the government was exactly as simultaneously savvy and idiotic as online pundits had claimed it was. Depressing.
- strags 14y ago"[Obama] repeatedly expressed concerns that any American acknowledgment that it was using cyberweapons—even under the most careful and limited circumstances—could enable other countries, terrorists or hackers to justify their own attacks. “We discussed the irony, more than once,” one of his aides said." "Irony" is the wrong word. It's "hypocrisy".
- freshhawk 14y agoNot when you honestly believe in American Exceptionalism
- rbanffy 14y agoCountries or terrorist groups rarely justify military action (even if it's cyberwarfare). At best, they explain it.
- philwelch 14y agoOn the contrary--they often go to great lengths to justify it. The German invasions of Denmark, Norway, Belgium, and the Netherlands were deemed protective occupations, in order to prevent the Allies from invading them. The Gulf War was justified by a UN resolution. You can find some attempt, however feeble, to justify any recent military action.
- rbanffy 14y agoThat's the point. Each and every military action creates an attempt to justify it. It usually fails at both justifying it and explaining the actual reasons behind it.
- waqf 14y agoOn the contrary, hypocrisy is all about believing that "when I do it it's not wrong". Decrying something when you are ashamed that you secretly do it yourself is not hypocrisy, because it doesn't involve a double standard.
- 14y ago
- gavinlynch 14y agoThe one part of the article that sticks out to me is that they "lost control" of the virus. I wonder if this is really true. Politically, it probably sounds better to say, "oops, this was only meant for Iran. Somebody messed up" than to have to field questions from reporters: "Why does the United States think it is okay to infect hundreds of thousands of computers with this virus?" "Is it ethical to introduce security holes or exploit security holes of everyday citizens of allies?" "Do you take responsibility for the collateral damage? Have you committed an act of aggression on nation-states you are not in conflict with? How does that affect your relations with these nations?" I wonder if this is their easy way to set themselves up to say, "This is complicated technology, our primary goal is to stop a dangerous nation from getting a dangerous weapon. We apologize for any collateral." even if that statement was false. Perhaps it was necessary for the virus to spread to ensure the success of the mission and that cost was accepted, but they just don't want to admit it publically because of what it would open themselves up to.
- lawnchair_larry 14y agoThis is a good point. Being somewhat familiar with the code, but not enough to call this a provable lie, there is nothing I'm aware of that really fits this statement. No "error" that caused it to "leak". I don't think they wanted it to leak, but the design of it could only constrain it so much. It was intentionally designed to infect other computers in order to reach its target. The other part that makes no sense to me is the bit about the "beacon" that would deliver info back to them over an air gap network. This is rather confusing and inconsistent with what has been seen from it, but it's not impossible. But of course these statements went through several non-technical people and were written for a non-technical audience, so they might be based on something accurate and just sound funny.
- elorant 14y agoSo let me get this straight, they lost control of it and it ended up inside an Iranian power plant? You can't lose control of something so specifically tailored. The possible targets of this thing could be a few hundred installations around the globe so the motivation of stealing it, if it's even remotely possible to steal something like that, should be very low.
- shriphani 14y agoPossibly relevant : Bruce Dang on stuxnet http://www.youtube.com/watch?v=rOwMW6agpTI http://www.youtube.com/watch?v=rOwMW6agpTI
- mthreat 14y agoThey should have read about the Internet Worm of 1988 - http://en.wikipedia.org/wiki/Morris_worm http://en.wikipedia.org/wiki/Morris_worm Those who don't know history are bound to repeat it?
- domwood 14y agoThe fact that one of the most powerful nations in the world not only created one of the most notorious viruses in the world but lost control of it is madness. Its original purpose was to cause hardware to physically destroy itself. Imagine if, by sheer coincidence, the commands for that were the same as the commands for something like a nuclear reactor's cooling turbines? It's incredibly improbable but not impossible. That makes this a hugely dangerous and downright stupid occurrence. America shouts at Pakistan for losing control of its nukes and then develops, with a country that has some reputation for overkill (Israeli invasion of Gaza being a prime example), a dangerous weapon in software form, then doesn't pay attention to what the thing actually does? Where's the review process? How does something like the software being modified so it can infect and spread on common consumer systems so rapidly (I'm assuming that the modifications were to the way it spread, not sure) get missed? It's crass carelessness. International espionage is half offence and half tact. It's not espionage if everyone finds out about it.
- lstroud 14y agoThe truth is, if you love the Internet you had better start fighting to stop these escalations. Otherwise, it will cease to exist. The first time a massive attack causes real fear in western civilization, people will start questioning how much they really need it in their lives. The lack of plausible deniability will lead to escalation. Once it does, national security (from the perspective of each country) will govern it's growth, not freedom.