7 ms·
Cyberattack in Venezuela demonstrated precision of U.S. capabilities
- sylware 9mo ago[flagged]
- fidotron 9mo agoThey can only do JS cyberattacks? Maybe they need to use RISC-V assembly ;).
- sylware 9mo agoNah, it is probably directly the xserver, or even the firmware of the display hardware block. An easy vector is the steam client or games. Hardware virtualization is amazing for complex malware/spyware. You would have to man-in-the-middle your network traffic then use a custom communication path to handle the correlation with your network usage with the right data probe added to the linux kernel ethernet driver. The problem: since I cannot remove the wifi hardware from my motherboard, all that is useless.
- zarflax 9mo agohttps://archive.is/rUYS4 https://archive.is/rUYS4
- flipped 9mo agoThird world countries lack the resources to secure their ICS and SCADA. Corrupted US govt doesn't even need NSA's capabilities for this.
- toomuchtodo 9mo agoChina should help them. Beijing tells Chinese firms to stop using US and Israeli cybersecurity software - https://news.ycombinator.com/item?id=46618949 https://news.ycombinator.com/item?id=46618949 - January 2026
- alephnerd 9mo agoIt's a performative announcement - most American and Israeli cybersecurity vendors either don't sell in China or white label a Chinese product for the Chinese market. I know 2 companies in that list that have done that very thing because otherwise it would have put their FedRAMP and CMMC pipelines at risk.
- trollbridge 9mo agoI worked at a place that faced exactly that. I initially was in the Huawei client engagement where they wanted copies of all of our source code. We said “no, nobody gets that”. They just keep asking over and over.
- bee_rider 9mo agoOn one hand, that seems like a sure way to get your product copied. On the other, they’d be totally nuts to run a cybersecurity product without the source code, right? Seems like a situation where getting the interests to align is just very difficult.
- trollbridge 9mo agoNo other customers demanded source code.
- barbazoo 9mo ago> In 2019, the Maduro government accused the United States of conducting a cyberattack on a hydropower plant that plunged much of the country into darkness for a week. > The power failures caused sporadic outbursts of looting and unrest, bringing the government close to collapse.
- bflesch 9mo agoLet's hope those chicken never come home to roost. NSA has a history of losing offensive cyber tools. IIRC both Texas and California had widespread power outages in the last few years. I am not convinced that US power grid is much better defended than the one in the EU.
- ericmay 9mo agoYes, you're missing that if you mess with the power grid the US will go and kinetically strike back (read: bomb your country) or attack you with its own cyber warfare capabilities, unlike the EU. That's why the EU is experiencing cyber attacks and cyber warfare with clear culpability from Russia, but is unable to do much about it besides give Ukraine more weapons. If Russia launched a cyber attack and shut down JFK the way it did Heathrow, the US would actually do something about it even with all the Trump is a Russian agent stuff aside.
- bflesch 9mo agoSounds too good to be true. I'd love to believe it. Didn't russia claim to have the full Epstein files, so how did they get them if not by hacking US government? Attribution of cyber attacks is extremely difficult, and US seems to notoriously under invest into infrastructure. Unlike other countries, most of the power grid is above ground. How can you be so sure that it is safe?
- ericmay 9mo ago> Unlike other countries, most of the power grid is above ground. How can you be so sure that it is safe? I didn't say it was safe by virtue of defensive capabilities, but it's safe by virtue of the US will very likely come bomb you or use its own cyber capabilities if you do something to the US. This is in contrast to the EU which was the comparison point, which is unable and unwilling to do much against cyber attacks.
- amadeuswoo 9mo agoStuxnet was 15 years ago. This isn’t crazy news, it’s just the first time it’s being reported openly
- nozzlegear 9mo agoI think I just got Mandela-Effected, I had to look this up. For some reason I thought Stuxnet was something that happened in the 90s, not late 2000s.
- bflesch 9mo agoIt happened to 90s systems which were used in the 2000s so you are still technically correct ;)
- ironyman 9mo agoBecause cyber is not a flashy capability like a new jet or missile but it's an area where the US has the clear edge: https://www.iiss.org/research-paper/2021/06/cyber-power---tier-one https://www.iiss.org/research-paper/2021/06/cyber-power---ti...
- 9mo ago
- msie 9mo agoIs the US attacking Russia and China and India as well because they’re the biggest threats?
- AnimalMuppet 9mo agoThe US is almost certainly ready to attack China, Russia, India, and every other country. Currently attacking? No, at least not on this scale. Also: Why is India on your list? "Biggest", certainly, but in what way are they a threat?
- joribu 9mo agoI read GP as a commentary of BRICS. There may/may not be interference there by the US and/or Five Eyes.
- bediger4000 9mo agoAlmost certainly not. The first impeachment trial revealed that Trump's foreign policy was for his personal benefit. It's pretty obvious Trump has figured out that nations, corporations and oligarchs will pay him for favors. I think the dots are connectable.
- Arun2009 9mo agoIndia has neither the ability nor the desire to attack the US. The very idea is silly. The country has its hands full enough coping with its state of quasi-chaos and belligerent nuclear-armed neighbors without taking on the worlds leading superpower for absolutely no reason at all.
- mosura 9mo ago> India has neither the ability nor the desire to attack the US. Extraordinarily wrong on the first part. Some countries have even outsourced some of their cyberattack capability to Indian companies in the past, and not for cost reasons.
- 9mo ago
- buildbot 9mo agoIt would be funny in this case if it was really just an open SCADA for their entire power grid that they clicked “off”, then “on”.
- yabones 9mo agoThe reality probably isn't far off... I know in the past the "breaches of critical infrastructure" breathlessly reported by the media have actually just been wide-open SNMPv2 services using the default community string. I'm sure something similar happened here. Turns out you can just connect to port 161, press "power off," and be reported in the news as an "advanced persistent threat actor"
- KaiserPro 9mo agoI work in electricity, it wouldn't be one, but yeah essentially it's probably an unpatched RDP/vnc/remote desktop exploit. Or the password is contraseña123
- bflesch 9mo agoI can see how a team of cyber bureaucrats is required to type in the fancy n you are using in your password. At least it is safe against brute forcing attempts with standard settings.
- robocat 9mo agoAnd remember that ñ on a traditional system is a single byte $F1, not one of those crazy kids-these-days multibyte codes like $C3 $B1
- qingcharles 9mo agoIs it that, or is it more likely they paid some anti-Maduro electric company worker to walk into HQ and shove a dongle in the back of a PC somewhere on their internal network, ala Stuxnet?