4 ms·
> The budget for something like this is probably in the tens of millions if not more. Absolutely. This was a massive defense spending project by any measure. H
by JakeSc 14y ago
> The budget for something like this is probably in the tens of millions if not more.
Absolutely. This was a massive defense spending project by any measure. How many people do you think worked on it? Assuming the project was highly compartmentalized, I would estimate that there are at least SIX subteams currently working on the next Stuxnet.
- 0-Day exploitation of PCs. How big is the team responsible for discovering / purchasing 0-day exploits?
- Hardware/firmware-level infection. This would require expert knowledge of the specific control systems.
- Networking / infrastructure. This requires an intimate knowledge of target network topology.
- Boots-on-the-ground payload delivery (nontechnical).
- Spear-phishing payload delivery. Perhaps the points of entry were several levels removed from the actual target facility (e.g., security guards' wives' laptops).
- Testing / QA.
All of this of course has to be backed up by world-class intelligence support, which I shan't address further. The technical feats of developing this alone are astounding and intriguing.
Holy shit.
- Mandatum 14y agoHere I am thinking it'd be cheaper to give a 5-million dollar duffel bag to some freelance Russians..
- daeken 14y ago> 0-Day exploitation of PCs. How big is the team responsible for discovering / purchasing 0-day exploits? Given the speculation that it was the US behind Stuxnet, this one is a cheap and easy one. The US has been buying up ready-made exploits for a good while now (there's a reason that the likes of Raytheon are hiring exploit devs left and right) and have nice stockpiles of them just ready and waiting for the likes of Stuxnet.
- contingencies 14y agoThis is definitely true.
- tptacek 14y agoThis is true because you heard it's true, or because you know it's true? Raytheon definitely has a lot of people on staff who are at least peripherally involved in vuln dev. That's not the same thing as having a staff full of exploit developers. You get peripheral involvement in vuln dev just by doing malware reversing, which is pretty low on the food chain, and something the government definitely (firsthand) spends money on.
- contingencies 14y agoAt least three different people I know are significantly involved in that area. You probably know some of them too. I detest them for the ethics of it, and keep my distance as a result, but there's no question what they do and where the money comes from.
- tptacek 14y agoAt least three different people you know work for Raytheon developing exploits?
- m0nastic 14y agoI can also confirm that Raytheon is building up this capability (although less so than Northrop and Lockheed). If you're curious what companies are actually committing to vulnerability dev you can search any cleared jobs site for "offensive"; the companies that have listings are who you'd imagine them to be (minus a couple placement firms that just put people right at the Fort).
- lawnchair_larry 14y agoPeople always forget about SAIC and General Dynamics AIS.
- deleted 14y ago[deleted]
- blacksmith_tb 14y agoBut that would still make it quite a bargain compared to buying physical weapons systems (not to mention the greater denyability / diplomatic two-steps it enables).
- waps 14y agoExactly "tens of millions" sounds like a lot, until you realize that's not that much. Most 50 employee companies could make an investment of 10 million if they really had to. What's going to happen when the first Chinese/North Korean/... company succeeds at actually doing this ? When will we have the first startup doing it ? Startups are known for creativity, both in technical development and interpretation of the law, so why not ? The cost for things like this needs to go up, by a lot, fast. Or we're going to be in a deep hole.
- sneak 14y agoIndeed. Stuxnet is clearly the hack of the century, so far.