7 ms·
Hackers Plundered Israeli Defense Firms that Built ‘Iron Dome’ Missile Defense
- caruana 12y agoIf defense firms are constantly under attack then maybe a good counter attack would be to embed exploits in documents that would "phone home" when opened outside the firms networks.
- tomp 12y agoI can't imagine hackers being as stupid as to allow scripts run in the documents. Actually, most modern software prevents such "phoning home" AFAIK (e.g. your mail client, Word, Excel, ... all ask you before loading remote images and executing scripts).
- chillacy 12y agoMaybe an encrypted document which phones home for the keys? And to force the user to run the script, make it so that the encrypted blob is generated by running the script (and it's painfully obfuscated to prevent reverse engineering)
- bhouston 12y agoOr that no one has local files, it is all served via virtual desktops to client machines.
- tomp 12y agoHow about just "an encrypted document"?!? Why would they share the keys?! Anyhow, no competent hacker would do that, and no hacker with a botnet would give themselves away even if they did that.
- adventured 12y agoKeep in mind that would not matter even if you could pull it off. Everyone already knows who the prime thieves of military / defense contractor technology are. Despite knowing that, nothing has ever been done about it. The routine will continue to be to 'fight back' with defense, because of the fear of overly angering China.
- opendais 12y agoThey'd open them inside VMs without networking. Try phoning home inside a setup like that setup by a professional hacker. ...ya I don't think you'll phone home either. You have to realize these hackers are people who have to deal with honeypots & law enforcement without getting infected/exposed/whatever. They are going to take some precautions if they are to be successful in the long run.
- refurb 12y agoUnfortunately I can't find it, but if you dig around the CIA FOID documents on their website, you'll find a story about the fake shuttle documents the CIA "allowed" the Soviets to steal. They knew the Soviets were digging around, so they created a honeypot with technical documents that were oh-so slightly changed, but would be non-functional. Too bad I can't find it, it was an interesting read.
- bhouston 12y agoChinese hackers have been incredibly good at infiltrating defense contractors around the world. This is just the latest in a very long list. These types of intrusions really do reduce any technical military advantages the "West" has over China.
- atmosx 12y agoYes. Apparently Chinese are awesome at getting caught too. Especially in cases where you can't prove anything. Weird that Americans never get caught, who knows. Maybe US doesn't do that sort of things.
- nitrogen 12y agoThe US/Israel did get caught with Stuxnet, so either they wanted to be found or they aren't perfect at hiding either. Note that I'm not making any comment on the ethics; I'm just mentioning evidence of the other side's activity.
- jsolson 12y agoWere they actually "caught", or was it simply determined that the level of sophistication was something that could only have come from state-sponsored malware (a claim I find dubious at best, but whatever)?
- kyboren 12y agohttp://www.theregister.co.uk/2013/07/08/snowden_us_israel_stuxnet/ http://www.theregister.co.uk/2013/07/08/snowden_us_israel_st...
- resu_nimda 12y agoI'm curious, why do you find that claim dubious? That is the conclusion of numerous top security experts, not just some pundits with an agenda. It seems like you're scoffing at the idea that only a national government could produce software that is "that good," or maybe even that they could at all, but mere code quality is not the whole basis for the claim. It's also the (initially) extremely precise target, the intelligence needed to affect the physical results they were after (disruption of uranium enrichment centrifuges), and the unprecedented effort to cover all tracks of the worm. Ralph Langner, whose team did a lot of the primary technical investigation into the worm, has said "the leading force behind Stuxnet is the cyber superpower – there is only one; and that's the United States." Here's his hour-long technical breakdown (with code): http://www.digitalbond.com/blog/2012/01/31/langners-stuxnet-deep-dive-s4-video/ http://www.digitalbond.com/blog/2012/01/31/langners-stuxnet-... His TED talk on Stuxnet: http://www.ted.com/talks/ralph_langner_cracking_stuxnet_a_21st_century_cyberweapon#t-11945 http://www.ted.com/talks/ralph_langner_cracking_stuxnet_a_21... A less technical article, which Schneier reposted as "the definitive analysis of Stuxnet [short version]": http://www.foreignpolicy.com/articles/2013/11/19/stuxnets_secret_twin_iran_nukes_cyber_attack?page=full http://www.foreignpolicy.com/articles/2013/11/19/stuxnets_se... There are also numerous bits of circumstantial evidence detailed on Wikipedia. A former Vice Chairman of the Joint Chiefs of Staff was put under investigation by the DoJ last year for allegedly leaking info on Stuxnet and "Operation Olympic Games." At this point it's all but certain, I think one would need a pretty good reason to be doubtful.
- atmosx 12y agoI love this: Five Chinese Military Hackers Charged with Cyber Espionage Against the US. Just 5? On the other side there's an entire entity known to spy/hack/attack virtually everyone.
- deleted 12y ago[deleted]
- salimmadjd 12y agoIf the hackers were after the Iron Dome, it looks like it doesn't work [1] based on analysis by Theodore Postol of MIT [2] 1: http://thebulletin.org/evidence-shows-iron-dome-not-working7318 http://thebulletin.org/evidence-shows-iron-dome-not-working7... 2: http://web.mit.edu/sts/people/postol.html http://web.mit.edu/sts/people/postol.html
- danielweber 12y agoI don't see Postol claiming that it doesn't work -- his report is full of theory but very low on numbers. Rather, it seems he is calling for the defenders of the system to provide verifiable numbers, such as "140 inbound targets were defended against, and here are the timestamps, and we intercepted 130 of them, given these timestamps," which could then be checked. Watching from the outside, I have no particular reason to believe one side or the other.
- bediger4000 12y agoPostol says maybe 5% of the Iron Dome rockets destroy their targets. A CNN page claimed 95%. This latest Krebs article has the IDF saying 20%. This whole argument smells like a modern military getting everybody to believe that "Iron Dome is 95% effective", just like everybody knows that the Patriot system was 95% or more effective during Desert Storm I. Or like everybody knows that WMD were found in Iraq after the USA invaded. That is, Iron Dome is more of a propaganda tool than a real defense system, or maybe its more of a way to funnel money to Rafael and IAI than a real defense system. I doubt we'll ever know. Statistically speaking, there's only a few real secrets, but there's lots and lots of career-ending blunders, accounting oddities, and systems gaming.
- wmil 12y agoHis analysis is flawed. For example, imagine if several rockets are fired at a hospital. Iron Dome intercepts the rockets, throwing them off course. The rockets then land in parks and parking lots, killing no one. Under Postol's standards, that's a complete failure. Because the warheads weren't destroyed. But most people would judge that as a major success. Assuming the rockets are reasonably accurate and targeted to do the most damage possible, simply damaging the rockets and changing their path is a success.
- trothamel 12y agoOne way of dealing with intrusions like this is to leak documents with subtle design flaws in them, rather than correct designs. If enough of the stolen material requires checks by skilled engineers before use, it dramatically reduces the value of the stolen material. (Of course, this requires the intrusion to be detected before it is over.) EDIT: See https://en.wikipedia.org/wiki/Siberian_pipeline_sabotage https://en.wikipedia.org/wiki/Siberian_pipeline_sabotage , with the caveat that it's not clear how real the story is.
- blisterpeanuts 12y agoNot a bad idea. Maybe they could name the flawed documents as "Blah Blah Blah [Final].doc" or "... [Corrected].doc" to throw them off the trail. Meanwhile, verbally inform internal staff to ignore anything with "final" in the title. It might cause some confusion from time to time, such as with new staff, and of course some dumb person will end up mentioning the practice in a document, thus blowing the secret. But it will still make the intruders' job harder.
- mortov 12y agoIt is standard practice in classified material communities to have carefully controlled variants of documents and a log of where and when the subtle variations go in order to detect and source leaks of information. When any particular area is detected as suspect, misinformation dressed up to look more valuable is then carefully spread in that direction to see who takes the bait. They are then either used to send misinformation or, if they have served their purpose or have nothing to offer, removed (fired/imprisoned or whatever is appropriate). The Americans (TV Series) had a couple of themes based around this - it's not exactly a secret strategy and receivers of information know to verify what they get before getting too excited. Since we're talking about government actors here, nowadays they would not be easily fooled and would have skilled engineers checking stuff no matter what, so that is not going to add any 'cost' to the operation. People in the espionage game learn pretty quickly or they don't get to play for very long.
- jokoon 12y agoI don't really know what use they have of such documents. I mean there aren't that many places in the world where you could sell that. I still wonder if any tech developed by iron dome is really useful at all for terrorits, Russia or china. I mean if hamas really has enough resource to build stealth rockets, or rockets than would be able to dodge iron dome, but I don't think they really have the resources to develop such thing.
- Kalium 12y agoThis is China, so they likely want to adapt and use the designs themselves.
- binarymax 12y agoOr china develops the tech, and gives it to those who would work to further disrupt the region? The question is - what does China gain from an even more chaotic middle east?
- yellowapple 12y agoPerhaps to throw a wrench into U.S. interests there? Being able to provide internal details of Israel's defense systems to anti-Israel factions would make U.S. intervention more necessary, allowing China a little more wiggle-room to do... something.
- XorNot 12y agoDefeating radar technology is still an uphill battle though. For a quick look at what you're dealing with, try Googling investigations on disrupting police radar guns (which is a very similar technology really as far as tracking radars for projectiles go). I've no doubt a state might be able to come up with a counter-measure based on this, but it would not at all be cheap or easy to implement (and Iron Dome doesn't work well enough to justify it in a normal war situation).
- tomjen3 12y agoMy guess is that China isn't particularly interested in the Iron Dome. Sounds more like the UAVs and they got Iron Dome by dragnet as a sort of added bonus.
- brandonmenc 12y agoIn light of all these "iron dome doesn't work" articles, this is some great propaganda (intentional or not) that the system is effective enough to be stolen and copied.
- BuildTheRobots 12y ago> "In light of all these "iron dome doesn't work" articles" I've not seen them; if you have links handy I'd like to go read some more. My understanding was that they were managing between 80-90% success rate for the targets they aimed for (which is pretty good) but also that they were deliberately leaving any rockets that were obviously not going to hit anything important.
- brandonmenc 12y agoYeah, that's my understanding too. https://www.google.com/search?q=postol+iron+dome https://www.google.com/search?q=postol+iron+dome "all these articles" = commentary on that one article by Postol.
- SEJeff 12y agoYou can argue that "Iron Dome is XXX%" effective all day, but it is a layer. Just like infosec, security is best in layers. That is why there are also things like the TROPHY system for Israel's Merkava tanks or lighter APC like vehicles: http://www.youtube.com/watch?v=4eCUCBS1SVk http://www.youtube.com/watch?v=4eCUCBS1SVk http://en.wikipedia.org/wiki/Trophy_(countermeasure) http://en.wikipedia.org/wiki/Trophy_(countermeasure) Israel is no stranger when it comes to rocket threats and has multiple countermeasures. So far, it seems to work pretty well overall when you look at the number of Israeli casualties due to incoming rocket fire. For the number of shots fired into the country, it is remarkably low even with the horrible accuracy of the rockets being fired.