Live data from Hacker News

German nuclear plant infected with computer viruses, operator says

reuters.com

91–100 of 101 posts

Re: German nuclear plant infected with computer viruses, operator says

#92
post #10

Possibly important to note the timing of this admission right on the heels of the announcement of our defense minister that she wants to build a 'cyber' division in the army with 13500 people working there. Thats almost 10% of our armed forces. I could only find decent reporting about this in german: http://www.tagesspiegel.de/politik/plaene-der-verteidigungsm...

Here in Germany that only means that 13000 people print out reports for the minister, while 500 people look at screens. 10 of them program the stuff that happens on the screens.

[deleted]

Re: German nuclear plant infected with computer viruses, operator says

#93
post #10

Possibly important to note the timing of this admission right on the heels of the announcement of our defense minister that she wants to build a 'cyber' division in the army with 13500 people working there. Thats almost 10% of our armed forces. I could only find decent reporting about this in german: http://www.tagesspiegel.de/politik/plaene-der-verteidigungsm...

These viruses are very serious and should be considered as a "near misses" in terms of critical power plant software malfunctioning.

After the US, Israel is #2 in Cyber security and is very dependent on Germany for military needs such as submarines and engines for their tanks. Since these nuclear power plants have nothing to do with national security directly, Germany should employ Israelis to help them if they have not already done so.

Re: German nuclear plant infected with computer viruses, operator says

#94
post #68

Earlier quoted context omitted.

I'm glad somebody joins them, though, or they would make up a law to legalize what drug cartels are doing with IT (and other) talent. Laws can be passed in parliament and be in use and need to go through trial at supreme court to be ruled invalid. I really wish passing laws was super had, super laborious, and took a very long time (at least 5 years). Then, the government, which needs to be reelected every 4 years, ca…

What are "drug cartels doing with IT talent"?

http://motherboard.vice.com/read/radio-silence

http://www.zdnet.com/article/it-myths-colombian-drugs-gangs-...

Re: German nuclear plant infected with computer viruses, operator says

#95
post #56
post #4

Earlier quoted context omitted.

The next sentence pretty much confirms my impression that this claim is almost certainly bullshit: > Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger. That's just...not how computers work.

See the recent BadUSB attack [1][2] for how this sort of attack can work; the firmware of the USB microcontroller itself can be infected. [1] https://srlabs.de/badusb/ [2] http://www.wired.com/2014/07/usb-security/

Can work is irrelevant. And mostly wrong, since can is not do.

They claim it is happening.

Re: German nuclear plant infected with computer viruses, operator says

#96
post #54

I wonder what scale of disaster will have to occur before information security is placed under the same legal and regulatory scrutiny as physical security?

Developing and maintaining software with a sufficiently large focus on information security will almost certainly cost so much money, that people will reconsider whether the investment is worth it. It probably takes several relatively large and frequent disasters not just to put the issue on the map politically but also to show that it's worth investing in information security besides the cost.

I think you're right, and I think it will have to take some obvious loss of life at least once.

Re: German nuclear plant infected with computer viruses, operator says

#97
post #8

Earlier quoted context omitted.

If behind the USB port is some (writeable) data storage (for PDF manuals etc) this is quite possible.

Or some infectable USB controller is involved.

What on here is able to store malware? https://learn.adafruit.com/minty-boost/parts-list

If the USB chargers in cockpits are any more complex than the above, why?

Re: German nuclear plant infected with computer viruses, operator says

#98
post #28

Earlier quoted context omitted.

Not at all, that's like saying floppy disk viruses happened because both PCs and floppy disks were vulnerable. Just imagine the cockpit to be a floppy disk. You plug your phone in, and your infected phone puts a file in the cockpit. Then someone with a vulnerable phone plugs into the cockpit, reads the file and is infected. Not saying that's how it happened, just that it's possible.

The hole in the argument is, why would the second phone read the file and execute it? We are waaaay past autorun.

Sadly, we're not: http://www.windows10update.com/2015/05/windows-10-tutorials-...

Re: German nuclear plant infected with computer viruses, operator says

#99
post #71
post #10

Possibly important to note the timing of this admission right on the heels of the announcement of our defense minister that she wants to build a 'cyber' division in the army with 13500 people working there. Thats almost 10% of our armed forces. I could only find decent reporting about this in german: http://www.tagesspiegel.de/politik/plaene-der-verteidigungsm...

That program is completely misguided. You don't need thousands of "cyber soldiers", just a few good computer scientists, mathematicians and engineers. Because a system built from trusted and provably correct components (hardware and software) is infinitely better than a swiss cheese with dozens of people attempting to keep it from falling apart. And from that point on, you only need to teach soldiers to operate their…

As someone who works in security operations, there is absolutely a need for people. Yes, a small number of experts could, given enough time, produce some small amount of thoroughly secure components. But that's not the situation we're facing.

In real life, governments are some of the largest enterprises that exist, and use the same software and systems as everyone else. Complete replacement with provably correct systems is such a large task that it would never be completed, for just the same reasons as in private industry. The attack surface of a government ranges from sophisticated military hardware to mobile apps.

Deterring, detecting, and remediating security incidents is thus done the same way the private sector does it: testing, continuous monitoring, hunting, forensics, etc. All of these activities are person-hour intensive, and I don't think there's a security operations center in the world that wouldn't tell you right now that they are limited by the size of their staff.

That said, full-service security departments will include technical auditing and software security components, and I suspect the German government intends to include this. Of course, these functions are quite limited by being on the client end of the relationship, as I doubt the German government produces any more of its software in-house than the US government does (which is not very much).

Re: German nuclear plant infected with computer viruses, operator says

#100

Earlier quoted context omitted.

Or some infectable USB controller is involved.

What on here is able to store malware? https://learn.adafruit.com/minty-boost/parts-list If the USB chargers in cockpits are any more complex than the above, why?

They almost certainly aren't USB chargers. Probably USB ports for inserting thumb drives to update the navigational charts. These kinds of USB ports are [mis]used for charging phones all the time, and the phone can end up being mounted as a mass-storage device.

No idea how the rest of the exploit would work in this scenario though, I have a hard time believing it.

Post reply on HN