Live data from Hacker News

CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

wikileaks.org

21–30 of 63 posts

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#21
post #12
post #5

On the face this seems ridiculous. It's a big stretch, but we do know that some US adversaries use portable media (usually thumb drives) to currior data. Maybe they had a target that was using floppies? Maybe Iran's centrifuges or N. Korea still uses really old tech?

It could be organizations in the US itself. I remember somewhere that the military was still requriing 3.5 floppies at least within the last 5 years. (no, I'm not talking about the nuke software that uses the bigger floppies)

Makes perfect sense to me. Why upgrade some critical piece of infrastructure if upgrading can only hurt you, but can never help you ? Assuming they didn't have ongoing problems such as bit-rot with floppies, why upgrade to USB ? There have been at least a few major attacks using either auto-run , auto-mount, or even infections in USB firmware over the years.

If you dont need the extra capacity or speed that USB or optical offers you, don't upgrade. I mean this specifically for infrastructure-size projects where the "thing" / entity that is controlled costs multiple orders of magnitude more than the computer system controlling it. Say I have a hydro-electric dam, or any kind of power plant (not just nuke), or train switch controller, submarine, aircraft carrier, etc. Stuff that can't break. Its just cheaper and safer to keep using the same tech, keep replacing known-working parts, than it is to risk updating the system to "stay current", and risk a costly outage (or some kind of catastrophe, even if theres only a 10^-7 chance of it happening). I dont blame them one bit.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#22
post #18

I don't understand why crypto doesn't help avoid detection? Imagine I have a usb thumb drive with gigabytes of mp3s on it, and I devise a way to embed and extract a floppy image into the mp3s (i.e. steganography), or perhaps family pictures. unless the images are viewed before and after, it can be difficult to determine what was stored or even if anything was stored. Of course, not impossible as their attacks that ca…

Steganography actually causes distortions that are noticeable. Unencripted data often has very odd patterns, encrypted data looks unusually random.

Probably was supposed to be steganography, since stenography is what courtroom reporters do.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#23

I imagine this is to target old manufacturing or scada equipment. If you want to sabotage an industrial target then you're going to be seeing a lot of legacy equipment. /r/sysadmin posts from manufacturing and industrial sysadmins are fascinating as they are scary. Also it may reveal that the target is using old methods for security purposes. Imagine an office where no one has any sort of user accessible networking (…

You could definitely put an RF tag on a floppy and then have detectors at all exits like a retail store does with merchandise. Hell, you could use a "mantrap" like banks do so that you automatically catch the person on their way out.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#24

I don't understand why crypto doesn't help avoid detection? Imagine I have a usb thumb drive with gigabytes of mp3s on it, and I devise a way to embed and extract a floppy image into the mp3s (i.e. steganography), or perhaps family pictures. unless the images are viewed before and after, it can be difficult to determine what was stored or even if anything was stored. Of course, not impossible as their attacks that ca…

The described use scenario is for smuggling the specified device in a secured environment where no electronic devices or storage devices are allowed, and passing through a physical search by masquerading the device as something innocuous i.e. "initial plan for concealment host is as a day planner". There's no intent to use steganography, random data (e.g. gigabytes of mp3 of family photos) should never be exiting the secure area in a legal manner, not even after a review; even if accidentally gets brought in, it's not getting out.

Bringing an USB thumb drive to such a place by itself would a serious incident, but might be treated (after a review) as a benign accident, but having a concealed device that can read floppies is another manner, it's obviously not a coincidence. Discovering that you ("the asset") have such a concealed device is by itself clearly sufficient for failing the mission and getting detained. It doesn't matter if it's "difficult to determine what was stored or even if anything was stored" - possession of the device and attempt to smuggle it to the secure area would be sufficient.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#25
post #5

On the face this seems ridiculous. It's a big stretch, but we do know that some US adversaries use portable media (usually thumb drives) to currior data. Maybe they had a target that was using floppies? Maybe Iran's centrifuges or N. Korea still uses really old tech?

Ancient technology is pervasive in established industries. Development and deployment costs (due to risk) are huge in this world. They don't have the staff to fix a glitch due to a docker migration or whatever, and frankly wouldn't see much benefit anyway. So they continue to use what works as long as they can. And if they have to pay $10 each for obsolete media and scrounge part bins for FDD replacements, so be it.

And the CIA's job is as much to spy on this world of established industrial capability as it is to hunt down laser-toting agents in the urban jungle of Beijing.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#26
post #6
post #2

This doesn't seem terribly surprising to me. There are still companies that use them, so if you need to spy on one, a device like this would be useful. The weirdest part is that the CIA uses agile-type user stories when developing its spy gear.

In fact, this is an excellent requirements document. Clear user stories with prioritization and notes. I also appreciate the Questions section at the bottom. Good requirements documents are a rare find in my experience.

Indeed, as a UX designer I would have loved having these types of requirements when starting a project. Especially with the "Must Have"/"Nice to Have" distinction which isn't always made clear when people are asking for an endless list of features.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#27
A 3.5" floppy copier concealed as a "day planner" and using systemd? Such spycraft in 2013 is hilarious to think about.

Especially thinking about some random corporate/government worker who got recruited as a source by the CIA and has 'unsupervised' access to some floppies.

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#28
post #16
post #8

Earlier quoted context omitted.

"Really old tech" is everywhere. For example Germany's high speed trains' reservation system runs on floppy disks.

...and if you're not careful when ordering Siemens Simatic software, the accompanying licence file arrives on a yellow 3,5" floppy. Don't ask me how I know. It took AGES to purge our ERP system of any reference to the Siemens item# which resulted in a floppy showing up. On the other hand, it resulted in some business for both DHL and whoever still manufactures floppy drives nowadays - service engineers opening a pack…

+1 for "3d-printed 'save' icon"!

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#29
Are there any devices (on the public market) that allow for high-density whole-disk imaging/scanning with one rotation of the floppy? Feels like it could be useful for bringing "dead" floppies back to life for e.g. retro computing enthusiasts.

Scan it once at insanely high resolution and later analyze the data...

Re: CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013

#30

Just to be clear, they actually made this. Not only that, but it appears like they had 3 different versions.[0] [0] https://wikileaks.org/ciav7p1/cms/page_1179700.html

It is also amazing that they were using RPI and Gumstix. Looks like rapid prototyping instead of custom miniature solutions, but if it works, why not...
Post reply on HN