Live data from Hacker News

Hackers set off Dallas’ 156 emergency sirens over a dozen times

arstechnica.com

11–20 of 52 posts

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#12
post #7

I was in Dallas when this happened. I can attest to the eeriness of sirens going off all over town with no idea what they mean. In Texas we're accustomed to tornado sirens, but when the skies are clear and they are going off, makes you wonder what might be happening - especially when it lasts for over an hour. But what really struck me was how much we expect instant information these days. Took over 30 minutes to fig…

Part of me suspects that there might be something in this related to current events. If I were to spitball ideas about motives and modus operandi, it feels like the kind of thing a state actor would tamper with, and in terms of style I'd gravitate toward looking in North Korea's direction, since it feels like their style.

Why do it? Raising noise with false alarms, desensitizes the intended signal of an alarm, ruining signal-to-noise, as people slack off about responding to alerts. It also serves as a probe to see what an actual outcome would look like. There's no profit (no money), and no incentive to whip emergency responders up into a confused state, for most non-state actors.

Even SWATTING is usually more targeted, with the prank being played on a specific person. Sometimes SWATTING serves to distract the target from something under their control. That doesn't seem to be present here.

North Korea's hacks usually come across as sort of impish in a lot of ways. They seem to like the attention of getting into the news. Messing with something reminiscent of air raid warnings seems to fit the personality of their general profile, given their ballistic missile ambitions. Other state actors in the news lately, probably wouldn't be as interested in domestic civil defense systems in the U.S.

They (whomsoever is responsible) might be motivated to do something like this (if it were a North Korean team) given some of the sabre rattling going around this season. It rings of something that would score points with Dear Leader.

But then again, yeah, maybe this is just the typical sort of "because it's there" hack, and some script kiddie found his way into another cookie jar.

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#14

When I helped run a college radio station as a student, one if the things I had to check on was the Emergency Alert System (EAS). It's the system that cuts into your broadcast and allows emergency personnel to transmit information over TV and radio. Maybe it was specific to our setup, but our station was assigned two other stations to listen to for EAS alert tones. If the box heard the tones it would flip a relay and…

Most stations have that device configured to only automatically take over air for the most egregious emergencies, with the rest aired on a discretionary basis. You generally only see full auto relays with full auto stations; pretty much every station with a butt in the big seat is wired discretionary, with individual station policy regarding which alerts to rebroadcast. I wouldn't generally retransmit a severe thunderstorm warning, for example, though I repeated every test. To my knowledge, only a Presidential Activation of EAS bypasses everything, and by law there's a book next to every eligible transmitter that describes the procedure for that (it's a bit unique).

For those who don't know, the tones -- which are indeed received from well-known designated primary stations -- come with a textual representation of the bad news, which is printed out on a little receipt-size slip from a box called a EAS-911 (a few vendors make them). One of two things happen next: either the EAS-911 takes over air automatically and rebroadcasts the bad news as it is received, or it is recorded instead and a little button begins blinking to indicate that the device is waiting for you to give it permission to take over air and rebroadcast the bad news. Pretty much everyone with resources is set up the latter way, partially for the very reason mentioned.

The real ugly scenario with the automatic relay stations is when the primary forgets the "I'm done" tones, and then every station in the state plays WGN for an hour. That's happened before. Fines have been levied.

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#15
post #7

I was in Dallas when this happened. I can attest to the eeriness of sirens going off all over town with no idea what they mean. In Texas we're accustomed to tornado sirens, but when the skies are clear and they are going off, makes you wonder what might be happening - especially when it lasts for over an hour. But what really struck me was how much we expect instant information these days. Took over 30 minutes to fig…

Part of me suspects that there might be something in this related to current events. If I were to spitball ideas about motives and modus operandi, it feels like the kind of thing a state actor would tamper with, and in terms of style I'd gravitate toward looking in North Korea's direction, since it feels like their style. Why do it? Raising noise with false alarms, desensitizes the intended signal of an alarm, ruinin…

I was going to joke that I'm surprised this wasn't posed as "Russian hackers set of sirens" considering that the US currently tries to pin everything on them but it seems you beat me to it -- and with Poe's law in full effect, too.

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#16

When I helped run a college radio station as a student, one if the things I had to check on was the Emergency Alert System (EAS). It's the system that cuts into your broadcast and allows emergency personnel to transmit information over TV and radio. Maybe it was specific to our setup, but our station was assigned two other stations to listen to for EAS alert tones. If the box heard the tones it would flip a relay and…

Well, the small stations who don't have a person decided when to play the alerts are typically listening to two larger stations, and it varies which ones they are listening to. So yes, a malicious actor could conceivably do this, but he/she would have to be close enough the antennas and have a transmitter powerful enough to broadcast over the assigned signals.

As others have noted, larger stations generally always have at least one person present who can verify alerts before rebroadcasting them.

EAS is not a perfect system, but it's not the worst in terms of infrastructure weaknesses.

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#18
post #7

I was in Dallas when this happened. I can attest to the eeriness of sirens going off all over town with no idea what they mean. In Texas we're accustomed to tornado sirens, but when the skies are clear and they are going off, makes you wonder what might be happening - especially when it lasts for over an hour. But what really struck me was how much we expect instant information these days. Took over 30 minutes to fig…

Part of me suspects that there might be something in this related to current events. If I were to spitball ideas about motives and modus operandi, it feels like the kind of thing a state actor would tamper with, and in terms of style I'd gravitate toward looking in North Korea's direction, since it feels like their style. Why do it? Raising noise with false alarms, desensitizes the intended signal of an alarm, ruinin…

I can almost guarantee this was just a kid messing around. There's no real motive for anyone else.

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#19

When I helped run a college radio station as a student, one if the things I had to check on was the Emergency Alert System (EAS). It's the system that cuts into your broadcast and allows emergency personnel to transmit information over TV and radio. Maybe it was specific to our setup, but our station was assigned two other stations to listen to for EAS alert tones. If the box heard the tones it would flip a relay and…

The SAME format has no inherent security to it. Some implementations do some signal processing (thresholding really) to try to mitigate fake messages.

Re: Hackers set off Dallas’ 156 emergency sirens over a dozen times

#20
post #6

When I helped run a college radio station as a student, one if the things I had to check on was the Emergency Alert System (EAS). It's the system that cuts into your broadcast and allows emergency personnel to transmit information over TV and radio. Maybe it was specific to our setup, but our station was assigned two other stations to listen to for EAS alert tones. If the box heard the tones it would flip a relay and…

Growing up, the audio tone for that signal was etched into my brain over the course of numerous Saturday mornings, when I woke up early enough to hear the tests. This was before cable was normal. Sometimes it felt like the dial-tone-like noise drilled into your ears for a solid 90 seconds. Example: https://www.youtube.com/watch?v=oOVwgKmzROw The new sound is even worse (and seemingly longer), and I imagine it's signa…

> The new sound is even worse (and seemingly longer), and I imagine it's signal (which sounds more like fax machine squelches than an alert noise) has been crafted to prevent incidents like you describe.

The evil part of me wonders if a replay attack would work for that more complex signal or whether it contains something tied to the current date.

The problem with emergency measures is they have to work in circumstances when you can't rely on other stuff any more which means they have to be as simple as possible.

Post reply on HN