Earlier quoted context omitted.
That's not how it works. You need the private key to sign the drivers. This is not a file that developers of those companies have access too. These keys are usually stored on a HSM. Even if you want to, you wouldn't be able to access the keys stored inside. This is specifically designed to protect against rogue/bribed personnel. So it's highly unlikely that the stuxnet developers had possession of the key. I'd bet th…
IDK, pre-windows-10 didn't you just need a ~$200 [1] code signing certificate? Do people usually buy HSMs to store those? [1] https://www.sslshopper.com/microsoft-authenticode-certificat...
The Stuxnet worm may be the most sophisticated software ever written
161–170 of 507 posts
Re: The Stuxnet worm may be the most sophisticated software ever written
#162I am just your average software dev with zero knowledge of malware creation, speculating here, and might come across as a fool. The author sensationalizes the effort of the creators, painting a Holywoodesque scenario where they break into every possible software company to steal keys to misrepresent the software, going undetected by every possible security company etc. Since this is a Quora post, I can live with him…
The sophistication of this software is that it did all this undetected.
Re: The Stuxnet worm may be the most sophisticated software ever written
#163Earlier quoted context omitted.
> I'd bet that they somehow had access to the HSM, to have it sign the driver for them. Or were able to duplicate the HSM before it was delivered. You know, like how the NSA intercepted shipments of internet routers in transit and inserted backdoors.
You don't ship HSM's with keys (you initialise them on-device yourself) nor can you read read keys out from one (at least in theory).
Re: The Stuxnet worm may be the most sophisticated software ever written
#164Earlier quoted context omitted.
Well, to be fair, Iran is trying to build a nuclear weapon and wants to wipe out Israel.
Every time someone brings up "wants to wipe out xyz", I wonder how that would play out. North Korea wants to nuke the US and SK, Iran wants to nuke Israel, Pakistan wants to nuke India, etc. But playing the scenario in your head leaves to a simple conclusion: If either NK or Iran would deploy nukes, it would be their end. It is likely that the US will remain the only nation on this planet who dropped nukes on civilia…
Re: The Stuxnet worm may be the most sophisticated software ever written
#165I would argue that this one was more sophisticated: http://pferrie.tripod.com/papers/zmist.pdf What I am seeing lately with malware is increasing decline in sophistication, today malware is lame compared to the malware created around 2000. I would think that level of low level knowledge is rapidly dropping. When there were still real file infectors, there were some serious nasty technologies involved (btw, todays ran…
I agree. Mistfall (and z0mbie himself) was years ahead of its time. For those not aware of Mistfall: typical viruses simply append their code to the target. To avoid detection, polymorphism was introduced: viruses generate permutations of decryption logic for the actual static but encrypted virus body. The next step was metamorphism: the virus body itself got permuted. Mistfall was one step further: it disassembled t…
http://dsr.segfault.es/stuff/website-mirrors/29A/
And mirror of z0mbie (mistfall author) site http://z0mbie.daemonlab.org/
I am really interested what happened with z0mbie... he just vanished at some point...
Re: The Stuxnet worm may be the most sophisticated software ever written
#166I am just your average software dev with zero knowledge of malware creation, speculating here, and might come across as a fool. The author sensationalizes the effort of the creators, painting a Holywoodesque scenario where they break into every possible software company to steal keys to misrepresent the software, going undetected by every possible security company etc. Since this is a Quora post, I can live with him…
> The rest of it is all about asking the associated companies, politely, to cooperate. What keeps this cooperation secret? It would only take one weak link at any one of those companies to reveal -- accidentally or otherwise -- that they were coerced into providing their signing keys. As soon as that got out, speculation runs amok: Are all products from said company compromised? This would be ruinous to a company, so…
Re: The Stuxnet worm may be the most sophisticated software ever written
#167Earlier quoted context omitted.
You know what's worse than the instant obliteration of millions of people? The slow obliteration and starving of millions of people. Imagine Venezuela, but much much worse. Picture a society that doesn't know how to create institutions, conduct trade and collaborate with the people around them without the aid of a computers. Now, I don't know if disabling their computers would result in an incredibly dysfunctional so…
Actually, in a capitalist country it might be easier to survive such an attack. If there is demand for a product or service, people and businesses will find a way to meet that demand. Millions of people working independently to satisfy their local market demand. It would probably hurt centralized socialist or communist countries more since it severs their control, surveillance, and communication mechanisms.
It doesn't matter if C&C is corporate or state, they break the same way.
Re: The Stuxnet worm may be the most sophisticated software ever written
#168I am just your average software dev with zero knowledge of malware creation, speculating here, and might come across as a fool. The author sensationalizes the effort of the creators, painting a Holywoodesque scenario where they break into every possible software company to steal keys to misrepresent the software, going undetected by every possible security company etc. Since this is a Quora post, I can live with him…
> The rest of it is all about asking the associated companies, politely, to cooperate. What keeps this cooperation secret? It would only take one weak link at any one of those companies to reveal -- accidentally or otherwise -- that they were coerced into providing their signing keys. As soon as that got out, speculation runs amok: Are all products from said company compromised? This would be ruinous to a company, so…
Re: The Stuxnet worm may be the most sophisticated software ever written
#169Earlier quoted context omitted.
You know what's worse than the instant obliteration of millions of people? The slow obliteration and starving of millions of people. Imagine Venezuela, but much much worse. Picture a society that doesn't know how to create institutions, conduct trade and collaborate with the people around them without the aid of a computers. Now, I don't know if disabling their computers would result in an incredibly dysfunctional so…
Who stands to benefit by destabilizing the western world to such a degree? Clearly some big players like Russia and China, as well as some smaller players can benefit from destabilizing the western world a little bit. But if they destroy it to the point where millions of people are suffering, they'll bring suffering on themselves as well. It seems to me that they're probably motivated to level the playing field and g…
Modern history is littered with examples of millions of people starving or being slaughtered because societies collapsed economically or politically.
> Who stands to benefit by destabilizing the western world to such a degree?
Who's limiting the conversation to the western world? Let's think beyond ourselves for a second. Wouldn't it be just as tragic if cyber attacks were used to destabilize other places in the world? Imagine an African country that has become entirely dependent on some sort of mobile money transferring platform. Maybe their neighbor launches an attack on that platform to destabilize the country for whatever nefarious reasons.
Re: The Stuxnet worm may be the most sophisticated software ever written
#170And then people make a fuss about Russia "hacking" the election with some dumb Facebook ads which cost less than maxed out Ford Mustang. When on the other hand we have the state-sponsored military grade/purpose viruses used to attack other nations/regions (Flume attacked a large number of targets and countries) and nobody blinks an eye.
Those are indicative of the public’s enduring lack of technology literacy, and the media’s desire to have facts and eyeballs meet halfway. Media reports Russian election interference via digital ad spend, astroturfing, and infiltration attempts on state voting systems accurately, but the views to that reporting probably pale in comparison to the oversimplified, tweet-size “Russia hacked the 2016 US election” reportin…
No, it's because the media is ultimately subservient to power regardless of what they might think of themselves. US attacks on countries designated by power as enemies -- Iran, Venezuela, Russia, etc., are only to be discussed in clinical terms, marveling at their technological sophistication, for example, never in moral terms. Bringing up any introspection of what American reaction would be if Iran did the same thing to us is virtually career suicide for a mainstream media professional. Trying to draw parallels between Russia meddling and Stuxnet, noting that Stuxnet was an attack many times worse, is cutting it dangerously close.