Live data from Hacker News

The Stuxnet worm may be the most sophisticated software ever written

quora.com

241–250 of 507 posts

Re: The Stuxnet worm may be the most sophisticated software ever written

#241

I'd argue that Google Search is much more sophisticated than Stuxnet. Windows is much more sophisticated. Linux is more sophisticated than Stuxnet. The list goes on. We tend to ignore the sophistication of things we are familiar with, and hype those that surprise. But that's not a fair measure of anything.

I agree.

It's the most sophisticated piece of malware, that's for sure (at least counting the ones we know of).

But calling it the most sophisticated piece of software is too big of a stretch.

That said, other answers to this question include what we would traditionally consider as contestants (like Linux kernel), it just happens that the submitter decided to submit this specific answer. I don't know was this the top answer before it exploded here, but it sure is now.

Re: The Stuxnet worm may be the most sophisticated software ever written

#242

> This driver was digitally signed by Realtek, which means that the authors of the worm were somehow able to break into the most secure location in a huge Taiwanese company, and steal the most secret key that this company owns, without Realtek finding out about it. > Later, whoever wrote that driver started signing it with secret keys from JMicron, another big Taiwanese company. Yet again, the authors had to figure o…

I can tell you that even a meager telco that I've worked for has very good security to their PKI equipment and none of it is networked. Has had since before stuxnet became known. And they don't even manufacture hardware.

If you manufacture hardware and distribute drivers you are an even bigger target than a telco.

Re: The Stuxnet worm may be the most sophisticated software ever written

#243
post #232
post #8

I've been arguing about this for the last three days. Mostly around the reason that "complexity" is not strictly the same thing as "sophistication" when it comes to software. Noobs will conflate the two, but experienced programmers will agree that -- just to illustrate my point -- some code which solves a complex problem in a very clever way while also being very clean and easy to maintain will be considered strictly…

On complexity vs sophistication: During the cold war, a US company noticed the USSR had stolen the plans for a natural gas pipeline system, but not the software. In response, the US introduced an integer overflow bug that was uptime dependent, and took something like 6 months to hit. The bug simultaneously cranked up the pumps and closed all the valves in the network. It was known that the Soviet economy would crash…

Do you have a source for this? I can only find reports from "At the Abyss", which are uncorroborated.

Re: The Stuxnet worm may be the most sophisticated software ever written

#244
post #134

Earlier quoted context omitted.

That's not how it works. You need the private key to sign the drivers. This is not a file that developers of those companies have access too. These keys are usually stored on a HSM. Even if you want to, you wouldn't be able to access the keys stored inside. This is specifically designed to protect against rogue/bribed personnel. So it's highly unlikely that the stuxnet developers had possession of the key. I'd bet th…

> That's not how it works. You need the private key to sign the drivers. This is not a file that developers of those companies have access too. No, you could unfortunately get around that very easily (or rather, ignore recommendations) at least a few years ago. So I bet there are a lot of certificates and private keys lying around on disks, build servers, version control systems and probably even on developer USB sti…

More likely they just spear phished the people who would have access that can be used to get the keys.

Re: The Stuxnet worm may be the most sophisticated software ever written

#245

Earlier quoted context omitted.

"Russia has hacked into many of our government entities and domestic companies in the energy, nuclear, commercial facilities, water, aviation and critical manufacturing sectors" https://www.forbes.com/sites/jamesconca/2018/03/16/russia-ha... The same was also reported by MI5, Europol and of course within Ukraine.

And, no doubt, we (USA/Western democracies) have hacked theirs.

Whataboutism

Re: The Stuxnet worm may be the most sophisticated software ever written

#246

Stuxnet changed history. Any "game of chicken" style equilibria is broken if the probability a nuclear actor's command and control drops below 100%. If there is even a 1% chance that when a Big Red Button is pushed the missiles fail to launch the game becomes unwinnable. Simulations of imperfect information in dynamic brinkmanship where both players are known to have advanced cyber capabilities results in a single dr…

> the probability a nuclear actor's command and control drops below 100%.

It's never been at 100% anyway. Read the book "Command and Control" if you are not convinced.

Re: The Stuxnet worm may be the most sophisticated software ever written

#247

How do you define sophisticated? Complex or elegant? Because if it's more towards the latter then I'd suggest the software that took humans to the moon and back, several times, is much more sophisticated. But from reading the article it seems the author is aiming more for complex than elegant.

I'd say it's got both. It's extremely complex, but it does what it needs so cleanly. I'd argue that it's extraordinarily elegant.

Re: The Stuxnet worm may be the most sophisticated software ever written

#249

Earlier quoted context omitted.

The problem is not everyone on the world stage is a rational game theory nerd that links to papers like we want them to be. Also 60 years of treating every other country as a box in a threat model to be manipulated against other boxes has been a completely unmitigated disaster, so maybe we should stop that.

For all the evidence we have, MAD has worked. Still here. Still no WWIII. At the beginning of the twentieth century it was looking like we'd have another world war every twenty years or so for the rest of time. As best we can tell, nukes actually did end large-scale war. I would call that at least a partially mitigated disaster.

While my humble opinion is that MAD was effective, let's be careful not to infer causation from a sequence of events (the rooster crows and then the sun rises). And the events of 'MAD' and 'peace' are not in sequence: WWII ended in 1945. MAD wasn't an idea until the 1960s and not implemented in a treaty until the 1972 Anti-Ballistic Missile (ABM) Treaty, AFAICT.[0]

It makes more sense if you remember that nuclear weapons and delivery technology didn't reach the 'assured destruction' stage for awhile. Remember that in the Korean War, in the 1950s, General MacArthur was pushing to use nuclear weapons (IIRC); it wasn't as taboo then. Finally, remember that MAD applied only to the Soviet Union and U.S. (or the Warsaw Pact and NATO), while major international wars ended worldwide, for the most part. Remember that WWI and WWII were fought between future NATO members; the later peace between them wasn't due to MAD.

> At the beginning of the twentieth century it was looking like we'd have another world war every twenty years or so for the rest of time.

The victors of WWII were very concerned about that, and began planning to prevent it before the war ended. That resulted in the UN, the institutions that became the EU, a rejection of nationalism (as a significant cause of war), the spread of democracy and universal human rights as a peace-making policy (democracies generally don't start wars with each other), and U.S. leadership in the international order to maintain those things and to provide stability. My understanding is that those are the reasons for the relative but extraordinary peace. Here's a Churchill speech about it in Zurich in 1946 (the speech focuses on the future EU; remember he also was one of the architects of the United Nations):

http://www.churchill-society-london.org.uk/astonish.html

(I'll also note that they seemed to have worked so well that now people take the peace for granted and are tossing aside the things that make it happen.)

[0] The best credible source I can find quickly. If you hit a paywall, access it via a search engine: https://www.britannica.com/topic/nuclear-strategy#ref1224926

EDIT: Added a detail

Re: The Stuxnet worm may be the most sophisticated software ever written

#250

> This driver was digitally signed by Realtek, which means that the authors of the worm were somehow able to break into the most secure location in a huge Taiwanese company, and steal the most secret key that this company owns, without Realtek finding out about it. > Later, whoever wrote that driver started signing it with secret keys from JMicron, another big Taiwanese company. Yet again, the authors had to figure o…

This is the most suspicious element of the whole affair. The actual security algorithms weren't compromised rather they compromised the whole environment by getting their hands on the Realtek keys.

Personally I doubt that retrieving this key involved required some act of super ninja skills espionage. I suspect somebody high up in the US government simply picked up the phone and called somebody high up in the Taiwanese government. The reality is Taiwan's security at the end of the day is wholly dependent upon US defense. There are no other options, there are no other cards in their hand. They absolutely need the US military to secure the continued existence of their nation.

This is the lesson of Stuxnet: "private" actors aren't. At the end of the day the US government has demonstrated again and again that it can compel cooperation from virtually every technology firm in the "free world." It's not a card to be played lightly but it's absolutely there. Thanks to Snowden we know the NSA regularly compromises Cisco telecom equipment created for export [1][2] and that the US government is working closely with all the major tech firms[3].

And this is why the US does not want China exporting Chinese phones, electronics, telcom kit, chips and social software. There's absolutely no problem when "private companies" in the US, Korea, Japan and Taiwan export this equipment and technology because these companies are squarely under the thumb of the US. Now that China is getting in on the game everybody is freaking the fuck out precisely because they understand perfectly what it means for "private companies" in China to have a significant chunk of the market.

Of course the Chinese also understand exactly what's going on here and this is why they've established the Great Firewall and why they're absolutely determined to homegrow all their technology needs. Right now China imports an absolutely extraordinary amount of chips and it is probably their greatest security weakness [4].

So this is what it comes down to: every large corporation that matters is likely a phone call and/or secret warrant away from literally giving its private keys to some government actor, likely the US or China. Any data stored by these corporate systems should be considered readable and writable by the government. Any service secured by these corporate systems should be considered accessible and ultimately under the control of these governments. These corporations will not risk either their continued existence or the possibility of fat government contracts in order to protect their customers from these governments. Individuals who depend upon these corporations are therefore completely at the mercy of these government actors.

All of this is a long way of saying that security of digital assets cannot be outsourced.

[1] https://arstechnica.com/information-technology/2016/08/cisco...

[2] https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

[3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

[4] http://nationalinterest.org/feature/how-china-will-benefit-a...

Post reply on HN