Live data from Hacker News

Nuclear weapons agency breached amid massive cyber onslaught

politico.com

191–200 of 222 posts

Re: Nuclear weapons agency breached amid massive cyber onslaught

#191

Classified networks are typically air gapped.[1] Doubtful that hackers obtained anything useful. [1] https://en.wikipedia.org/wiki/Air_gap_(networking)

Wouldn't be so sure. Data is eventually copied out of the airgapped side, e.g. NSA exploits are developed in the airgap and copied to an attack staging server on the Internet. And there's one-way connectivity into the airgaps via data diodes. So it's possible that a sufficiently advanced malware got through the data diode, infected the airgap side and hitched a ride out over sneakernet.

Re: Nuclear weapons agency breached amid massive cyber onslaught

#192

I am pointing the finger at Microsoft for allowing bad security practice in windows kernel, architecture and other aspects of the Windows operating system. I am have to hand it to Microsoft for the good job security. However without knowing the extent of the incident, and going off of this part: "At this point, the investigation has found that the malware has been isolated to business networks only..." It is more tha…

I'm not a fan of Windows in the slightest, but it should be noted that the Linux kernel has been moving in that direction for the better part of 2 decades now. The amount of privileged code running in the kernel now is absolutely mind boggling. I'm really hoping to see an industrial-scale push to develop a solid headless unix-y userland for SeL4.

Do you mean eBPF? Or what kind of privileged code is the problem?

Regarding security. I think the problem is simply that neither Linux nor Windows is the right tool for this job. They are secure, but not nuclear arsenal secure. And there is where SeL4 and other formally verified components should come in.

Re: Nuclear weapons agency breached amid massive cyber onslaught

#193

How come this community of self-proclaimed hackers and independent thinkers are so quick to believe whatever "cyber-attack" related news that gets published?

What would you assume the intention is here to lie? Are they trying to make themselves intentionally look bad to start a war with Russia? Put more sanctions on them? I don't really see the incentive here.

Re: Nuclear weapons agency breached amid massive cyber onslaught

#194
post #182

Earlier quoted context omitted.

I worked for a company that had all their Customer data stolen and then sold on a darknet market place. They completely swept it under the rug, told the infosec guys that if they talked about the incident with anyone they would have their employment terminated and that it was to never be discussed because they were worried about their share price. We also have laws here in Australia that says if this happens to a bus…

That's why GDPR includes personal liability for DPOs(Data Protection Officers) and chief executives, and requires the company have a DPO with no conflict of interest ( e.g. working under the CEO with bonuses based on stock price).

I think the idea of "no conflict of interest" for an employee of a company is a bit silly. No internal conflict of interests sure, but everyone on payroll has a vested interest in the continued financial health of the organisation.

Re: Nuclear weapons agency breached amid massive cyber onslaught

#195
post #50

I have to wonder how many corporations have been hacked but we will never know, because they are worried about the value of their stock. This could actually be a much greater threat to hobbling our infrastructure or blackmailing wealthy people to do their bidding.

I worked for a company that had all their Customer data stolen and then sold on a darknet market place. They completely swept it under the rug, told the infosec guys that if they talked about the incident with anyone they would have their employment terminated and that it was to never be discussed because they were worried about their share price. We also have laws here in Australia that says if this happens to a bus…

Open source software has "more" vulnerabilities because more of them get reported. With proprietary software black hats are gathering exploits in a weapons silo ready to be sold on the black market.

For some reason businesses prefer to cover up their vulnerabilities instead of fixing them. When you report a vulnerability as a white hat there is a big risk that the company will use you as a scapegoat and sue you. For a business it is much easier to claim that they "caught a hacker" rather than admit their weakness in public.

Hackerone is basically a "vulnerability blackhole as a service" because researchers are dependent on bounties for their income. Disclosing an ignored vulnerability publicly weeks or months after the hackerone report can lead to getting banned on hackerone and thereby ruin your ability to collect bounties.

Re: Nuclear weapons agency breached amid massive cyber onslaught

#197

Earlier quoted context omitted.

I think he even has a trigger on that which sometimes leads to funny situations.

dang has a trigger on the nuclear weapons suite? wow, I thought being an hn mod was powerful but I had no idea .

Off topic, I know, but this entire exchange was quite wholesome and funny. With everything going on these days you all brought some levity to my day, thanks.

Re: Nuclear weapons agency breached amid massive cyber onslaught

#198

The good news is that US nuclear weapon silos are stuck with 1970s technology. https://slate.com/technology/2014/04/huge-floppy-disks-and-o...

Everyone calm down:

It was just a kid trying to hack into a video game company. He accidentally started a war simulation. The US had recently turned over control of its entire nuclear arsenal to an AI because humans resisted launching weapons that would kill millions.

Anyway, the kid accidentally started a war simulation and now the AI wants to nuke everyone. Don’t worry though, as soon as the AI plays itself in tic-tac-toe, it will realize that peace is the only way.

If you aren’t old enough to understand this, you need to catch up on your 80s nerd movies. :)

Re: Nuclear weapons agency breached amid massive cyber onslaught

#200
Yes evidence, more evidence, just like the good ol' time that US had evidence from Nayirah, and Powell wielded a tube of wash powder in UN claiming that was WMD.

I do believe that President Trump deserves a Nobel Peace Prize, because with so many evidences, his precedents, including our be-loving Obama, would have bombed the hell out of our designated enemy.

Post reply on HN