Live data from Hacker News

Computer virus hits US Predator and Reaper drone fleet

arstechnica.com

101–110 of 197 posts

Re: Computer virus hits US Predator and Reaper drone fleet

#101
post #73

Earlier quoted context omitted.

I'd attach them to the PCIe bus somehow, or otherwise wire them straight into the motherboard. Let me remind you that this computer can fire missiles at people , and has a potentially unlimited budget.

It does not have a potentially unlimited budget. As was mentioned above, these are often contracted third parties who develop the systems. They put in bids on government jobs and undoubtedly have their own margins to look after. Once the job is awarded, my understanding is that you can't change the price-tag it was awarded at. (At least, not easily)

The individual contracts have limited budgets, but if there were a DoD or Government-wide instruction that all systems meet a specific security standard, all contracts would be amended (cost increased along with scope) to comply with that standard. There's very little external pressure to constrain the maximum possible IT and IT security spending within government, especially the military.

The costs of good vs. bad IT security are actually not terribly significant in the context of the overall defense budget, either.

It's really a failure of process and vision, not resource constraint. Government IT and IT security used to lead industry; now consumers especially and even enterprises are more advanced than government.

Re: Computer virus hits US Predator and Reaper drone fleet

#102
post #68

Earlier quoted context omitted.

I have never heard of a drone running anything other than an RTOS. However the ground stations for command/control/monitoring are typically run on traditional Windows-OS machines.

If the drone is running a RTOS, wouldn't the GCS need RTOS-like reliability as well to communicate with it? That's all I can say (I think)

No. Windows boxes can communicate to an RTOS like VxWorks over a network just fine.

Re: Computer virus hits US Predator and Reaper drone fleet

#103
post #78

Earlier quoted context omitted.

"usb ports with glue" Keyboards, Mice, Joysticks for these systems were probably designed with the idea that a USB bus would be available. It will take a while to replace all of these systems with their non-USB configurations. Given that BlueTooth is probably a no-no as well, how would one build a system these days that needs to support Mice, Joysticks, and Keyboards without using USB?

How about an over-cage for the physical machine? A literal chicken-wire-style cage that encloses the PC case, with openings too small to pass the head of a USB device. The cage would be locked to prevent removal of the machine and have a locked backpanel which allows certified staff to install the various usb devices -- with some sort of cage mount inside to loop the cables around, so that a tug from the user wouldn'…

People do this for kiosks (unattended, public use) all the time. It's a good solution for some things.

It's easier to enforce a security policy on well-managed PCs which turn off various ports in software (AND DISABLE AUTORUN!), vs. trying to physically disable them, but DoD also had people go around and epoxy USB ports, or at the very least put foil seals on them. There are problems with this, like the usb cd-rom token things, and the attack mouse.

One of the few areas of IT security the DoD gets right is physical protection of infrastructure (relatively). Unfortunately, it's usually basically a strong shell with a gooey inside of software/networks, and with big pipes bringing lots of stuff in and out of the shell constantly. Once something bad gets in, it's kind of too late.

There's a lot of awesome new Intel stuff to make PC hardware potentially more secure -- secure boot, CPU features, memory protection, etc. Combined with the right OS, you could go a long way. Unfortunately a lot of people are also against this technology because it has been used for Digital Rights Management (DRM) anti-piracy, other privacy violations, etc. I was really against it for those reasons, but have come to think it would on the whole be a net win for society to have more secure IT, even if not being able to break it so easily means some people can use computers for bad things.

Re: Computer virus hits US Predator and Reaper drone fleet

#104
"Eventually, the technicians had to use a software tool called BCWipe to completely erase the GCS’ internal hard drives."

You mean they paid $40 a license for dd if=/dev/null of=/dev/sda?

(I know BCWipe is a secure delete tool. But a computer virus can't perform forensic analysis of your hard drive.)

Re: Computer virus hits US Predator and Reaper drone fleet

#105

It would be great if Ars had used its security and technical staff to tell us if this is a problem or the minor annoyance that the military says it is. The article amounts to little more than a summary of the drone program and a bit of "he said she said" http://archive.pressthink.org/2009/04/12/hesaid_shesaid.html reportage.

How could they do that analysis without having the virus or other data firsthand? They can only report what they have.

Analyse what they know: 1. It's a keylogger 2. They've been aware of it for weeks 3. They admit that they can't seem to beat it 4. These are isolated systems and it's likely that the attack was via USB drives

Based on those facts, is it likely that this is benign? Are there known viruses that fit this pattern? Who's in charge of this project, and what do they say about it? Is it SOP for viruses to be able to completely beat military security for weeks? What are the possible security breaches? Why attack this part of the system?

There's a lot of questions that could and should be asked. Instead, Ars just repeated history and summarized the press release.

Re: Computer virus hits US Predator and Reaper drone fleet

#106
post #89

Earlier quoted context omitted.

I am totally with you. If software is going to operate deadly weapons, it sure as hell better be secure. But you are glossing over a LOT of detail here. The military doesn't work like Apple: they don't design, oversee, or directly control the construction of the hardware they use. And they shouldn't - the government is woefully inefficient at building products, that's what corporations are good at. Here's the situati…

Perhaps they shouldn't use a platform that runs Norton in the first place? I suspect that under it all, you'll find an unpatched XP or even Win2000.

I guarantee UAV's are not running XP or Windows 2000. The government has heard of things called RTOS.

Re: Computer virus hits US Predator and Reaper drone fleet

#107
post #99

Earlier quoted context omitted.

Wow can anyone confirm this? I'm surprised that the drones themselves are running windows. If so, I presume it's win CE or a custom variant of?

The control systems run XP, Vista, or maybe Windows 7 (not sure about 7 yet). This is true of almost all military desktops, and all office automation servers, and most specialized servers (well, Windows Server 2003/2008). I'm not sure what OS is on the aircraft; I think it's probably a RTOS for flight control and possibly separate processors (running whatever) on a bus for sensor packages. A lot of UAVs have intercha…

I know the F22 runs windows on top of a RTOS. I imagine many other planes and such are similar.

Re: Computer virus hits US Predator and Reaper drone fleet

#109
post #106

Earlier quoted context omitted.

Perhaps they shouldn't use a platform that runs Norton in the first place? I suspect that under it all, you'll find an unpatched XP or even Win2000.

I guarantee UAV's are not running XP or Windows 2000. The government has heard of things called RTOS.

But the computers controlling the Drones seem to be running some sort of Windows variant. There's no real need to control the drones directly if you can control the computer that controls the drones.

Re: Computer virus hits US Predator and Reaper drone fleet

#110
post #106

Earlier quoted context omitted.

Perhaps they shouldn't use a platform that runs Norton in the first place? I suspect that under it all, you'll find an unpatched XP or even Win2000.

I guarantee UAV's are not running XP or Windows 2000. The government has heard of things called RTOS.

I wouldn't be so sure about that.

http://gcn.com/articles/1998/07/13/software-glitches-leave-n...

And, have you seen all the computers necessary to carry out a drone operation? I guarantee you not all of them are running an RTOS. Probably not even all of them onboard the drone.

Post reply on HN