Computer virus hits US Predator and Reaper drone fleet
141–150 of 197 posts
Re: Computer virus hits US Predator and Reaper drone fleet
#142Re: Computer virus hits US Predator and Reaper drone fleet
#143Earlier quoted context omitted.
Well the ISS uses windows [1] and there were reports of malware getting up there. They also had driver compatibility issues and were rebooting the systems that controlled the gyros a lot. One would think you could just write a mil-spec OS for their computers but government, and more specficially government procurement, doesn't really work that way. [1] http://www.zdnet.com/blog/security/malware-detected-at-the-i...
There's no virus on the ISS. It was on the laptops the crew carries around. Big difference. The control systems of the ISS aren't windows.
[1] http://www.wired.com/science/discoveries/news/2001/04/42912?...
[2] "At about 2200, we were reconfiguring some mail files which, with a lot of help from Windows NT, got put in the wrong place during the backup procedure. When we finished restoring the files, the network was down and would not come back up. We worked this for several hours. Finally, jiggling some cables brings just a part of the net back. (that really instills confidence in the stability of your network)." - from http://spaceflight.nasa.gov/station/crew/exp1/exp1shepmarfeb...
Re: Computer virus hits US Predator and Reaper drone fleet
#144Perhaps the fact that our computer systems are now of military importance and the fact that a security hole can mean deaths and international relations disasters will finally lead to people taking a good look at verified computing. Where a virus doesn't mean outsmarting some forgetful C programmer but is mathematically impossible. Or not, it was just a bug, we'll fix it this one time and pretend it will never happen…
Re: Computer virus hits US Predator and Reaper drone fleet
#145So all that terrorists have to do is commandeer a drone (thanks to this virus) and then they can rain terror anywhere they want? This is scary.
That's a bit like saying all a terrorist would need to do to seize control of an ICBM is to infect the missile base with a virus. It's not that easy.
Re: Computer virus hits US Predator and Reaper drone fleet
#146Earlier quoted context omitted.
If you're talking about the China hacks, they were using ie6. I'd argue that would preclude the "top notch engineer" label.
Nope. Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0...
"Microsoft thanks the following companies for working with us and for providing details of limited, targeted attacks against customers of Internet Explorer 6:
Google Inc. and MANDIANT; Adobe; McAfee; French government CSIRT (CERTA)"
http://technet.microsoft.com/en-us/security/bulletin/MS10-00...
Re: Computer virus hits US Predator and Reaper drone fleet
#147Earlier quoted context omitted.
How about an over-cage for the physical machine? A literal chicken-wire-style cage that encloses the PC case, with openings too small to pass the head of a USB device. The cage would be locked to prevent removal of the machine and have a locked backpanel which allows certified staff to install the various usb devices -- with some sort of cage mount inside to loop the cables around, so that a tug from the user wouldn'…
People do this for kiosks (unattended, public use) all the time. It's a good solution for some things. It's easier to enforce a security policy on well-managed PCs which turn off various ports in software (AND DISABLE AUTORUN!), vs. trying to physically disable them, but DoD also had people go around and epoxy USB ports, or at the very least put foil seals on them. There are problems with this, like the usb cd-rom to…
on the topic of disabling autorun, there was a patch earlier this year to disable autorun on non-shiny media by default in XP and Vista (it's already turned off in 7.)
http://blogs.technet.com/b/mmpc/archive/2011/06/14/autorun-a...
infections by autorun-abusing malware families dropped by over 60% as everything got patched, and total infection rate dropped by almost half.
Re: Computer virus hits US Predator and Reaper drone fleet
#148Either that or gross incompetence but my money is on the former.
Re: Computer virus hits US Predator and Reaper drone fleet
#149Earlier quoted context omitted.
I'd attach them to the PCIe bus somehow, or otherwise wire them straight into the motherboard. Let me remind you that this computer can fire missiles at people , and has a potentially unlimited budget.
you can disable any removable device, except the drone itself which seems talking back to the base using [non-encrypted] regular TCP/Ethernet and thus is a very plausible vector of continuous re-infection. The problem is well known and dates several years back: http://online.wsj.com/article/SB126102247889095011.html