Live data from Hacker News

Stuxnet Source Code

github.com

41–50 of 127 posts

Re: Stuxnet Source Code

#41
post #32

I remember having to write a presentation about Stuxnet while at Uni, it was insane. At the time they reckoned the authors had a functioning QA environment to ensure it actually worked (broke) the Siemens PLCs they were targeting.

Me too! It was such a pivotal moment.

Re: Stuxnet Source Code

#42
post #36
post #32

I remember having to write a presentation about Stuxnet while at Uni, it was insane. At the time they reckoned the authors had a functioning QA environment to ensure it actually worked (broke) the Siemens PLCs they were targeting.

Nitpick but it was even harder, they wanted to keep the PLCs intact, report back normal operation, and change the control output specifically to destroy/damage uranium centrifuges

Yep. I'd be surprised if their QA environment didn't contain at least one uranium centrifuge.

Re: Stuxnet Source Code

#43
post #36

Earlier quoted context omitted.

Nitpick but it was even harder, they wanted to keep the PLCs intact, report back normal operation, and change the control output specifically to destroy/damage uranium centrifuges

Yep. I'd be surprised if their QA environment didn't contain at least one uranium centrifuge.

You'd be insane to develop something of the complexity of Stuxnet and not include a full end to end test in the QA process. It would be incredibly embarrassing for this to fail.

Re: Stuxnet Source Code

#45
post #13

Earlier quoted context omitted.

A nuclear plant is just as weaponizable as any large dam...

Is it? The nuclear fallout of a plant may linger for longer than any destruction done by the water of a large dam I would say or do you mean something else?

Certain types of nuclear reactors can be used to create fissile material; kind of super weaponisable?

https://en.wikipedia.org/wiki/Breeder_reactor

Re: Stuxnet Source Code

#46
post #22

Earlier quoted context omitted.

Nuclear power is vastly better in terms of emissions, so I'd argue that blowing up a plant or two is worth stopping global warming. But why target plants when a dirty bomb attack would be way easier and more effective? Additionally, most countries don't have the resources to pull off something like Stuxnet, and the ones that do have much more to gain through corporate and government espionage.

There is some problem there though - peacefully using nuclear power creates plutonium, which could be later extracted.

Not if you use other processes. But those don't produce plutonium so they haven't been invested in enough.

Re: Stuxnet Source Code

#47
I just love that not only they copyrighted it, they even give excuses for it. You can't copyright someone else's work, regardless of how long you took to reverse-engineer it from disassembled binaries. Obviously the "rights owners" are not going to take those two guys to court (pity though, that would've been hilarious), but since the only reason those two could license this is that this is a computer virus and no one will claim authority, their claims to ownership of the code have no merit. I would love it if someone would publish or use it and not give them credit or "violate" the terms of the license in some manner, as I'd love to see those two try to claim their case.

Re: Stuxnet Source Code

#48

Can anyone explain why Stuxnet was admitted to and publicised so much. Aren’t secret operations usually kept… secret? What was the motivation for the PR drive?

I don't think there was a PR drive from the US/Israeli government, more like despite the US/Israeli government.

Remembering that the only reason we even know about stuxnet is because it was so aggressive that practically every PC on the planet caught it at one point. Also "stuxnet" is the name we gave it, it seems similar to another US Govt project that we know very little about codenamed "Olympic Games".

If it had not been so aggressive it would have gone completely unnoticed. Likely this is the case for a lot of state-sponsored malware. (especially coming out of FIVE-EYES).

Re: Stuxnet Source Code

#49
post #44

Has anybody else here read Kim Zetter's great book Countdown to Zero Day? It's a wonderful look at the discovery of Stuxnet.

Yes i can't recommend this book enough if you are interested in Stuxnet or cybersecurity. Very detailed and thorough.

Re: Stuxnet Source Code

#50
post #47

I just love that not only they copyrighted it, they even give excuses for it. You can't copyright someone else's work, regardless of how long you took to reverse-engineer it from disassembled binaries. Obviously the "rights owners" are not going to take those two guys to court (pity though, that would've been hilarious), but since the only reason those two could license this is that this is a computer virus and no on…

Is the law clear in this? They created something different from the source material binary program.
Post reply on HN