Live data from Hacker News

Stuxnet Source Code

github.com

111–120 of 127 posts

Re: Stuxnet Source Code

#111
post #80

Earlier quoted context omitted.

I guess to be more exact, Stuxnet didn't break anything, but the PLC payload it delivered was designed to damage centrifuges, and that would have been the module under test in that QA environment

Wasn't it actually about spoiling the whole stock of Iranian's Uranium by applying damaging amounts of centrifugal force to it? I'm probably wrong about that, just asking.

the payload had a few modes of operation, IIRC

one was to spin it far faster than it should, then stop abruptly in an attempt to damage the centrifuge

one was to run it at the wrong RPM to spoil the product of the centrifuge

in either mode, it would replay 'good' data to make the centrifuge look functional to an administrator

the way I understood, a 'bonus goal' was to keep the Iranians unable to diagnose what was going wrong, both with their production process (producing bad stock) and the failures (promoting distrust in their engineers) - i can't find an article right now, but I remember reading they were churning through site engineers at the time - presumably firing them for the on-site failures of centrifuges or their inability to stop them

Re: Stuxnet Source Code

#112
post #52

Earlier quoted context omitted.

// TODO: תקן את זה

When an LTR Android system user selects RTL text, the selection markers are displayed LTR (the wrong way).

Relevant XKCD: https://xkcd.com/1137/

Surprisingly, I couldn't find a relevant XKCD for the post itself.

Re: Stuxnet Source Code

#113

Earlier quoted context omitted.

Honestly, it would be irresponsible and surprising if Israel _didn't_ try to sabotage Iran's nuclear program, especially given some of the things that the Iranians were saying publicly at the time.

[flagged]

What negative stereotype? That Israel has excellent cyber capacity?

Sure, there wasn't any official attribution, but the US aren't the only player in town either.

EDIT: As an aside, an ex-director of the DGSE[1] (french CIA basically) complained that there tend to be a general misunderstanding between the communication modes of western countries and middle-east countries, the former prefers to proverbially "Speak softly and carry a big stick" while the latter prefer a good incendiary speech as a form of catharsis. As a result western audiences tend to take some speeches too literally, as if they were a plan of action while the discourse wasn't made with them in mind.

[1] Alain Chouet, in the excellent (french-only) book "Au coeur des services spéciaux" https://www.editionsladecouverte.fr/au_coeur_des_services_sp... https://www.amazon.fr/coeur-services-sp%C3%A9ciaux-Jean-GUIS...

Re: Stuxnet Source Code

#114
post #54

Earlier quoted context omitted.

This. They don't give you the same as the original virus code, they give you different code (namely readable one), than apparently compiles to the virus assembly. It's plausible this took effort, so I think it's only fair if they license it - it seems also ethically fair, since their licence is permissive.

Wouldn’t that be considered a derivative work? You can copyright those.

I mean you cannot copyright derivative work.

Re: Stuxnet Source Code

#115

Earlier quoted context omitted.

You'd be insane to develop something of the complexity of Stuxnet and not include a full end to end test in the QA process. It would be incredibly embarrassing for this to fail.

Indeed. But as engineers it’s insane to think of having a testing environment that includes a uranium enrichment plant

Fair point. I can barely get access to a testing environment that contains a keycloak server.

Re: Stuxnet Source Code

#116

Earlier quoted context omitted.

This concept is featured in The Dark Forest, the second book in the Three Body Problem trilogy. It was something where you could genetically tag someone and then if they woke up 50 years later from a chrono sleep, various systems were preprogrammed to have "accidents" around them, like self driving cars, etc.

It's also in the (1998) Metal Gear Solid game, where the protagonist is the unknowing carrier of a virus deadly only to specific key people.

It's also explorered in the plot of a Limitless (TV series) episode. There, it targets people that have the Khan marker in their DNA.

Re: Stuxnet Source Code

#117

I remember first hearing about this while working at a US firewall company. The scale and precision of the attack kept this virus in the minds of everyone who appreciated what it proved capable of and the scale of social engineering employed to effect it. It kind of ushered in state-on-state cyber warfare, or at least, brought the reality of weaponized viruses to the public conscience.

Imagine if the same strategy were applied to biological warfare. Novel viruses tailored to be symptomatic and cause harm to just one specific world leader. If the technology exists, it could be the most formidable assassination tool available; a self-delivering, non-nuclear ace-in-the-hole for winning a war.

You don't have to imagine it, you can just play Metal Gear Solid!

Re: Stuxnet Source Code

#118

I remember first hearing about this while working at a US firewall company. The scale and precision of the attack kept this virus in the minds of everyone who appreciated what it proved capable of and the scale of social engineering employed to effect it. It kind of ushered in state-on-state cyber warfare, or at least, brought the reality of weaponized viruses to the public conscience.

Imagine if the same strategy were applied to biological warfare. Novel viruses tailored to be symptomatic and cause harm to just one specific world leader. If the technology exists, it could be the most formidable assassination tool available; a self-delivering, non-nuclear ace-in-the-hole for winning a war.

Corona ?

Re: Stuxnet Source Code

#119
post #58

I remember reading a very well written article on stuxnet, detailing the entire way it worked. It was written in a very story-like way that built slowly until it revealed what the actual payload and impact was. Does anyone have a link to this article?

The Perfect Weapon by David Sanger.

Everything Sanger knows about Stuxnet he borrowed from Kim Zetter without attribution.

Goes double for Alex Gibney

Re: Stuxnet Source Code

#120

What always impressed me about Stuxnet wasn't the technical complexity, but the amount of spycraft that must have gone into identifying exactly what to program it to do, and what they could get away with.

You don’t need to be a genius nor invest very deeply to figure out the technical details of introducing vibration into a high-speed centrifuge using SCADA (industrial automation protocol) in a barely noticeable way. As you suggest, tradecraft is the primary skill, jumping the air gap required an asset inside.
Post reply on HN