Live data from Hacker News

US and Israel created Stuxnet, lost control of it

arstechnica.com

271–280 of 321 posts

Re: US and Israel created Stuxnet, lost control of it

#271
The fact that one of the most powerful nations in the world not only created one of the most notorious viruses in the world but lost control of it is madness. Its original purpose was to cause hardware to physically destroy itself. Imagine if, by sheer coincidence, the commands for that were the same as the commands for something like a nuclear reactor's cooling turbines? It's incredibly improbable but not impossible. That makes this a hugely dangerous and downright stupid occurrence. America shouts at Pakistan for losing control of its nukes and then develops, with a country that has some reputation for overkill (Israeli invasion of Gaza being a prime example), a dangerous weapon in software form, then doesn't pay attention to what the thing actually does? Where's the review process? How does something like the software being modified so it can infect and spread on common consumer systems so rapidly (I'm assuming that the modifications were to the way it spread, not sure) get missed? It's crass carelessness.

International espionage is half offence and half tact. It's not espionage if everyone finds out about it.

Re: US and Israel created Stuxnet, lost control of it

#272
post #249
post #207

Earlier quoted context omitted.

At one point special warfare was also considered taboo, now it is the U.S.'s bread and butter. Unfortunately while our nation recognized the need to develop our black ops capabilities early on, we are a bit late to the party when it comes to cyber-warfare. When it comes to international conflict, right and wrong are often subjective. Of course someone who is hostile towards the west is going to feel justified about h…

Taboo? Do you have a reference for that? I was always under the impression that the initial resistance to SO was from traditional generals in the pentagon who came up through the infantry and armored ranks...

You are correct. There was a lot of resistance from generals who were well versed in conventional warfare. Many of them thought that guerrilla warfare was either cowardly or somehow below us.

Richard Marcenko, the founder of the now defunct SEAL Team 6 (got transformed into the Developmental Warfare Group) discusses the attitudes he encountered throughout his navy career in some of his earlier novels. (he does write fiction now, but some of his earlier works were based on his life.) I know that he's an extremely controversial figure and that his writing ability is questionable, but he was both a SEAL and an officer at a time when the military was just starting to realize how significant a role that guerrilla warfare would play in future conflicts.

Re: US and Israel created Stuxnet, lost control of it

#273
post #207

Earlier quoted context omitted.

At one point special warfare was also considered taboo, now it is the U.S.'s bread and butter. Unfortunately while our nation recognized the need to develop our black ops capabilities early on, we are a bit late to the party when it comes to cyber-warfare. When it comes to international conflict, right and wrong are often subjective. Of course someone who is hostile towards the west is going to feel justified about h…

> Unfortunately while our nation recognized the need to develop our black ops capabilities early on, we are a bit late to the party when it comes to cyber-warfare. Out of curiosity, what makes you say this?

If there's one good example that our military underestimated the importance of cyber-security until recently, it is that the U.S. Army Cyber Command was just established in 2009. Before this happened, there was definitely work being done by the Army in this field, but it wasn't the large-scale, coordinated effort that such an important threat demands.

In the years leading up to the creation of the Cyber Command, there were many field grade officers who expressed the need for such a unit. These officers suggested that the military needed some sort of presence in cyberspace, mostly to ensure the safety of U.S. networks and partly to enable us to effectively respond to cyber-attacks around the world.

This article has a lot of good information about CYBERCOM.

http://en.wikipedia.org/wiki/United_States_Cyber_Command

Re: US and Israel created Stuxnet, lost control of it

#274
post #272
post #249

Earlier quoted context omitted.

Taboo? Do you have a reference for that? I was always under the impression that the initial resistance to SO was from traditional generals in the pentagon who came up through the infantry and armored ranks...

You are correct. There was a lot of resistance from generals who were well versed in conventional warfare. Many of them thought that guerrilla warfare was either cowardly or somehow below us. Richard Marcenko, the founder of the now defunct SEAL Team 6 (got transformed into the Developmental Warfare Group) discusses the attitudes he encountered throughout his navy career in some of his earlier novels. (he does write…

Given your knowledge of Marcinko's reputation I'm surprised you used him as your reference material. When Marcinko formed ST6 he selected the first members from an already existing specwar community. The same thing can be said for Beckwith and the creation of SFOD-D which predated ST6.

Re: US and Israel created Stuxnet, lost control of it

#275

Earlier quoted context omitted.

Not when you honestly believe in American Exceptionalism

Countries or terrorist groups rarely justify military action (even if it's cyberwarfare). At best, they explain it.

On the contrary--they often go to great lengths to justify it. The German invasions of Denmark, Norway, Belgium, and the Netherlands were deemed protective occupations, in order to prevent the Allies from invading them. The Gulf War was justified by a UN resolution. You can find some attempt, however feeble, to justify any recent military action.

Re: US and Israel created Stuxnet, lost control of it

#276

Earlier quoted context omitted.

You cannot effect much control over a signal that you cannot distinguish from random noise. There are so many factors that affect the likelihood of terrorism, and yet even in a bad year that likelihood is insignificant. Our ridiculously outsized counterterrorism efforts are akin to putting a shroud around the Earth to block out cosmic background radiation. It would cost more money than we can fathom, and in the end w…

It's equally hard to measure how much of a threat terrorism actually poses. One could easily make the argument that the reason it's perceived to be so little of a threat today is because we've gotten damn good at stopping terrorist plots. See the recently intercepted ALQ documents which describe how good the West has gotten at tracking their movements and foiling their plans.

There have been numerous terrorist attacks in the West since 9/11, in Israel (2002-), Madrid (2004, 2006), London (2005, 2007), and Moscow (2010, 2011).

Also, I grew up with several major terrorist attacks against the United States, in New York (1993), Oklahoma (1997), Africa (1998), against the USS Cole (2000), and finally 9/11.

The death toll from all these incidents barely breaks 4000. More people died last week of cancer.

Re: US and Israel created Stuxnet, lost control of it

#277

Earlier quoted context omitted.

Terrorist victims in 2001: 3,000 Murder victims in 2001: 15,000 Car collision fatalities in 2001: 42,000 Cancer deaths in 2001: 550,000 The only thing that's disproportionate is how we react to terrorism. (statistics are for United States)

Terrorist victims in 2001: 3,000 That's not entirely true. There were ~3000 terrorism-related deaths , but the point of terrorism is that it victimizes an entire society by creating a culture of fear and uncertainty. That's what differentiates terrorism from (conventional) murder.

To "create a culture of fear and uncertainty" is certainly the aim of terrorism. However, its effectiveness is dictated by the reaction of the affected population, not by the perpetrators or their actions.

Re: US and Israel created Stuxnet, lost control of it

#278
post #272
post #249

Earlier quoted context omitted.

Taboo? Do you have a reference for that? I was always under the impression that the initial resistance to SO was from traditional generals in the pentagon who came up through the infantry and armored ranks...

You are correct. There was a lot of resistance from generals who were well versed in conventional warfare. Many of them thought that guerrilla warfare was either cowardly or somehow below us. Richard Marcenko, the founder of the now defunct SEAL Team 6 (got transformed into the Developmental Warfare Group) discusses the attitudes he encountered throughout his navy career in some of his earlier novels. (he does write…

A lot of it varies from service to service. The Marine Corps was the last to develop special ops teams, under the doctrine that all Marines were capable of special operations. The smallest integrated Marine units, the MEU's, are all certified as "special operations capable", and are indeed capable of covert, small-unit action. One of the missions they're often tasked with is TRAP, "Tactical Recovery of Aircraft and Personnel". It was a Marine TRAP team that rescued downed F-16 pilot Scott O'Grady during the Bosnian war, for instance.

Ironically, it was the Marines who actually had some of the earlier predecessors to black ops, in the form of the Raider Battalions in the Second World War. One of the Raider Battalions was commanded by FDR's son, which protected the Raiders from political interference, at least until FDR died.

It's not exactly publicized, but my dad told me that the first Raider Battalion, at least, was even organized as a Maoist guerrilla unit; Samuel B. Griffith, its second commander, had previously served in China and spent a great deal of time with Mao. Among other things, the unit was run democratically.t My dad was acquainted with Griffith for a time, and I don't know how much of this is public information, or even accurate, but it's what he told me.

Re: US and Israel created Stuxnet, lost control of it

#279
post #170

"[Obama] repeatedly expressed concerns that any American acknowledgment that it was using cyberweapons—even under the most careful and limited circumstances—could enable other countries, terrorists or hackers to justify their own attacks. “We discussed the irony, more than once,” one of his aides said." "Irony" is the wrong word. It's "hypocrisy".

Ok, fine, it's hypocritical. There are worse things in the world than hypocrisy. I smoke cigarettes, yet I would advise others not to. I may be a hypocrit, but I'm not wrong. The two are not mutually exclusive.

Re: US and Israel created Stuxnet, lost control of it

#280
post #273

Earlier quoted context omitted.

> Unfortunately while our nation recognized the need to develop our black ops capabilities early on, we are a bit late to the party when it comes to cyber-warfare. Out of curiosity, what makes you say this?

If there's one good example that our military underestimated the importance of cyber-security until recently, it is that the U.S. Army Cyber Command was just established in 2009. Before this happened, there was definitely work being done by the Army in this field, but it wasn't the large-scale, coordinated effort that such an important threat demands. In the years leading up to the creation of the Cyber Command, ther…

I hope you realize that NSA, perhaps the biggest and most capable information security organizations in the world has always been under the Pentagon. It's absurd to suggest the US attention to data security started with the establishment of "Cyber Command".

My personal view is that it's a dangerous experiment in ineptitude allow the Pentagon to "defend in cyberspace" US networks. Most of the people who are tossing around such terms don't have the slightest clue what they're talking about.

It's one thing to say we're going to let the Pentagon use its procurement bucks to have defense contractors weaponize exploits in case the day arrives. But it's highly debatable whether allowing the military to get involved in US domestic networks is even legal.

Their ability to defend even their own networks for less than 10x the cost of the private sector is still an open question, much less whether or not they can defend anything having a wide diversity of traffic such as today's business and consumer internet.

Post reply on HN