Live data from Hacker News

I think the military commissary's freezers were hacked

signalandsilence.substack.com

31–40 of 251 posts

Re: I think the military commissary's freezers were hacked

#32
post #17

There's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers. We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people…

To be fair, if you want to mess with your adversaries troop morale, screwing up dinner is pretty effective.

These are commissary fridges, not galley fridges.

Re: I think the military commissary's freezers were hacked

#33

A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising. I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on…

Isn't this the industry expectation in that kind of equipment? If it was signed by a real CA the cert. could expire and render the equipment unable to communicate.

Re: I think the military commissary's freezers were hacked

#34

I would suspect a firmware bug. Or a "Service Required" timer that was ignored.

I'm in the firmware bug camp too. Over/under on "the remote management server went down and a bug on all the freezers decided to put them back into some form of local control where its first action was to do a defrost cycle then put it back into offline service"?

Re: I think the military commissary's freezers were hacked

#35
post #20

Earlier quoted context omitted.

The article has a post that says this happened across 14 bases at the same time.

So what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.

> I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.

according to the article, the denominator is ~235.

Re: I think the military commissary's freezers were hacked

#36

A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising. I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on…

[dead]

Re: I think the military commissary's freezers were hacked

#37

A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising. I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on…

Most factories I know do not allow their PLC be accessed from the internet. They are usually on a separate Network. However, the "engineering" station (the computer running e.g. TIA Portal) sometimes is.

The PLC engineers I had contact with usually had an electrical engineering background. That's why they like PLCs in the first place with the ladder logic programming languages, grafcet and if they feel fancy a bit of structured text (assembly like) or structured control language (pascal like). They indeed did not know much about software security but a great deal about machine safety.

A real security nightmare are older OPC servers (OPC-DA) which is super reliant on DCOM. OPC is quite important to connect the PLCs to SCADA systems or 3rd party devices.

Re: I think the military commissary's freezers were hacked

#38

A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising. I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on…

Isn't this the industry expectation in that kind of equipment? If it was signed by a real CA the cert. could expire and render the equipment unable to communicate.

also you can't pin the user/pw to the machine with a note, because someone might need remote access. better stick with admin/admin

Re: I think the military commissary's freezers were hacked

#39

I'm waiting for the OpenAI report that their agents defrosted everything.

It'll take them two weeks and then they'll find the systems were hacked half a year ago and they had industrial robots write messages on a literal chalkboard in order to share progress.

Re: I think the military commissary's freezers were hacked

#40

Earlier quoted context omitted.

So what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.

OTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about. Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late. All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusu…

And how many shipboard stores have been affected? Hardly something they’re going to talk about, and a far stronger candidate for attack. This could be spillover.
Post reply on HN