Live data from Hacker News

I think the military commissary's freezers were hacked

signalandsilence.substack.com

71–80 of 252 posts

Re: I think the military commissary's freezers were hacked

#71

A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising. I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on…

Most factories I know do not allow their PLC be accessed from the internet. They are usually on a separate Network. However, the "engineering" station (the computer running e.g. TIA Portal) sometimes is. The PLC engineers I had contact with usually had an electrical engineering background. That's why they like PLCs in the first place with the ladder logic programming languages, grafcet and if they feel fancy a bit of…

>They are usually on a separate Network.

Then someone plugs in a cable because boss wants something "over there" and there's already a network that runs "over there". Or optimizes to a smart switch with vlans, and then someone else optimizes to a single vlan. It's not hard to not give a shit, or not understand, network security.

Re: I think the military commissary's freezers were hacked

#72

"To be very clear: I do not have evidence that the Defense Commissary Agency was hacked." Should be much closer to the top of the article. Otherwise this is just weird and potentially dangerously wrong research.

what's with the pearl clutching?

Re: I think the military commissary's freezers were hacked

#74
post #12

Earlier quoted context omitted.

The bold text use make me think it was largely LLM-written. Maybe even LLM-researched.

I was getting hints of that as well.

Weirdly I felt like it got more LLM-y the further I got in. Then I hit the part with:

  But the thing I can’t get past is Fort Huachuca’s failure mode.
  
  Not: the freezer compressor died.
  
  Not: the power went out.
  
  Not even: the refrigeration system stopped cooling.
  
  Every freezer went into active defrost.

Re: I think the military commissary's freezers were hacked

#75

Earlier quoted context omitted.

>Generally, when a state actor has hacked something, they don't want the victim to know Could be the Iranians, or someone aligned, conducting anti-morale operations. Could be the start of a series of small but annoying failures.

Or could be a rouge LLM in one of the big labs, that accidentally self-prompt-injected itself with the title of that vulnerability research paper.

I suppose.

But if I was an Iranian operative with instructions to damage the morale of the American war machine, I'd absolutely do a series of things like this.

It doesn't really harm anyone, but enough similar events and the families of servicemembers start to feel unsafe, which is psychologically very different than the servicemembers themselves feeling unsafe.

It's probably more benign than that, most likely firmware or a central controller failure, but still

Re: I think the military commissary's freezers were hacked

#76

There's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers. We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people…

I would agree, but the freezers going into high heat defrost mode seems like an intentional action from someone, whether that be incompetence or malice on the side of DeCA, or malice from a third party. If they got rid of the people commanding the freezers what to do, I feel like they'd just stay on whatever mode they were already on, rather than suddenly command all the freezers to defrost

Defrosting is very often automatic. That can involve mechanical timers, or software timers, or logic/code of any complexity. All of these things can be badly-implemented and/or become broken or stuck.

Maybe the mode they got stuck on was defrost.

  if n>100 then defrost until y=3
If n is found to be greater than 100 and y subsequently never comes 'round to be 3, then defrost starts and runs forever.

Re: I think the military commissary's freezers were hacked

#77
post #32

Earlier quoted context omitted.

These are commissary fridges, not galley fridges.

Still troops, still dinner?

Often more like a tax-free cost-plus-5% grocery store that sells some of everything (including cat food), but yeah: Still troops, and some of that stuff might become dinner.

Re: I think the military commissary's freezers were hacked

#78
post #5

Welcome to the internet of shitty unsupported and insecure crap! Are we really this dumb as a society?

What's funny is that trump of all people is banning a lot of crap like this - internet connected chinese cars, internet connected solar panels, and other utility stuff.

But I fear the vested/wealthy interests involved in iot data mining, advertising, "relationship management" and plain "we own this"...

It (probably) prevents a comprehensive law supporting common sense.

Re: I think the military commissary's freezers were hacked

#80
post #77

Earlier quoted context omitted.

Still troops, still dinner?

Often more like a tax-free cost-plus-5% grocery store that sells some of everything (including cat food), but yeah: Still troops, and some of that stuff might become dinner.

Fair points.

"some of that stuff might become dinner" is splitting hairs, I feel.

Why? Because disruptions along the supply line are disruptions along the supply line. If a deep Russian ammo depot had a sudden smoking accident, you would (rightly) think it absurd for a Russian mil-blogger to quip that "technically we didn't lose ammo, the fuses are put in right before firing, we lost stuff that might become ammo." Seems less convincing now, right?

Maybe tonight's meal isn't disrupted, but the weekly meal planning is certainly disrupted. I hate to say it, but if the intent was an opportunistic hit to troop morale before a CVE got burned anyway, I'd say mission accomplished. :(

If this does turn out to be an attack, it's from decades of higher-ups ignoring cybersecurity coming home to roost.

Post reply on HN