Live data from Hacker News

I think the military commissary's freezers were hacked

signalandsilence.substack.com

101–110 of 252 posts

Re: I think the military commissary's freezers were hacked

#101
post #94
post #70

Earlier quoted context omitted.

Generally agree with your assessment, but in the case of Guam or other more remote installations if there were catastrophic issues we'd just airlift food in. Costly but certainly manageable. Hawaii I'm not sure why that would be an issue unless the whole island was attacked or shut down. Even if the on-base shops were hacked you could just go shop at Wal-Mart or Costco or any number of other locations on the islands.…

Did they airlift better supplies to a floating aircraft carrier somewhere in the northern Indian Ocean recently? No.

[flagged]

Re: I think the military commissary's freezers were hacked

#102
post #77

Earlier quoted context omitted.

Often more like a tax-free cost-plus-5% grocery store that sells some of everything (including cat food), but yeah: Still troops, and some of that stuff might become dinner.

Fair points. "some of that stuff might become dinner" is splitting hairs, I feel. Why? Because disruptions along the supply line are disruptions along the supply line. If a deep Russian ammo depot had a sudden smoking accident, you would (rightly) think it absurd for a Russian mil-blogger to quip that "technically we didn't lose ammo, the fuses are put in right before firing, we lost stuff that might become ammo ." S…

> Maybe tonight's meal isn't disrupted, but the weekly meal planning is certainly disrupted.

This appears to be happening stateside, and most, if not all, of the listed bases have nearby grocery stores (I'm saying most based on the ones I recognize and know where they are, I didn't look up the rest). This is an annoyance, not a massive disruption.

Honestly, it probably creates more disruption for the retirees in the areas around the bases than it does the local active duty members.

Re: I think the military commissary's freezers were hacked

#103

Earlier quoted context omitted.

That’s a tough question. If your PLC is on an airgapped LAN, admin/admin is not great security hygiene but you’ve reduced most of the risk by airgapping. On my project the service I wrote was doing bidirectional communication with the PLC over OPCUA. The server running this pod was connected to the internet, so it was critical to have proper TLS for the OPCUA client/server. Rotating LetsEncrypt certs on the system ev…

> Rotating LetsEncrypt certs on the system every 45 days is a lot of toil What is unique about your system using LetsEncrypt that you can't automate certbot to handle this task as it was designed and intended to be done?

On an airgapped system that is is turned on once and needs to keep running for many, many years? Industrial equipment is a world of its own and internet best practices just don't transfer directly.

Some PLCs run extremely expensive machines. Some machines can't afford to have their control systems stutter or fail because that can lead to physical damage and production outages of enormous proportions. A PLC that stops communicating because a certificate just expired is absolutely not acceptable in some plants.

Re: I think the military commissary's freezers were hacked

#104
post #43

To summarize for people who TLDR: 14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability . They all failed by turning on the defrost cycle and heating food. Regardless if this was a hack or a bug, the bigger lesson is that overcomplicated systems fail in catastrophic ways. Why do military commissaries need remote-controlled freezers? It…

Iran is actively looking for ways to attack back against the United States especially against military targets without actually escalating the situation.

I'm sure some script kiddie broke into a government network, hacked an industrial process, and forced a limited supply piece of equipment into a failure mode that takes some thought and is more unique as an attack vector. It's just like buying hacks for CS source right?

Re: I think the military commissary's freezers were hacked

#105
post #77

Earlier quoted context omitted.

Often more like a tax-free cost-plus-5% grocery store that sells some of everything (including cat food), but yeah: Still troops, and some of that stuff might become dinner.

Fair points. "some of that stuff might become dinner" is splitting hairs, I feel. Why? Because disruptions along the supply line are disruptions along the supply line. If a deep Russian ammo depot had a sudden smoking accident, you would (rightly) think it absurd for a Russian mil-blogger to quip that "technically we didn't lose ammo, the fuses are put in right before firing, we lost stuff that might become ammo ." S…

I'm not splitting hairs. I'm just tryin' to talk about the commissary's role. :)

I agree that it is an important role that would be worthy of disruption for a motivated attacker.

But also: These things aren't usually at the center of vast food deserts. There's typically other ways to find some grub, like the Wal-Mart right over there.

Re: I think the military commissary's freezers were hacked

#106
post #45

I would suspect a firmware bug. Or a "Service Required" timer that was ignored.

Yeah I don't know why "hack" is more obvious than this. Central control pushes an update, it bugs out and cooks a dozen commissaries' frozen foods. Smart hack would be to do this randomly and fly under the radar.

If you are a country currently in a weird war like situation looking for ways to make your opponent look foolish without escalating militarily, this seems like an amazing avenue.

I'm guessing Iran will claim it as an attack even if it doesn't end up being them in the end.

Re: I think the military commissary's freezers were hacked

#107

Earlier quoted context omitted.

That’s a tough question. If your PLC is on an airgapped LAN, admin/admin is not great security hygiene but you’ve reduced most of the risk by airgapping. On my project the service I wrote was doing bidirectional communication with the PLC over OPCUA. The server running this pod was connected to the internet, so it was critical to have proper TLS for the OPCUA client/server. Rotating LetsEncrypt certs on the system ev…

I'm not sure if you're speaking from personal experience, but most I've interacted with don't have to worry about the self-signed vs. LetsEncrypt debate. They just don't do it. Also there would be no way to do LetsEncrypt as the system is air gapped.

You can do DNS challenges for air gapped networks as long as the TXT records resolve publicly.

Re: I think the military commissary's freezers were hacked

#108

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

[dead]

Re: I think the military commissary's freezers were hacked

#109
post #32
post #17

Earlier quoted context omitted.

To be fair, if you want to mess with your adversaries troop morale, screwing up dinner is pretty effective.

These are commissary fridges, not galley fridges.

Sorry, forgot '/its-a-joke-not-a-legal-filing'.

Re: I think the military commissary's freezers were hacked

#110

Howdy y’all, author here. Just discovered this thread after wondering why Hacker News was a linked views source to my silly little freezergate braindump. Wanted to offer a few clarifications: I’m not a cybersecurity expert; I’m an investigator (in a totally different field), and this was essentially me following a weird thought to see where it went. My background is in natsec so that’s where my mind goes. There have…

I came to these comments coz I was curious about the AI usage here, and FWIW I also thought it smelled AI written, but I didn't think it was slop. (IMO not all AI output is slop and not all slop comes from AI).

My main question was "did Claude do the investigation by itself or just write up the article from someone's notes?"

Also though, I'm quite willing to believe this is human written and the human just happens to have a Claudey style. The actual prose isn't that Claudey it's just the structure of how it presents ideas. But, Claude had to get that structure from somewhere. It's not that surprising to see people with that style of communication.

Post reply on HN