Live data from Hacker News

I think the military commissary's freezers were hacked

signalandsilence.substack.com

191–200 of 252 posts

Re: I think the military commissary's freezers were hacked

#191
post #188

Earlier quoted context omitted.

Yes? “one of us made a mistake” vs “someone is attacking us” is a difference that people care about.

Not only care about; a mistake is unlikely to be repeated, a motivated attack is very likely to be attempted again.

> a mistake is unlikely to be repeated

If it was a mistake, it happened at many facilities. That seems like a repeated mistake to me.

Re: I think the military commissary's freezers were hacked

#192

Earlier quoted context omitted.

>Generally, when a state actor has hacked something, they don't want the victim to know Could be the Iranians, or someone aligned, conducting anti-morale operations. Could be the start of a series of small but annoying failures.

Or could be a rouge LLM in one of the big labs, that accidentally self-prompt-injected itself with the title of that vulnerability research paper.

Why would an LLM wear makeup?

Re: I think the military commissary's freezers were hacked

#193

There's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers. We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people…

A quick check says this contract has been in place since 2020.

The internet security practices I experienced when working with the DOD in a prior life were…interesting?

Outside of the classified realm, there seemed to be little to no on the ground understanding of the Internet. Many things where internet connected that shouldn’t be or weren’t that should. I was involved in one contract where we had to demonstrate the ability to remotely access and control a system (to satisfy the system’s owner) as well as demonstrate that the system could not be remotely accessed via the internet (to satisfy the base IT folks). The solution was a hotspot kept in a lock box…that I doubt was ever locked after we left because it was constantly attached to our internal monitoring network despite our pleas.

Re: I think the military commissary's freezers were hacked

#194

The author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems? Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something li…

At the same time, I think some people in this comment section are underestimating the likelihood that this was a hack, because they're overestimating how sophisticated such a hack would have to be.

In my mind, if this was a hack, it was probably not a Stuxnet virus or something. These are smart fridges we're talking about - someone probably just logged into them using leaked credentials or a Web app vuln, and turned them off.

Re: I think the military commissary's freezers were hacked

#195
Central unanswered question in the article on wich all the speculation rests: "If this were a cyberattack, why mess with freezers?"

And yes, remember you can explain everyting by adding enough dimensions to a game of chess. But in reality? Seems the upside is near zero while the dowside is sacrifising your access.

Re: I think the military commissary's freezers were hacked

#196
post #179

Earlier quoted context omitted.

They hit back on 9/11 and it caused a panic that is still ongoing.

I'm no shill for the US, but that's a hot take that's too simplistic by far. Eg who armed the Mujahideen?

The USA, to fight the democratically elected government of afghanistan.

Re: I think the military commissary's freezers were hacked

#197

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

This points to either an inside job (a US gov agency that feels it needs to create urgency) or Iran (that has an urgent need to do something), since no serious adversary would use this capability in the absence of a theater.

Re: I think the military commissary's freezers were hacked

#198
post #178

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

In any cases, it is a strong evidence that the freezer can be remotely controlled globally, and this is in itself a source of concerns (what other electrical equipment can be controlled remotely, especially on such critical features?)

> it is a strong evidence that the freezer can be remotely controlled globally

As per the article that's literally a selling feature

Re: I think the military commissary's freezers were hacked

#199

Central unanswered question in the article on wich all the speculation rests: "If this were a cyberattack, why mess with freezers?" And yes, remember you can explain everyting by adding enough dimensions to a game of chess. But in reality? Seems the upside is near zero while the dowside is sacrifising your access.

If we're actually talking about a hack, there's no particular reason to believe it was done by an APT who would like to retain access.

Maybe a kid just wanted to do it for fun? Maybe a smaller hacking group who would just like to make a statement against fascist/imperialist USA is happy to just cost them a few million dollars with a few network packets?

Re: I think the military commissary's freezers were hacked

#200
This is the dumbest thing I've ever heard of. The only reason I can conceive to really need network connectivity is to monitor temp, and there's zero reason to have that hooked into power, on/off, whatever.

Having remote on/off capability, or even the ability to set temperatures for freezers remotely is just so insanely idiotic, I don't get it. Why even have the path? If the temp is wrong, go investigate.

This is such a colossal non-problem. The risk is now, at the start of a war action base supplies could be made unusable.

One of the big current risk scenarios is, all smart cars, all meat packing plants, all industrial capacity, all phones, all internet, all interrupted at precisely the same time. A multi-pronged hack, right at the start of the war.

Imagine all electric cars bursting it flames in garages as they charge overnight. Conjoined with all cell phones, network connectivity, and landlines going out. And 911 call centres.

So now you have a fire raging, the fire department doesn't even know, and if it wanted to respond? There's 4 fires on every suburban block.

Within a few hours, a large portion of the populous now has no housing.

That's just from two simple hacks, communication and electric cars.

The society of always-on-connected is just dumb, stupid, insane, and has threat-results worse than some nuclear exchange scenarios.

And there will never, ever, ever be secure software. Ever. Never going to happen, ever. No rust, no this or that, no AI help, will ever, ever, ever secure software. Ever.

And how do I know this?

Because 50 years later, I've seen software just as buggy, insecure, as it always has. Anyone thinking "oh, we can just do this thing! And then software will be safe" is a loon, it'll never ever happen.

And that means?

Nothing important should ever be network connected, ever.

So why would any yahoo think remote control capacity on a freezer is sane?

Post reply on HN