Live data from Hacker News

I think the military commissary's freezers were hacked

signalandsilence.substack.com

201–210 of 252 posts

Re: I think the military commissary's freezers were hacked

#201
post #94

Earlier quoted context omitted.

Did they airlift better supplies to a floating aircraft carrier somewhere in the northern Indian Ocean recently? No.

Aircraft carriers are not particularly well suited to be supplied by cargo aircraft. The largest cargo aircraft with the strengthened landing gear, arresting hook, and catapult attachment used to be the C-2 Greyhound. It had a range of approximately 1,500 miles with a 10,000 pound cargo. It was retired on July 28th, 2026. The C-2 has been replaced by the CMV-22B Osprey. It has a range of only 1,150 miles and a more l…

> It was retired on July 28th, 2026.

Why does it seem like the US always retires useful hardware and replaces it with less useful hardware?

The complete lack of frigates in the US navy is another example of this.

Re: I think the military commissary's freezers were hacked

#202
post #46

Earlier quoted context omitted.

My mind was blown when I realized that the way tftp works is that as the machine is booting it asks the network if anyone has some software for it to run.

Well, what else can it do, really? It has to boot with pretty much zero knowledge about the external world (maybe except asking the user for the current date and time). Sure, you can hardcode an outdated list of CAs (it's always outdated because the system can be booted 10/20/100 years after it was made) in but that just opens you to unexpected obsolescence, and you usually can't put too much stuff in the bootloader…

If we pretend we're revising TFTP boot in 1995, let's have it get up to 20 boot options from the server and their md5 hashes, and if it's not set to auto it waits for the user to pick one. It then verifies the hash as it downloads. Also it uses TCP for the download.

Re: I think the military commissary's freezers were hacked

#203
post #197

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

This points to either an inside job (a US gov agency that feels it needs to create urgency) or Iran (that has an urgent need to do something), since no serious adversary would use this capability in the absence of a theater.

Or criminals (perhaps ransom not paid etc) or Kiddies for the lolz or US teen lashing out or any of the gazillion nationalist-aligned hackers who don’t like USA.

But a misconfiguration is even more likely.

Can’t think _why_ freezers need to be web connected and remotely managed in the first place. What benefits does that bring the commissary in normal operation?

Re: I think the military commissary's freezers were hacked

#204

Earlier quoted context omitted.

Aircraft carriers are not particularly well suited to be supplied by cargo aircraft. The largest cargo aircraft with the strengthened landing gear, arresting hook, and catapult attachment used to be the C-2 Greyhound. It had a range of approximately 1,500 miles with a 10,000 pound cargo. It was retired on July 28th, 2026. The C-2 has been replaced by the CMV-22B Osprey. It has a range of only 1,150 miles and a more l…

> It was retired on July 28th, 2026. Why does it seem like the US always retires useful hardware and replaces it with less useful hardware? The complete lack of frigates in the US navy is another example of this.

Minesweepers?

Re: I think the military commissary's freezers were hacked

#206
post #197

Earlier quoted context omitted.

This points to either an inside job (a US gov agency that feels it needs to create urgency) or Iran (that has an urgent need to do something), since no serious adversary would use this capability in the absence of a theater.

Or criminals (perhaps ransom not paid etc) or Kiddies for the lolz or US teen lashing out or any of the gazillion nationalist-aligned hackers who don’t like USA. But a misconfiguration is even more likely. Can’t think _why_ freezers need to be web connected and remotely managed in the first place. What benefits does that bring the commissary in normal operation?

To try to guess at a plausible answer, any monitoring / remote management stemmed from wanting to keep an eye on temps over time. Freezers can go out of temp for only so long before its all bad.

Tada. It saves someone from making the rounds with a clipboard and writing down temps every X hours.

I agree its unneeded, just I can see the thought process.

Re: I think the military commissary's freezers were hacked

#207

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

No expert but mechanical parts all built to the same specification and used in more or less the same manner can fail around the same time.

We see that in commercial aviation a lot which is why when there’s so much as 2 instances of a similar failure within a short timespan investigators start looking more closely at maintenance and manufacturing.

Re: I think the military commissary's freezers were hacked

#208

Central unanswered question in the article on wich all the speculation rests: "If this were a cyberattack, why mess with freezers?" And yes, remember you can explain everyting by adding enough dimensions to a game of chess. But in reality? Seems the upside is near zero while the dowside is sacrifising your access.

[deleted]

Re: I think the military commissary's freezers were hacked

#209

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

Would a hostile state actor with access to basically a command and control network inside military bases ruin the food or stay quiet and try to use it to gain access to more interesting systems?

Re: I think the military commissary's freezers were hacked

#210
post #161

Earlier quoted context omitted.

> You'll notice that the aircraft carrier continues sortie generation. No, it doesn't. It's now in Thailand for R&R, then back to base in the US, because of this issue. https://apnews.com/article/thailand-singapore-us-aircraft-ca... > What's causing us to lose is failure to achieve victory due to the means employed… Right. We're being too restrained. That's some Vietnam War era cope you're huffing.

In the Vietnam war the US didn't win because it couldn't, no matter how much force was employed. Here same thing: we can't depose the Iranian government without a land invasion (which is too costly) and nothing else keeps them from having control of the strait.

Exactly, which makes this a stupid war to start in the first place.

Also, to be clear, a land invasion isn't "too costly". It's suicidal because we're talking about a massive country that has been preparing for decades, has a terrain advantage and literally more than a million fanatics ready to die for the regime. You'd need millions of soldiers deployed, and are looking at some Operation Downfall level expected losses.

Post reply on HN