Live data from Hacker News

US Emergency Alert System private SSH key mistakenly distributed

arstechnica.com

1–10 of 42 posts

Re: US Emergency Alert System private SSH key mistakenly distributed

#3
>Stations that use vulnerable gear should upgrade to version 2.0-2, which is available by sending an e-mail to _suport@digitalalertsystems.com.

Oh for fuck's sake. I hope Ars screwed up that email address. Sometimes I feel like regulatory capture has totally screwed our national defense.

I'm from Maryland. I know a lot of defense/NSA people. Some are fantastic. Others... let's just say not everybody is the best and brightest.

Re: US Emergency Alert System private SSH key mistakenly distributed

#6
post #5

National zombie attack alert... it's only a matter of time.

EAS has so many weaknesses, I'd actually qualify this as the least worrisome. The way we deploy any computerized equipment that is a part of our air-chain includes firewalls and only allowing connections to the necessary servers for CAP type alerts.

Every EAS receiver is typically monitoring other stations in the area for EAS relay. We actually have a tuner tuned to another station in the market and if we hear an EAS alert go across the air on their station we simply relay it. Due to the FM capture effect, it's _very_ easy to attack this channel; especially because there's _zero_ authentication on these incoming "relay" messages.

Even worse, some types of messages are setup for "national relay." This system was tested recently to ensure that a message could be relayed like this from one end of the country to the other -- and yes, it can. So, if you construct the right type of message, you can have it broadcast over _every_ station in america.

Re: US Emergency Alert System private SSH key mistakenly distributed

#7

>Stations that use vulnerable gear should upgrade to version 2.0-2, which is available by sending an e-mail to _suport@digitalalertsystems.com. Oh for fuck's sake. I hope Ars screwed up that email address. Sometimes I feel like regulatory capture has totally screwed our national defense. I'm from Maryland. I know a lot of defense/NSA people. Some are fantastic. Others... let's just say not everybody is the best and b…

"The best and the brightest" is such a strange phrase. Whenever I read it I always think of Halberstam and assume the author is using the phrase pejoratively.

Re: US Emergency Alert System private SSH key mistakenly distributed

#9
post #7

>Stations that use vulnerable gear should upgrade to version 2.0-2, which is available by sending an e-mail to _suport@digitalalertsystems.com. Oh for fuck's sake. I hope Ars screwed up that email address. Sometimes I feel like regulatory capture has totally screwed our national defense. I'm from Maryland. I know a lot of defense/NSA people. Some are fantastic. Others... let's just say not everybody is the best and b…

"The best and the brightest" is such a strange phrase. Whenever I read it I always think of Halberstam and assume the author is using the phrase pejoratively.

Yeah, I cannot help but hear that phrase sarcastically, sort of like "good enough for government work."

Re: US Emergency Alert System private SSH key mistakenly distributed

#10

>Stations that use vulnerable gear should upgrade to version 2.0-2, which is available by sending an e-mail to _suport@digitalalertsystems.com. Oh for fuck's sake. I hope Ars screwed up that email address. Sometimes I feel like regulatory capture has totally screwed our national defense. I'm from Maryland. I know a lot of defense/NSA people. Some are fantastic. Others... let's just say not everybody is the best and b…

Yeah, it looks like Ars messed it up: http://digitalalertsystems.com/contact.htm
Post reply on HN