Live data from Hacker News

I think the military commissary's freezers were hacked

signalandsilence.substack.com

111–120 of 252 posts

Re: I think the military commissary's freezers were hacked

#111
post #94
post #70

Earlier quoted context omitted.

Generally agree with your assessment, but in the case of Guam or other more remote installations if there were catastrophic issues we'd just airlift food in. Costly but certainly manageable. Hawaii I'm not sure why that would be an issue unless the whole island was attacked or shut down. Even if the on-base shops were hacked you could just go shop at Wal-Mart or Costco or any number of other locations on the islands.…

Did they airlift better supplies to a floating aircraft carrier somewhere in the northern Indian Ocean recently? No.

Surely airlifting supplies to a carrier in a war zone is not totally comparable to airlifting supplies to a base in a US territory?

Re: I think the military commissary's freezers were hacked

#112
Probably not, but my closest bet would fall to Hanlon's razor:

I was curious if this was continued evidence of poor appropriations and upkeep or what... I do see "U.S. military commissary refrigeration maintenance, equipment replacement, and physical infrastructure are funded through the 5% commissary surcharge paid by customers at checkout rather than direct congressional appropriations."

So, perhaps the first place would be to follow the money - are these being repaired at the proper rate? Is this repair outsourced to third party vendors? (my guess). Is this gonna end up being the McDonald's Ice Cream machine all over again?

Really though, Hanlon's would be much easier to believe this is yet further ineptitude by those who run things (I am not going to claim malfeasance/malevolence, except a general sense of such across the board by this admin).

Since I'm not on the inside, anything I have to say would be speculative, just like the above, or the author themselves (I have no idea who it is, and perhaps they have a better beat on the ground with regards to this), but it just falls in line with "we're running out of missiles" and "sailors attempting to kill themselves".

We're so insistent on being #1, we can't admit we're in a society that is falling apart (and again, it may be the case that this IS a hack, but if I were to place my bets...)

Ineptitude, lowest cost players, etc "efficiency" indeed. You get what you pay for, and I guess 5% don't pay for a whole hell of a lot these days.

Re: I think the military commissary's freezers were hacked

#113
post #111
post #94

Earlier quoted context omitted.

Did they airlift better supplies to a floating aircraft carrier somewhere in the northern Indian Ocean recently? No.

Surely airlifting supplies to a carrier in a war zone is not totally comparable to airlifting supplies to a base in a US territory?

There was supposed to be a base there.

The Fifth Fleet base in Bahrain got flattened.

Re: I think the military commissary's freezers were hacked

#114

Earlier quoted context omitted.

>They are usually on a separate Network. Then someone plugs in a cable because boss wants something "over there" and there's already a network that runs "over there". Or optimizes to a smart switch with vlans, and then someone else optimizes to a single vlan. It's not hard to not give a shit, or not understand, network security.

That someone can be brought into an office and shown a small diagram of the approved network topology. Then they can be shown a small diagram of the current network topology. Next, they can be asked if they're the same. If they're not, they can finally be asked if they're aware that deviating from the approved network topology without consulting infosec is grounds for termination of their employment.

You're assuming that it'll be noticed at all, and that the person noticing cares enough about it to make a big deal out of it - likely involving several layers of management.

In reality it'll likely first be noticed ten years down the line, by someone who lets out a big sigh, mutters something about "incompetent dipshits not updating documentation", and moves on with their day.

Re: I think the military commissary's freezers were hacked

#115
post #70

As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house: Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly. That said, the timing of the disclosure and the issue are rather concerning. Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overs…

Generally agree with your assessment, but in the case of Guam or other more remote installations if there were catastrophic issues we'd just airlift food in. Costly but certainly manageable. Hawaii I'm not sure why that would be an issue unless the whole island was attacked or shut down. Even if the on-base shops were hacked you could just go shop at Wal-Mart or Costco or any number of other locations on the islands.…

I didn't mean to imply that this would hit Hawai'i as hard as Guam, just that it would be one of the more effective places to hit with a DeCA supply chain attack.

Re: I think the military commissary's freezers were hacked

#116
First let's acknowledge that this could very easily be a misconfiguration issue.

But, I'd be a lot more inclined to that idea if it wasn't for how they failed: they started a defrost cycle that turned the freezers into heaters, spoiling the food quicker. And the failure happened overnight, delaying discovery of the problem.

It could be just a compounding of bad luck. But an attacker with access to the specs for the freezers might be aware of how long they would stay cold after being simply shut off.

Re: I think the military commissary's freezers were hacked

#117
post #107

Earlier quoted context omitted.

I'm not sure if you're speaking from personal experience, but most I've interacted with don't have to worry about the self-signed vs. LetsEncrypt debate. They just don't do it. Also there would be no way to do LetsEncrypt as the system is air gapped.

You can do DNS challenges for air gapped networks as long as the TXT records resolve publicly.

So then you have a signed CSR right? How would you get the certificate onto the box?

Re: I think the military commissary's freezers were hacked

#118

Earlier quoted context omitted.

That’s a tough question. If your PLC is on an airgapped LAN, admin/admin is not great security hygiene but you’ve reduced most of the risk by airgapping. On my project the service I wrote was doing bidirectional communication with the PLC over OPCUA. The server running this pod was connected to the internet, so it was critical to have proper TLS for the OPCUA client/server. Rotating LetsEncrypt certs on the system ev…

> admin/admin is not great security hygiene but you’ve reduced most of the risk by airgapping. admin/admin is on a post-it stuck to the monitor because everyone we hire is perfectly capable of rooting a machine they have physical access to.

Yeah, but deliberately rooting a machine you have no business touching means you are instantly getting fired.

Having an actual password prevents people "borrowing" a key to the equipment broom closet from "optimizing" some config values they really shouldn't be messing around with.

Re: I think the military commissary's freezers were hacked

#119

Howdy y’all, author here. Just discovered this thread after wondering why Hacker News was a linked views source to my silly little freezergate braindump. Wanted to offer a few clarifications: I’m not a cybersecurity expert; I’m an investigator (in a totally different field), and this was essentially me following a weird thought to see where it went. My background is in natsec so that’s where my mind goes. There have…

I came to these comments coz I was curious about the AI usage here, and FWIW I also thought it smelled AI written, but I didn't think it was slop. (IMO not all AI output is slop and not all slop comes from AI). My main question was "did Claude do the investigation by itself or just write up the article from someone's notes?" Also though, I'm quite willing to believe this is human written and the human just happens to…

Nope, I'm one of those lucky folks who was privileged enough to be accused of writing in a weird and probably too mature for my high school English paper-way before the advent of gpt, lol. I've had to all but remove the em-dash from my vernacular, thanks to the ~ plague of inauthenticity ~ as I call it.

I did all the digging, researching, writing, etc myself. The reason the screenshots are from mobile is because I wrote a lot of it literally in my notes app, on my phone before I started putting together more dots. I eventually asked gpt if I was correct in my understanding about refrigeration controllers doing XYZ and if it was plausible for them to be hacked in this way, when looking for some docs I asked if it would be standard to have XYZ part of a contract public and XYZ private, and other singular questions like that. I also use a browser extension for spellcheck that (I think) uses AI to suggest phrasing improvements, which I used pretty nominally.

Is there any type of sidebar/footnote that you, as a reader, would like to see to denote AI usage during the writing and/or research process? Would you expect none? I don't plan to do many investigations such as this (literally started because I was personally impacted) but I do have a few potential article seeds about defense procurement tech I've asked a few definition/research questions to AI about and would like to make sure I'm keeping tabs on it since this is something I want to be perhaps hyper aware of moving forward. Keeping in mind this is my personal substack and I would like to maintain integrity, but also, not doing really any groundbreaking work here. Intended to be an outlet for my thoughts, not news.

Re: I think the military commissary's freezers were hacked

#120
post #96

Howdy y’all, author here. Just discovered this thread after wondering why Hacker News was a linked views source to my silly little freezergate braindump. Wanted to offer a few clarifications: I’m not a cybersecurity expert; I’m an investigator (in a totally different field), and this was essentially me following a weird thought to see where it went. My background is in natsec so that’s where my mind goes. There have…

Hi, I'm the poster. Sorry for the unexpected attention! I saw this on Bluesky and thought it was interesting enough to share here. If anything the style of your writing makes it stand out in a good way, we shouldn't always have polished/corporate-speak posts here.

No apologies please, I'm flattered! I figured I should put the substack I made months ago to use and start putting some of my thoughts to paper (/keyboard) when it comes to my hyperfixation-of-the-week, instead of continuing to subject my friends to these rants. It's been an interesting few days.
Post reply on HN