Live data from Hacker News

The Stuxnet worm may be the most sophisticated software ever written

quora.com

141–150 of 507 posts

Re: The Stuxnet worm may be the most sophisticated software ever written

#141
post #54

And then people make a fuss about Russia "hacking" the election with some dumb Facebook ads which cost less than maxed out Ford Mustang. When on the other hand we have the state-sponsored military grade/purpose viruses used to attack other nations/regions (Flume attacked a large number of targets and countries) and nobody blinks an eye.

You mean how they hacked and leaked the personal emails of multiple people and organizations?

Like Watergate, but by a foreign actor.

Re: The Stuxnet worm may be the most sophisticated software ever written

#142

The scary thing about this is: Stuxnet is one of the "most sophisticated" pieces of malware we have discovered up until now . Who knows what kinds of software are still out there quietly doing their thing in the shadows.

"Russia has hacked into many of our government entities and domestic companies in the energy, nuclear, commercial facilities, water, aviation and critical manufacturing sectors" https://www.forbes.com/sites/jamesconca/2018/03/16/russia-ha... The same was also reported by MI5, Europol and of course within Ukraine.

And, no doubt, we (USA/Western democracies) have hacked theirs.

Re: The Stuxnet worm may be the most sophisticated software ever written

#143
post #72

Earlier quoted context omitted.

Think of controllers for say a dam, or an autopilot system in a jet.

How would either of these be worse than a nuke going off in Hong Kong or NYC?

If you took out a dam in Montana the following chain of dam failures would cut the United States in half all the way to the Gulf of Mexico and destroy US agricultural output. The US produces 40-50% of the world Soybean and Corn supply. Long term you're probably talking billions of deaths due to food shortages.

Re: The Stuxnet worm may be the most sophisticated software ever written

#144
post #134

> This driver was digitally signed by Realtek, which means that the authors of the worm were somehow able to break into the most secure location in a huge Taiwanese company, and steal the most secret key that this company owns, without Realtek finding out about it. > Later, whoever wrote that driver started signing it with secret keys from JMicron, another big Taiwanese company. Yet again, the authors had to figure o…

That's not how it works. You need the private key to sign the drivers. This is not a file that developers of those companies have access too. These keys are usually stored on a HSM. Even if you want to, you wouldn't be able to access the keys stored inside. This is specifically designed to protect against rogue/bribed personnel. So it's highly unlikely that the stuxnet developers had possession of the key. I'd bet th…

> I'd bet that they somehow had access to the HSM, to have it sign the driver for them.

Or were able to duplicate the HSM before it was delivered. You know, like how the NSA intercepted shipments of internet routers in transit and inserted backdoors.

Re: The Stuxnet worm may be the most sophisticated software ever written

#145
IMO, the sophistication of the final worm that made it out to security researchers doesn't have anything on the process that must have been used to develop it. Take the normal iterative development process, except that:

You don't know anything at all about the design of your targeted system and networks.

Even getting a little information about it requires writing sophisticated malware, using various spy capers to get the malware near the target systems, and somehow exfiltrating data from airgapped systems over the internet, where the whole mission is blown if anyone detects your data movement.

You may need dozens of iterations of adjusting the software to try and dive a little bit deeper, getting it snuck into the target systems (hopefully by a built-in update over the net), gathering information on the network architecture, then exfiltrating that data back out.

Always a tough balance of spread-happy enough to infect highly protected airgapped systems in a top-secret facility, but not so spread-happy to get out on the open net and infect half of the world, where it will inevitably be discovered eventually. This is probably where they eventually screwed up.

How long to detect that they're using this particular model of PLC with this particular centrifuge, buy your own copy of them, dig up someone who actually knows about these things, collaborate with them to figure out a sneaky way to screw things up just a little bit, build ways to get your virus onto the target system to do its damage, etc.

I'd assume that there was a team somewhere with a big library of zero-day exploits and a bunch of ace developers, but no starting knowledge of the target. Someone gave them the order to figure out a way to hack and screw up the Iranian nuclear program, maybe with the helper that some other org has a guy that can deliver any product near the program. They must have spent years devising ways to get in, slowly gathering info about their target, figuring out a way to achieve the assigned goal of screwing things up without getting detected. Now that would be a hell of a project to work on.

Re: The Stuxnet worm may be the most sophisticated software ever written

#146

I am just your average software dev with zero knowledge of malware creation, speculating here, and might come across as a fool. The author sensationalizes the effort of the creators, painting a Holywoodesque scenario where they break into every possible software company to steal keys to misrepresent the software, going undetected by every possible security company etc. Since this is a Quora post, I can live with him…

> The rest of it is all about asking the associated companies, politely, to cooperate.

What keeps this cooperation secret? It would only take one weak link at any one of those companies to reveal -- accidentally or otherwise -- that they were coerced into providing their signing keys. As soon as that got out, speculation runs amok: Are all products from said company compromised? This would be ruinous to a company, so no one in charge would agree to that without something significant -- which would be even harder to hide from the public -- in return. Then, who asked for the key and why? Could that be traced back to the (presumably) agency in question? That weak link was weak once, there's nothing to assume that he/she won't be weak again, etc., etc.

Re: The Stuxnet worm may be the most sophisticated software ever written

#147
If someone adds a layer to OS's file system such as only the know good white list app, exe, .so, .dll, .sys files with complete crypto-hash signatures are allowed to run in "lockdown" mode.

Everything else are reported and blocked.

Would it be enough to prevent such worm?

It would be interesting exercise to take an old exploitable OS (Win XP, or 10 years old Linux with known issue) add such layer to it. Put it on internet as honeypot and see what other kind of inflections it might get.

Re: The Stuxnet worm may be the most sophisticated software ever written

#148
post #134

> This driver was digitally signed by Realtek, which means that the authors of the worm were somehow able to break into the most secure location in a huge Taiwanese company, and steal the most secret key that this company owns, without Realtek finding out about it. > Later, whoever wrote that driver started signing it with secret keys from JMicron, another big Taiwanese company. Yet again, the authors had to figure o…

That's not how it works. You need the private key to sign the drivers. This is not a file that developers of those companies have access too. These keys are usually stored on a HSM. Even if you want to, you wouldn't be able to access the keys stored inside. This is specifically designed to protect against rogue/bribed personnel. So it's highly unlikely that the stuxnet developers had possession of the key. I'd bet th…

IDK, pre-windows-10 didn't you just need a ~$200 [1] code signing certificate? Do people usually buy HSMs to store those?

[1] https://www.sslshopper.com/microsoft-authenticode-certificat...

Re: The Stuxnet worm may be the most sophisticated software ever written

#149
post #58
post #27

Earlier quoted context omitted.

They mentioned they were Tawainese comapanies. I’d bet it was stolen rather than passed to them by some insider.

The hard part was writing the worm and getting it in to the facility, not getting in to Realtek's network. I would bet.

Didn’t the CIA drop USB sticks around the enrichment facility? I read that somewhere trying to find the source.

Re: The Stuxnet worm may be the most sophisticated software ever written

#150
post #103
post #54

And then people make a fuss about Russia "hacking" the election with some dumb Facebook ads which cost less than maxed out Ford Mustang. When on the other hand we have the state-sponsored military grade/purpose viruses used to attack other nations/regions (Flume attacked a large number of targets and countries) and nobody blinks an eye.

Those are indicative of the public’s enduring lack of technology literacy, and the media’s desire to have facts and eyeballs meet halfway. Media reports Russian election interference via digital ad spend, astroturfing, and infiltration attempts on state voting systems accurately, but the views to that reporting probably pale in comparison to the oversimplified, tweet-size “Russia hacked the 2016 US election” reportin…

To me the astro-turfing--which is still going on btw--is the most impressive/scariest part of the whole thing. It basically means there is a constant undercurrent of motivated Russian trolls tipping the scales of perception on every single news story, online poll, comments section, social platform, clickbait site, etc. It basically means that the internet is even more a reality distortion field than we imagined, and there is no real bottom. Imagine hooking up decent conversational AIs to do this, and scaling this all the way up to drown out the real conversation.
Post reply on HN