Live data from Hacker News

Stuxnet's Secret Twin

foreignpolicy.com

21–30 of 61 posts

Re: Stuxnet's Secret Twin

#21

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

[deleted]

Re: Stuxnet's Secret Twin

#23

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

That's because a lot of industrial "control" is still done via classic OPC [1] for communication. That's Microsoft DCOM. I kid you not!!

And afaik they didn't have internet access directly for the control boxes at Natanz. Stuxnet got into the plant via USB sticks.

[1] http://en.wikipedia.org/wiki/OLE_for_process_control

Re: Stuxnet's Secret Twin

#24

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

someone should have told the iranians that linux computers have no security vulnerabilities

Re: Stuxnet's Secret Twin

#25
post #24

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

someone should have told the iranians that linux computers have no security vulnerabilities

They are seriously less insecure by design than Windows.

http://philosecurity.org/2009/01/12/interview-with-an-adware...

Don't tell me you aren't familiar with this.

Re: Stuxnet's Secret Twin

#26

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

I have a little experience in industrial control systems. Near as I can tell, both support and demand in the industry for controlling these devices with anything but Windows XP is basically nonexistent. Support for Windows 7 seems half-hearted at best, even now, when XP is nearly EOL. The package I have used the most, GE iFix, is so tightly tied in with Microsoft technologies, including OPC, DCOM, VBA, and ActiveX, that it's tough to imagine a port to anything else happening anytime soon. If you're interested in the industry, look up info on this, and stuff like Wonderware.

Most of the people working on these devices are far from being computer experts. I went to an advanced class for them, where the instructor took pains to advise the class that it was an advanced class and you would probably be lost if you hadn't taken the beginner class. I hadn't, and I breezed right through all of their material. Not that I'm that much smarter than anyone there, just from having experience using and figuring out a lot of different types of computer systems. This type of software is made for people who are experts in stuff like chemical plant operations, but who think Excel would be a great way to program their control systems. I'd bet that not one of them have even heard of the Nataz attack.

Given the total lack of interest or experience in computer security that seems to be prevalent in the industry, I expect it will get a lot worse before it gets better.

Re: Stuxnet's Secret Twin

#27

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

If a government entity was willing to pay for 0-day exploits to target a specific system and infrastructure I don't think it really mattered what OS was behind the controllers since they'd be building the super-virus to the needs of the assignment.

Re: Stuxnet's Secret Twin

#28
post #23

Serious question: Why THE FUCK are industrial controllers connected to the Internet still running Windows? What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...

That's because a lot of industrial "control" is still done via classic OPC [1] for communication. That's Microsoft DCOM. I kid you not!! And afaik they didn't have internet access directly for the control boxes at Natanz. Stuxnet got into the plant via USB sticks. [1] http://en.wikipedia.org/wiki/OLE_for_process_control

Oh god, DCOM memories. I've spent days in a futile attempt to get that working. The best demo of how bad DCOM is would be the existence of OPC Tunneler:

http://www.matrikonopc.com/products/opc-data-management/opc-...

DCOM is such a headache that these guys sell a $1000 program whose sole purpose is to make it easy to make remote DCOM connections. And I've recommended it as a screaming deal at that price. Given what it costs to get myself or a proper tech to a remote site for a day, I'd much rather use that and spend my time solving the actual problem than spend a day trying to get DCOM working before working on the actual problem.

Re: Stuxnet's Secret Twin

#29
post #12

This is incredibly interesting and extremely important. It has clear implications for infrastructure and security, particularly energy infrastructure which I am most interested in. This is the future of war.

My Dad used to write software for large technology companies. When he was with Control Data, they had just finished a huge project where they automated a ton of processed for the local energy company to make it more efficient.

When I was in college and the internet got big I and I was touting all this cool stuff you could do, he told me about this project they did way back in the 70's. He said it terrified him at the time because it took the human element out of the equation. If something went wrong, it could do some serious damage. A misplaced decimal point here and it could basically bring down an entire region of the power grid.

He always said the software was great, but it made the people using it lazy - which is where the real danger is.

Re: Stuxnet's Secret Twin

#30
post #5

Try this link if you get hit with registration: https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&c...

that one requires registration as well.

1. right-click paywall

2. "inspect element"

3. right-click highlighted html

4. "delete node"

5. ???

6. profit

Post reply on HN