I'd argue that Google Search is much more sophisticated than Stuxnet. Windows is much more sophisticated. Linux is more sophisticated than Stuxnet. The list goes on. We tend to ignore the sophistication of things we are familiar with, and hype those that surprise. But that's not a fair measure of anything.
The Stuxnet worm may be the most sophisticated software ever written
311–320 of 507 posts
Re: The Stuxnet worm may be the most sophisticated software ever written
#312Earlier quoted context omitted.
Without any kind of metric for “sophisticated” it’s all subjective anyhow. I like Stuxnet as an example - it’s devious and a true hacker approach, albeit as blackhat as they come.
i think for something to be sophisticated we are looking at how complex it is. this worm does nothing new in that regard (taking advantage of 0days, hiding, covering tracks etc.) it is no more sophisticated than a regular worm. quora is a fucking joke.
If we can just capture that essence, we will wield the power of sophistication in our hands.
Re: The Stuxnet worm may be the most sophisticated software ever written
#313I'd argue that Google Search is much more sophisticated than Stuxnet. Windows is much more sophisticated. Linux is more sophisticated than Stuxnet. The list goes on. We tend to ignore the sophistication of things we are familiar with, and hype those that surprise. But that's not a fair measure of anything.
For example - it might take years of research to develop a formula for calculating something, but the final code can be very simple one-liner.
Re: The Stuxnet worm may be the most sophisticated software ever written
#314I've been arguing about this for the last three days. Mostly around the reason that "complexity" is not strictly the same thing as "sophistication" when it comes to software. Noobs will conflate the two, but experienced programmers will agree that -- just to illustrate my point -- some code which solves a complex problem in a very clever way while also being very clean and easy to maintain will be considered strictly…
Yes, in my experience, solving a problem / feature well involves three steps: 1. Get the code to work 2. Clean up the code 3. Simplify the code 1 is self explanatory. 2 involves removing any logical redundancy, separating and cleaning the logic into methods, etc. 3 involves simplifying logic and logical mechanisms. Most developers only do step 1 and maybe step 2. Step 3 is where beauty comes in. If I could organize m…
Re: The Stuxnet worm may be the most sophisticated software ever written
#315I'd argue that Google Search is much more sophisticated than Stuxnet. Windows is much more sophisticated. Linux is more sophisticated than Stuxnet. The list goes on. We tend to ignore the sophistication of things we are familiar with, and hype those that surprise. But that's not a fair measure of anything.
In my view, the sophistication is implied by the breadth of expertise required to put the whole thing together. Google Search and the OS landscape are for sure broad and sophisticated. However, their development was accomplished by computer scientists. In order for stuxnet to be effective, it was necessary to employ expertise in: - Uranium enrichment methods and processes - Capital equipment control systems and their…
I think this understates it; it required a deeper understanding of the vulnerabilities of those operating systems than anyone else in the world, including the creators of the operating systems
Re: The Stuxnet worm may be the most sophisticated software ever written
#316Earlier quoted context omitted.
Try not to think about how many SREs in the big five are likely receiving a second secret paycheck from Langley and/or Fort Meade.
Interesting. This is the first time I've seen a public comment anywhere about a strong suspicion I've held for more than 20 years.
Re: The Stuxnet worm may be the most sophisticated software ever written
#3171: What is sophisticated for a non-state actor may be semi-trivial for a state actor. Why? State actors demand access to the source code of proprietary software; state actors circumvent laws that bind mere mortals like ourselves. If you own the playing field that which is sophisticated for even the most competent and knowledgeable coders may be semi-trivial for the spooks. 2: In my opinion Stuxnet is an act of war. I…
> State actors demand access to the source code of proprietary software So, when China or Russia are building windows exploits, they just demand Microsoft hand over source? Also, the idea that “locked down” Linux would do any better than windows is ridiculous. The Linux codebase is enormous and complex and full of bugs. At least if you’d said some type of high security microkernel, you could put forward forward some…
Yes in fact they do. https://download.microsoft.com/download/B/C/A/BCAFF3F5-5DB5-...
“Throughout the history of the company, Microsoft has worked with national governments around the world to help them build and deploy more secure IT infrastructure and services to protect their citizens and national economies. In 2003, Microsoft built on these efforts to create the Government Security Program (GSP). The scope of the program has grown over time, and continues as a cornerstone of Microsoft’s efforts to help address the unique security requirements of more than 30 national governments around the world.” (Russia and China included) https://www.zdnet.com/article/does-microsofts-sharing-of-sou...
> Also, the idea that “locked down” Linux would do any better than windows is ridiculous. The Linux codebase is enormous and complex and full of bugs. At least if you’d said some type of high security microkernel, you could put forward forward some logical arguments.
It's not a `logical' argument, it's a pragmatic argument. A sufficiently tech-savvy admin can dictate the hardware on the network, roll their own kernel so that USB drivers cannot be loaded, have that image as the boot image, and use TPM if totally necessary. The reason you wouldn't want to run a high security microkernel is because those can't run regular desktop software like LibreOffice and what have you.
Re: The Stuxnet worm may be the most sophisticated software ever written
#318Earlier quoted context omitted.
Actually, in a capitalist country it might be easier to survive such an attack. If there is demand for a product or service, people and businesses will find a way to meet that demand. Millions of people working independently to satisfy their local market demand. It would probably hurt centralized socialist or communist countries more since it severs their control, surveillance, and communication mechanisms.
I agree that markets tend to buffer the effects significantly. The problem is in times of crisis, the appreciation of market dynamics and rule of law tend to wane. Even if those things are intact, the flow of goods and services can be undermined by well-intentioned but misguided politicians. My point was simple. Despite the systems of trade, a catastrophic shock in trade or production systems could literally kill mil…
Systems have trade have made the market economy of the US more vulnerable to many kinds of "a catastrophic shock[s] in trade or production systems." IIRC, there are only a few days of slack in the US food supply chain. That's down from a month or two during the cold war (where I think there were mandates for reserves).
Re: The Stuxnet worm may be the most sophisticated software ever written
#319Earlier quoted context omitted.
But do those things really contribute to the sophistication of the software? For example imagine some code written with no understanding of uranium enrichment: const int CENTRIFUGE_RPM = 500; And then some other code written with a deep understanding of uranium enrichment: const int CENTRIFUGE_RPM = 1203; Can you really say that the second bit of code is more "complex"? Same goes for stolen driver signing keys and so…
The second piece of code is not more complex, but it is (presumably) a lot more sophisticated. The fact that I had to prefix that with "(presumably)"—i.e. I can't actually tell using my own expertise—is evidence of that.
Of course if the sophistication is more about what they needed to know in order to break the things (and make that code change), then talking about this subsystem by itself that's either way lower or roughly the same as what they'd need to know to build and operate their own centrifuges. Much less, if they only needed to focus on one part of the process (motor control) that would cause problems (which might just be a brief consultant call with our own nuclear physicists and engineers, I don't know, nuclear science details seem as mysterious to me as high level language details might to impoverished programmers), or about the same, if they knew everything the Iranians knew about the systems (did we ever find out if they got all the blueprints and so forth and built replicas for end-to-end testing?) plus a bit extra on how and where to make it break without easily being detected.
Anyway how sophisticated can they really be when they didn't even use source control? (Old joke... https://news.ycombinator.com/item?id=4052597)
Re: The Stuxnet worm may be the most sophisticated software ever written
#320Earlier quoted context omitted.
MAD is a local maximum of peace, but only if we define "peace" to include "tense standoff". It appears to be the best we can do in the presence of overwhelmingly powerful offensive capabilities. Imagine the different "peace" if instead we had overwhelmingly powerful defensive capabilities.
But everyone would have to have those, or else the first country to develop them would have an insurmountable advantage. A country that has both nuclear weapons and the ability to block all attacks including nuclear would rule the world, or at least dominate it without opposition.
I'm thinking along the lines of grey-hat anarchists constantly attacking everyone's nuclear capabilities. "If nobody is super, everybody is super."