Live data from Hacker News

German nuclear plant infected with computer viruses, operator says

reuters.com

81–90 of 101 posts

Re: German nuclear plant infected with computer viruses, operator says

#81
post #69

I found that part much more .. interesting: > As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit.

Yeah, it's sad that so many people actually use USB ports at airports to charge their devices, without knowing what they are connecting their devices to. I don't expect them to know better, but all their data could be copied, stuff could be modified. Isn't there an adapter which limits the active lines to just what's needed to pass power, no data, or is charging without some data exchange impossible?

Not a problem if you use iOS9: https://labsblog.f-secure.com/2015/09/09/apple-ios-9-securit... For Android, you can root it and disable USB host functions when locked.

Re: German nuclear plant infected with computer viruses, operator says

#82
post #65

Earlier quoted context omitted.

Or alternatively, how about WTF are you doing plugging your phone into this fucking cockpit? You're here to do your job and if you want to carry your phone around with you in the factory all day that's up to you, but plugging your phone into the fucking cockpit you're meant to be working on will result in demotions, suspensions and unemployment all round. More politely put, I see no obligation on employers to provide…

> More politely put, I see no obligation on employers to provide employees with the means to recharge their personal phones :) This is a classic "design a better human" problem - sure, you can try to 'persuade' people by threatening them with demotions, suspensions and unemployment. And then you can hope that this will work in every single instance. Or ... you can provide a few usb ports in a convenient location, so…

[deleted]

Re: German nuclear plant infected with computer viruses, operator says

#83
post #65

Earlier quoted context omitted.

Or alternatively, how about WTF are you doing plugging your phone into this fucking cockpit? You're here to do your job and if you want to carry your phone around with you in the factory all day that's up to you, but plugging your phone into the fucking cockpit you're meant to be working on will result in demotions, suspensions and unemployment all round. More politely put, I see no obligation on employers to provide…

> More politely put, I see no obligation on employers to provide employees with the means to recharge their personal phones :) This is a classic "design a better human" problem - sure, you can try to 'persuade' people by threatening them with demotions, suspensions and unemployment. And then you can hope that this will work in every single instance. Or ... you can provide a few usb ports in a convenient location, so…

They were working in a cockpit factory. They had many other options for charging their phone in a USB socket, and they still chose to charge it by plugging it into the cockpit. Your solution, in this situation, already existed and people still plugged phones into the cockpit.

Why would they NOT do this, under your system? If I can plug my phone in right where I am, in the cockpit, or somewhere less convenient for me, why would I not just do it where I am, in the cockpit? There are no penalties for it, so why wouldn't I do it?

Re: German nuclear plant infected with computer viruses, operator says

#84
post #67

We have to be more concerned about the things that are not reported. And why is it even technically possible to infect the control system of a power plant at all, or was this just a virus in some auxilliary sytem like, say, the machines only connected to another network, totally decoupled from the control system? Without details, this is just fear mongering on the heels of recent media outbreak regarding Belgian reac…

The article said the virus was on "a computer system retrofitted in 2008 with data visualization software associated with equipment for moving nuclear fuel rods".

Control systems generally have two components; the actual controllers that interface with the machine or equipment and then an HMI for the operator to interface with the controller (ignoring completely hard wired systems consisting of lights, buttons, chart recorders, etc). The majority of the HMI software runs on windows.

Once an attacker is on the HMI system they can probably easily do anything the operator can do, and possibly have full access to the controller and make things happen that Should Never Happen.

Re: German nuclear plant infected with computer viruses, operator says

#85
post #4

Earlier quoted context omitted.

The next sentence pretty much confirms my impression that this claim is almost certainly bullshit: > Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger. That's just...not how computers work.

Bullshit, I've watched Independence Day. You can easily take down advanced alien warships with some objective-c.

Was that really Objective-C?

Re: German nuclear plant infected with computer viruses, operator says

#86
post #56
post #4

Earlier quoted context omitted.

The next sentence pretty much confirms my impression that this claim is almost certainly bullshit: > Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger. That's just...not how computers work.

See the recent BadUSB attack [1][2] for how this sort of attack can work; the firmware of the USB microcontroller itself can be infected. [1] https://srlabs.de/badusb/ [2] http://www.wired.com/2014/07/usb-security/

Doesn't badusb have to pwn the host OS to propagate?

Re: German nuclear plant infected with computer viruses, operator says

#87
post #86
post #56

Earlier quoted context omitted.

See the recent BadUSB attack [1][2] for how this sort of attack can work; the firmware of the USB microcontroller itself can be infected. [1] https://srlabs.de/badusb/ [2] http://www.wired.com/2014/07/usb-security/

Doesn't badusb have to pwn the host OS to propagate?

Nope, and reinstalling it wont help it..

Re: German nuclear plant infected with computer viruses, operator says

#88

Earlier quoted context omitted.

Bullshit, I've watched Independence Day. You can easily take down advanced alien warships with some objective-c.

Was that really Objective-C?

Well it was on a mac laptop :)

Re: German nuclear plant infected with computer viruses, operator says

#90
post #68

Earlier quoted context omitted.

Yeah, totally agree. They also have aggressive print advertising everywhere (here in Munich) for this campaign. I wonder if they can attract any real talent though? Only people I know willingly wanted to work for the Bundeswehr eiter did not have the grades to study elsewhere or went to Afghanistan for the money.

I'm glad somebody joins them, though, or they would make up a law to legalize what drug cartels are doing with IT (and other) talent. Laws can be passed in parliament and be in use and need to go through trial at supreme court to be ruled invalid. I really wish passing laws was super had, super laborious, and took a very long time (at least 5 years). Then, the government, which needs to be reelected every 4 years, ca…

What are "drug cartels doing with IT talent"?
Post reply on HN