Page 1 of 2 12 LastLast
Results 1 to 30 of 52

Thread: stuxnet vs Iran

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1

    Default stuxnet vs Iran

    arstechnica.com/tech-policy/news/2010/11/clues-suggest-stuxnet-virus-was-built-for-subtle-nuclear-sabotage.ars

    summary: stuxnet may have been designed to sabotage iranian nuclear power plants. is this true? is it okay? if a nation is responsible, should it be uncovered and held responsible, given that it affected a lot of computers besides those in Iranian nuclear power-plants?
    "One day, we shall die. All the other days, we shall live."

  2. #2
    Its not ok and this sort of thing is not going to stop even if you call out *cough* Israel. From what I've heard on the topic, this bit of code is pretty ground breaking and likely will be used as a basis by all sorts of bad actors for future malware. Nice.
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  3. #3
    Quote Originally Posted by EyeKhan View Post
    likely will be used as a basis by all sorts of bad actors for future malware. Nice.
    A malicious computer attack that appears to target Iran's nuclear plants can be modified to wreak havoc on industrial control systems around the world, and represents the most dire cyberthreat known to industry, government officials and experts said Wednesday.
    http://news.yahoo.com/s/ap/20101117/..._cyber_threats

  4. #4
    Reddit has been talking about this for months. Once they discovered it wasn't meant to target personal machines people started understanding just how insanely advanced the code was. If I'm not mistaken, Iran had previously asked for outside help in removing the threat, it was that bad. Its mentioned in one of kat's threads too.

    You will likely never be able to pin this on a nation. Maybe a group within a nation, but thats it. Just like China IPs taking down the Nobel Peace Prize site after Liu Xiaobao won the award, an award China was very much aganist him winning.

    Just like Operation Payback is hitting MPAA/RIAA, anti-piracy groups, lawyers and lobbyists all over the world, but is mostly US based.

    Or when Google accussed China of hacking into their Gmail service. Google even throws up login warnings now when IP addresses from that country attempt to log in to gmail accounts, instead of listing the last login locations (at the bottom on the scene) like they've always done.
    Last edited by Ominous Gamer; 11-16-2010 at 03:24 PM.

  5. #5
    Yeah, Minx, this is super old. That being said, it's my understanding that the code isn't advanced or ground breaking so much as expensive - it takes advantage of multiple separate vulnerabilities in the systems they were targeting; identifying these vulnerabilities is expensive (either requiring a stable of good programmers or buying the vulnerabilities on the market for hefty sums). It's not like it's a revolutionary way of making a virus, it's just a gold-plated version that has decent targeting and good penetration. (BTW it wasn't targeting nuclear power plants specifically but Siemens technology inside various parts of the Iranian nuclear infrastructure, notably at their enrichment facilities.)

    As for whether it's okay or not, that's a question that really asks whether it's okay the sabotage Iranian nuclear ambitions by clandestine means. In terms of the methods used, collateral damage was very low, no one was hurt, etc. So I don't think the method is a problem per se; then it's just a matter of arguing over the Iranian nuclear program, which we've done ad infinitum.

  6. #6
    Yup, old news. Suspects are US or Israel. Yawn.

    My main problem was that the hand was tipped. Why shoot your wad now instead of later?

  7. #7
    Quote Originally Posted by ']['ear View Post
    Yup, old news. Suspects are US or Israel. Yawn.

    My main problem was that the hand was tipped. Why shoot your wad now instead of later?
    Factors we don't know about likely.
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  8. #8
    And possibly stalling the program as long as possible to change the mind of Obama/Congress to support a military strike.

  9. #9
    I don't think a military strike has ever really been in the cards.

  10. #10
    All things considered, this is a nice alternative, just so long as it doesn't cause a ton of "collateral damage." I was under the impression from the stories I had heard that this software was somehow extraordinary and therefore putting it out there was very risky. Now you say its not that special, which is comforting I guess. Assuming you're not full of shit, of course.
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  11. #11
    It was written very specifically towards its intended victim. Its very sophicated considering you can trace it back to around Jan, but it wasn't discovered until June. On a personal PC that it wasn't written for. Slightly alarming considering Iran had a “serious” nuclear incident in July. Reading through Aimless' article, it was able to alter the process of certain parts of the plant, and still remain undetected, that speaks volumes for how hard this attack was/is to counter. Its not like the plant runs without any protection.
    Iran has also had to ask for outside help to counter stuxnet.

    I don't see how any old script kiddie group can alter this to their needs for right now. Researchers have spent months trying to reverse-engineer it.

  12. #12
    Quote Originally Posted by Ominous Gamer View Post
    I don't see how any old script kiddie group can alter this to their needs for right now. Researchers have spent months trying to reverse-engineer it.
    Its the Russian and Chinese version of these guys we need to be concerned about. Friends my ass....
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  13. #13
    Chinese would be my concern right now. Even gave them special mention in my first post.
    Another example: we are just now starting to understand what happened when they hijacked around 15% of the internet traffic for almost 20 minutes back in April. Including data for gov and mil orginzations. Sure some of its encrypted, and an internet favorite would be via SSL certificates. An encryption that China has a master key for.

    The fact this is possible isn't surprising (its happened before, supposedly by mistake), its the idea that no one knew/knows the reason or true extent.

  14. #14
    All right, this contradicts Wiggy's poo pooing of this situation. This is the same thing I'd heard on NPR. So where does Wiggs get his blaise yawn story from?
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  15. #15
    I didn't say the virus wasn't dangerous, I just said it wasn't revolutionary. Plenty of viruses can do plenty of bad stuff.

    Another odd feature is that Stuxnet uses two compromised security certificates (stolen from firms in Taiwan) and a previously unknown security hole in Windows to launch itself automatically from a memory stick. The use of such “zero-day vulnerabilities” by viruses is not unusual. But Stuxnet can exploit four entirely different ones in order to worm its way into a system. These holes are so valuable that hackers would not normally use four of them in a single attack. Whoever created Stuxnet did just that to boost its chances. They also had detailed knowledge of Siemens’s industrial-production processes and control systems, and access to the target plant’s blueprints. In short, Stuxnet was the work neither of amateur hackers nor of cybercriminals, but of a well- financed team. “Behind this virus there are experts,” says Mr Simon. “They need money and know-how.”
    http://www.economist.com/world/inter...ry_id=17147818

    Bottom line: someone spent a lot of money and bought a bunch of vulnerabilities - and had some pretty good programmers to put it together into a fancy virus. That means it was likely done by a government or someone with very deep pockets. What it doesn't mean is that the worm was some fundamentally new technology that's going to revolutionize the way viruses are made. Anyone with a sufficient desire and sum of money to burn could have done it.

    Also, suggesting it can be modified to attack other industrial systems is true, but very misleading. It specifically attacks an obscure piece of equipment that is not widely used. You'd have to significantly rework the virus in order to attack another type of industrial equipment. Furthermore, the exploits built into the virus are now known and can be protected against. So, in other words, it's possible to use the same basic idea, but it would require a lot of money and time to do it. Not a new paradigm, just a gold-plated solution for someone who really wanted to be sure they'd infect Iran's equipment.

  16. #16
    Quote Originally Posted by wiggin View Post
    I didn't say the virus wasn't dangerous, I just said it wasn't revolutionary. Plenty of viruses can do plenty of bad stuff.


    http://www.economist.com/world/inter...ry_id=17147818

    Bottom line: someone spent a lot of money and bought a bunch of vulnerabilities - and had some pretty good programmers to put it together into a fancy virus. That means it was likely done by a government or someone with very deep pockets. What it doesn't mean is that the worm was some fundamentally new technology that's going to revolutionize the way viruses are made. Anyone with a sufficient desire and sum of money to burn could have done it.

    Also, suggesting it can be modified to attack other industrial systems is true, but very misleading. It specifically attacks an obscure piece of equipment that is not widely used. You'd have to significantly rework the virus in order to attack another type of industrial equipment. Furthermore, the exploits built into the virus are now known and can be protected against. So, in other words, it's possible to use the same basic idea, but it would require a lot of money and time to do it. Not a new paradigm, just a gold-plated solution for someone who really wanted to be sure they'd infect Iran's equipment.
    More poo pooing.
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  17. #17
    Love the conspiracy theories about the Book of Esther and the alleged number-as-date.

    November 18, 2010
    Worm Was Perfect for Sabotaging Centrifuges

    By WILLIAM J. BROAD and DAVID E. SANGER

    Experts dissecting the computer worm suspected of being aimed at Iran’s nuclear program have determined that it was precisely calibrated in a way that could send nuclear centrifuges wildly out of control.

    Their conclusion, while not definitive, begins to clear some of the fog around the Stuxnet worm, a malicious program detected earlier this year on computers, primarily in Iran but also India, Indonesia and other countries.

    The paternity of the worm is still in dispute, but in recent weeks officials from Israel have broken into wide smiles when asked whether Israel was behind the attack, or knew who was. American officials have suggested it originated abroad.

    The new forensic work narrows the range of targets and deciphers the worm’s plan of attack. Computer analysts say Stuxnet does its damage by making quick changes in the rotational speed of motors, shifting them rapidly up and down.

    Changing the speed “sabotages the normal operation of the industrial control process,” Eric Chien, a researcher at the computer security company Symantec, wrote in a blog post.

    Those fluctuations, nuclear analysts said in response to the report, are a recipe for disaster among the thousands of centrifuges spinning in Iran to enrich uranium, which can fuel reactors or bombs. Rapid changes can cause them to blow apart. Reports issued by international inspectors reveal that Iran has experienced many problems keeping its centrifuges running, with hundreds removed from active service since summer 2009.

    “We don’t see direct confirmation” that the attack was meant to slow Iran’s nuclear work, David Albright, president of the Institute for Science and International Security, a private group in Washington that tracks nuclear proliferation, said in an interview Thursday. “But it sure is a plausible interpretation of the available facts.”

    Intelligence officials have said they believe that a series of covert programs are responsible for at least some of that decline. So when Iran reported earlier this year that it was battling the Stuxnet worm, many experts immediately suspected that it was a state-sponsored cyberattack.

    Until last week, analysts had said only that Stuxnet was designed to infect certain kinds of Siemens equipment used in a wide variety of industrial sites around the world.

    But a study released Friday by Mr. Chien, Nicolas Falliere and Liam O. Murchu at Symantec, concluded that the program’s real target was to take over frequency converters, a type of power supply that changes its output frequency to control the speed of a motor.

    The worm’s code was found to attack converters made by two companies, Fararo Paya in Iran and Vacon in Finland. A separate study conducted by the Department of Homeland Security confirmed that finding, a senior government official said in an interview on Thursday.

    Then, on Wednesday, Mr. Albright and a colleague, Andrea Stricker, released a report saying that when the worm ramped up the frequency of the electrical current supplying the centrifuges, they would spin faster and faster. The worm eventually makes the current hit 1,410 Hertz, or cycles per second — just enough, they reported, to send the centrifuges flying apart.

    In a spooky flourish, Mr. Albright said in the interview, the worm ends the attack with a command to restore the current to the perfect operating frequency for the centrifuges — which, by that time, would presumably be destroyed.

    “It’s striking how close it is to the standard value,” he said.

    The computer analysis, his Wednesday report concluded, “makes a legitimate case that Stuxnet could indeed disrupt or destroy” Iranian centrifuge plants.

    The latest evidence does not prove Iran was the target, and there have been no confirmed reports of industrial damage linked to Stuxnet. Converters are used to control a number of different machines, including lathes, saws and turbines, and they can be found in gas pipelines and chemical plants. But converters are also essential for nuclear centrifuges.

    On Wednesday, the chief of the Department of Homeland Security’s cybersecurity center in Virginia, Sean McGurk, told a Senate committee that the worm was a “game changer” because of the skill with which it was composed and the care with which it was geared toward attacking specific types of equipment.

    Meanwhile, the search for other clues in the Stuxnet program continues — and so do the theories about its origins.

    Ralph Langner, a German expert in industrial control systems who has examined the program and who was the first to suggest that the Stuxnet worm may have been aimed at Iran, noted in late September that a file inside the code was named “Myrtus.” That could be read as an allusion to Esther, and he and others speculated it was a reference to the Book of Esther, the Old Testament tale in which the Jews pre-empt a Persian plot to destroy them.

    Writing on his Web site last week, Mr. Langner noted that a number of the data modules inside the program contained the date “Sept. 24, 2001,” clearly long before the program was written. He wrote that he believed the date was a message from the authors of the program, but did not know what it might mean.

    Last month, researchers at Symantec also speculated that a string of numbers found in the program — 19790509 — while seeming random, might actually be significant. They speculated that it might refer to May 9, 1979, the day that Jewish-Iranian businessman Habib Elghanian was executed in Iran after being convicted of spying for Israel.

    Interpreting what the clues might mean is a fascinating exercise for computer experts and conspiracy theorists, but it could also be a way to mislead investigators.

    Indeed, according to one investigator, the creation date of the data modules might instead suggest that the original attack code in Stuxnet was written long before the program was actually distributed.

    According to Tom Parker, a computer security specialist at Securicon LLC, a security consulting firm based in Washington, the Stuxnet payload appeared to have been written by a team of highly skilled programmers, while the “dropper” program that delivered the program reflected an amateur level of expertise. He said the fact that Stuxnet was detected and had spread widely in a number of countries was an indicator that it was a failed operation.

    “The end target is going to be able to know they were the target, and the attacker won’t be able to use this technique again,” he said.

    John Markoff contributed reporting.

    http://www.nytimes.com/2010/11/19/wo.../19stuxnet.htm

  18. #18
    I always felt it was a very tentative association - Myrtus to myrtle to Hadas(sah) to the book of Esther? I doubt most Israelis even know how to translate Hadas into English, or that Esther's original name was Hadassah. Also calling the story a 'preemptive strike' on a Persian threat is stretching the text to fit the current Iranian situation.

    I find it quite possible Israel was involved, or another sophisticated Western power (or group of powers), but the evidence given so far is thin to nonexistent.

  19. #19
    If indeed it wasn't made by Israelis, they are still geniuses because they know the power of Zionist conspiracies to captivate people. "JEWS DID SEPT 11" is based on thinner info and outright lies, yet it persists. Everyone will think this is Israeli forever.

  20. #20
    Quote Originally Posted by Dreadnaught View Post
    If indeed it wasn't made by Israelis, they are still geniuses because they know the power of Zionist conspiracies to captivate people. "JEWS DID SEPT 11" is based on thinner info and outright lies, yet it persists. Everyone will think this is Israeli forever.
    AFAIK there's no real motive for Israel to do 9/11. Disrupting Iran's nuclear program, on the other hand . . . . who has greater motive?
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  21. #21
    You think I can't find a few thousand Websites with detailed explanations for why Israel had motivation for orchestrating September 11? Those kinds of trivial "facts" and "logic" don't factor into the Zionut complex.

  22. #22
    Quote Originally Posted by Dreadnaught View Post
    You think I can't find a few thousand Websites with detailed explanations for why Israel had motivation for orchestrating September 11? Those kinds of trivial "facts" and "logic" don't factor into the Zionut complex.
    Of course you can find loads of nonsense about Israel-did-9/11 but none of it would survive Occam's razor. This virus coming from the Israeli government does, however.
    The Rules
    Copper- behave toward others to elicit treatment you would like (the manipulative rule)
    Gold- treat others how you would like them to treat you (the self regard rule)
    Platinum - treat others the way they would like to be treated (the PC rule)

  23. #23
    I'm not actually familiar with those kinds of sites, but I'd assume the real motivation wouldn't even lie within Israel in those explanations, since the US is also run by a shadow-Jew cabal and Israel is just their puppet/money-hole/Ay-rab spy station in most modern anti-Semitic tirades I've seen.
    In the future, the Berlin wall will be a mile high, and made of steel. You too will be made to crawl, to lick children's blood from jackboots. There will be no creativity, only productivity. Instead of love there will be fear and distrust, instead of surrender there will be submission. Contact will be replaced with isolation, and joy with shame. Hope will cease to exist as a concept. The Earth will be covered with steel and concrete. There will be an electronic policeman in every head. Your children will be born in chains, live only to serve, and die in anguish and ignorance.
    The universe we observe has precisely the properties we should expect if there is, at bottom, no design, no purpose, no evil, no good, nothing but blind, pitiless indifference.

  24. #24
    arstechnica.com/tech-policy/news/2011/05/us-warns-of-military-response-to-severe-cyberattacks.ars

    http://www.wired.com/threatlevel/201...tment-stuxnet/

    Hey guys, are you at war with Iran?
    "One day, we shall die. All the other days, we shall live."

  25. #25
    Would you prefer we created viruses or used bombs?
    Hope is the denial of reality

  26. #26
    No I'm just wondering how serious the US is when it says a cyber attack can merit a conventional military response. If it's really serious, then isn't a cyber attack equivalent to a military attack? So, basically, if the US had much to do with stuxnet, it has--by it's own standards--executed a military attack on Iran? Is Iran allowed to retaliate? I'm just curious
    "One day, we shall die. All the other days, we shall live."

  27. #27
    Quote Originally Posted by Aimless View Post
    No I'm just wondering how serious the US is when it says a cyber attack can merit a conventional military response. If it's really serious, then isn't a cyber attack equivalent to a military attack? So, basically, if the US had much to do with stuxnet, it has--by it's own standards--executed a military attack on Iran? Is Iran allowed to retaliate? I'm just curious
    Allowed to retaliate? Who allows a country to do something? Each is independently sovereign. So it has every "right" to retaliate and we have every "right" to blow the shit out of them.

  28. #28
    Quote Originally Posted by Lewkowski View Post
    Allowed to retaliate? Who allows a country to do something? Each is independently sovereign. So it has every "right" to retaliate and we have every "right" to blow the shit out of them.
    Would you be ranting about Irani animals who kill Americans for something so trivial as meddling with their nuclear power programme or would you be sporting about it?
    "One day, we shall die. All the other days, we shall live."

  29. #29
    Quote Originally Posted by Aimless View Post
    Would you be ranting about Irani animals who kill Americans for something so trivial as meddling with their nuclear power programme or would you be sporting about it?
    We are better then they are. They can't be trusted with nukes. Its like saying look there is two people. If person A hits person B he is bad. If person B hits person A he is bad. But this ignores that Person A is a police officer who came to arrest person B. You need context, whats good for for the goose isn't always good for the gander.

  30. #30
    Quote Originally Posted by Aimless View Post
    No I'm just wondering how serious the US is when it says a cyber attack can merit a conventional military response. If it's really serious, then isn't a cyber attack equivalent to a military attack? So, basically, if the US had much to do with stuxnet, it has--by it's own standards--executed a military attack on Iran? Is Iran allowed to retaliate? I'm just curious
    I'm not quite sure I get your point. If Iran has proof that the US is responsible for that virus, then yes it can claim that the US engaged in an act of war. War does not work by one side committing an act of war and the other side getting in a free retaliation after, however. If Iran wants to retaliate, whether conventionally or not, the US also has the right to retaliate. So sure, Iran would have a legal rationale for attacking the US; the problem is that retaliating gives the US a legal rationale to invade Iran.
    Hope is the denial of reality

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •