German nuclear plant infected with computer viruses, operator says
reuters.com
reuters.com
I could only find decent reporting about this in german: http://www.tagesspiegel.de/politik/plaene-der-verteidigungsm...
I wonder if they can attract any real talent though? Only people I know willingly wanted to work for the Bundeswehr eiter did not have the grades to study elsewhere or went to Afghanistan for the money.
The challenges of information technology w.r.t. warfare are fundamentally different from usual war tactics. You can't solve them by throwing lots of personel or big guns at them. If midst-fight your equipment or infrastructure fails because of security flaws, it's not because there's no personel to deal with it (for that it's already too late): it's because its designers failed at the drawing board.
It'd be better they concentrated on quality instead of quantity and the resignative "anything can be hacked" myth a lot of popular media is putting forward, as if information technology operated according to the same rules the physical battlefield does. These analogies only go so far...
(of course the same applies to non-military contexts as well)
And although the article says only a few of those thousands will be used for offensive ops, I suspect that many more will be.
I think you can make a better effort with more people; the critical thing is the quality of the people.
Of course there's a good chance more will be less valuable!
In real life, governments are some of the largest enterprises that exist, and use the same software and systems as everyone else. Complete replacement with provably correct systems is such a large task that it would never be completed, for just the same reasons as in private industry. The attack surface of a government ranges from sophisticated military hardware to mobile apps.
Deterring, detecting, and remediating security incidents is thus done the same way the private sector does it: testing, continuous monitoring, hunting, forensics, etc. All of these activities are person-hour intensive, and I don't think there's a security operations center in the world that wouldn't tell you right now that they are limited by the size of their staff.
That said, full-service security departments will include technical auditing and software security components, and I suspect the German government intends to include this. Of course, these functions are quite limited by being on the client end of the relationship, as I doubt the German government produces any more of its software in-house than the US government does (which is not very much).
After the US, Israel is #2 in Cyber security and is very dependent on Germany for military needs such as submarines and engines for their tanks. Since these nuclear power plants have nothing to do with national security directly, Germany should employ Israelis to help them if they have not already done so.
> As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit.
More politely put, I see no obligation on employers to provide employees with the means to recharge their personal phones :)
This is a classic "design a better human" problem - sure, you can try to 'persuade' people by threatening them with demotions, suspensions and unemployment. And then you can hope that this will work in every single instance. Or ... you can provide a few usb ports in a convenient location, so people use these instead of the usb port in your multi million dollar cockpit to charge their phones. Take your pick.
For another example decide if it's easier to provide waste bins or to threaten people who litter streets.
Why would they NOT do this, under your system? If I can plug my phone in right where I am, in the cockpit, or somewhere less convenient for me, why would I not just do it where I am, in the cockpit? There are no penalties for it, so why wouldn't I do it?
> Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger.
That's just...not how computers work.
But if the claim is that the virus lie 'dormant' in the uninfectable plane OS, then I can't understand that.
Edit: corrected it's its
I think you added an apostrophe by accident, or the poster corrected the mistake.
If the USB chargers in cockpits are any more complex than the above, why?
No idea how the rest of the exploit would work in this scenario though, I have a hard time believing it.
So the virus would have to infect both android and the cockpit to spread from phone to cockpit to phone.
Not saying that's how it happened, just that it's possible.
[1] https://srlabs.de/badusb/ [2] http://www.wired.com/2014/07/usb-security/
They claim it is happening.
Boeing's new 787 Dreamliner passenger jet may have a serious security vulnerability in its onboard computer networks that could allow passengers to access the plane's control systems, according to the U.S. Federal Aviation Administration.
The computer network in the Dreamliner's passenger compartment, designed to give passengers in-flight internet access, is connected to the plane's control, navigation and communication systems, an FAA report reveals.
Boeing spokeswoman Lori Gunter wouldn't go into detail about how Boeing is tackling the issue but says it is employing a combination of solutions that involves some physical separation of the networks, known as "air gaps," and software firewalls. Gunter also mentioned other technical solutions, which she said are proprietary and didn't want to discuss in public.
"There are places where the networks are not touching, and there are places where they are," she said.
Don't worry, the most important parts are running on DOS or OS/2, so we're saved from doom!
I'd rather have my local solar power plant infected with viruses or hit by cyberattacks.
The problem with modern nuclear reactor designs is that they're just that, designs. Great ideas people in comment sections love to mentally masturbate about. In reality almost all nuclear reactors are decades old.
Politics alone ensure nuclear reactors with the exception of maybe fusion (which will be way too late for climate change) will never get off the ground. In the meantime renewables, solar especially, get cheaper and more efficient every day, not designs but actual installations.
Few years ago, Westinghouse tried to kick out Rosatom from VVER power plants in Eastern Europe as a supplier of the fuel. They pulled very heavy levers to do that, but in the end, they were still refused due to their pellets not being up to the task and being a security hazard.
And yet they still try that in Ukraine...
Regulations say you can't just ran any random device (including software) there, that's unsafe.
Unfortunately regulations weren't being made with PCs in mind where anybody can plug in an infected USB stick. Or needs to in case he's a service technician. (Yes, those ports are not available for "anybody" who is there, but somebody needs to install software on those machines).
There are things I have seen I wish I could unsee to feel safe.
Windows has no business being used in any application that is life or safety critical. Its license even says so. Doing so should be a crime. There are much better OSes out there for this kind of thing: just ask anyone who builds jet aircraft.
Operators mostly watch the plant during the weekend while the engineers are not there. It is a security job: check if something turns red and pick up the phone if it goes bonkers. The operator has a limited access to the core process. Boring, and they get busy by going to the Internet and downloading random stuff. And yes they do have access to the Internet...
One thing for sure: you can't infect a PDP11 system with Windows or Dos Virus, nor can one plug in an USB.
It probably takes several relatively large and frequent disasters not just to put the issue on the map politically but also to show that it's worth investing in information security besides the cost.
"In 2007, FERC designated NERC the ERO in accordance with Section 215 of the Federal Power Act, enacted by the Energy Policy Act of 2005. Upon FERC’s approval, NERC’s Reliability Standards became mandatory within the United States. These mandatory Reliability Standards include CIP standards 001 through 009, which address the security of cyber assets essential to the reliable operation of the electric grid."
Source: http://www.nerc.com/pa/CI/Comp/Pages/default.aspx
(Edit: clarification)
Control systems generally have two components; the actual controllers that interface with the machine or equipment and then an HMI for the operator to interface with the controller (ignoring completely hard wired systems consisting of lights, buttons, chart recorders, etc). The majority of the HMI software runs on windows.
Once an attacker is on the HMI system they can probably easily do anything the operator can do, and possibly have full access to the controller and make things happen that Should Never Happen.
A nuclear power plant has computers on its airgapped network infected with a computer virus from 8 years ago for an operating system which expired from support two years ago.
At least the nuclear power plant near me runs on a PDP-11.
http://qz.com/671383/germany-has-sacked-its-spy-chief-but-ha...
Homer: "NUC-U-LAR"! IT'S PRONOUNCED, "NUC-U-LAR."
https://frinkiac.com/meme/S09E19/665197/m/Ik5VQy1VLUxBUiIhCk...