CIA wanted a way to copy 3.5“ floppy disks ”in a covert manner“ in 2013
wikileaks.org
wikileaks.org
So, 3.5" floppies are probably used in much more modern weapon designs. Perhaps orbital lasers or something. /s
The weirdest part is that the CIA uses agile-type user stories when developing its spy gear.
Good requirements documents are a rare find in my experience.
#Turn on blue LED for 2 seconds and then turn it off
echo 0 > /sys/class/leds/fxi-ccandy\:blue\:/brightness
Should be echo 1 > /sys/class/leds/fxi-ccandy\:blue\:/brightnessSCADA systems are often very old and sit unconnected to the internet for decades at a time. There are likely hundreds of nuclear reactors around the world running this old, unpatched, and very vulnerable software. They'll likely not patch it until they refurbish the entire system.
Don't ask me how I know. It took AGES to purge our ERP system of any reference to the Siemens item# which resulted in a floppy showing up.
On the other hand, it resulted in some business for both DHL and whoever still manufactures floppy drives nowadays - service engineers opening a package somewhere in the world, finding what kids today would assume was a 3d-printed 'save' icon - and order a drive, double haste...
If you dont need the extra capacity or speed that USB or optical offers you, don't upgrade. I mean this specifically for infrastructure-size projects where the "thing" / entity that is controlled costs multiple orders of magnitude more than the computer system controlling it. Say I have a hydro-electric dam, or any kind of power plant (not just nuke), or train switch controller, submarine, aircraft carrier, etc. Stuff that can't break. Its just cheaper and safer to keep using the same tech, keep replacing known-working parts, than it is to risk updating the system to "stay current", and risk a costly outage (or some kind of catastrophe, even if theres only a 10^-7 chance of it happening). I dont blame them one bit.
OTOH, the only way to actually preserve data is to keep rolling them forward to new physical media as the old ones die off (this is of course abstracted away in cloud solutions).
And the CIA's job is as much to spy on this world of established industrial capability as it is to hunt down laser-toting agents in the urban jungle of Beijing.
Any university has dozens of labs with 386s, or similar vintage, because the software they need to operate incredibly expensive equipment is abandonware.
In fact an IT guy I knew kept the best surviving examples of vintage computers in his closet for parts or to transfer data with.
Then again, I suppose embedded Linux keeps getting lighter / better.
That requirement strikes me as classic non-/semi-technical product owner trying to suggest to the engineers how to do their job.
As for people using floppy disks in 2013... actually not surprised at all. They have a little bit of security through obscurity now and they can be easily cleared with a magnet and some scissors or open flame. And as another poster pointed out, it might be for legacy systems like industrial control.
Imagine I have a usb thumb drive with gigabytes of mp3s on it, and I devise a way to embed and extract a floppy image into the mp3s (i.e. steganography), or perhaps family pictures. unless the images are viewed before and after, it can be difficult to determine what was stored or even if anything was stored.
Of course, not impossible as their attacks that can be done on this, but I'd argue that if one is already suspected of using steganography and they have access to the device you are storing the data on, you are most likely screwed anyways, even if they can't prove it.
Bringing an USB thumb drive to such a place by itself would a serious incident, but might be treated (after a review) as a benign accident, but having a concealed device that can read floppies is another manner, it's obviously not a coincidence. Discovering that you ("the asset") have such a concealed device is by itself clearly sufficient for failing the mission and getting detained. It doesn't matter if it's "difficult to determine what was stored or even if anything was stored" - possession of the device and attempt to smuggle it to the secure area would be sufficient.
Scan it once at insanely high resolution and later analyze the data...
Especially thinking about some random corporate/government worker who got recruited as a source by the CIA and has 'unsupervised' access to some floppies.
Also it may reveal that the target is using old methods for security purposes. Imagine an office where no one has any sort of user accessible networking (ethernet would be just for updates, security, auditing, etc), just a 1980s style set of workstations each accessing things from the floppy drive. If you want to see a file on a certain topic then you'd walk up the librarian who would check your ID and give you the disk. If you wanted to sneak that data out, then you'd have to physically copy the disk or steal it. The latter being much more risky as the librarian knows you had it last. Perhaps there's enough empty space in the floppy case to put in some kind of tracker as well.
You also don't need to worry about USB vulnerabilities with USB sticks nor the worry that someone will show up with the right cable, mount the USB drive to their phone, and copy the data. Nor the write limits and versioning exploits on writable CD media. You could also set off a EM burst that'll wipe a room full of floppies in a millisecond if need be.
If you deal with text data files then the 3.5" space limitation is not an issue, what's the average word file size? 80k? Imagine an intelligence service that keeps its state secrets like this. You'd be hard pressed to hack them. This isn't a hypothetical as we have data that suggests some intelligence services have moved to typewriters to avoid hacking[1]. Seems to me, I'd much rather just use 3.5" disks on a linux box with no networking attached to a printer than a typewriter. Even spies can't live without WYSIWG editors. Perhaps the great typewriter experiment has failed and sneakernet is a better compromise between security and convenience.
[1]
https://www.theguardian.com/world/2013/jul/11/russia-reverts...
https://www.theguardian.com/world/2014/jul/15/germany-typewr...
edit (as it wont let me reply) in regards to exploits here:
Your attack surface has now changed from "Anastasia in accounting clicking on resume.js" to now dragging TEMPEST equipment into the basement of the Lubyanka building undetected.
Or a mole now trying to sneak in a bulky 3.5" copy device instead of right-click > encrypt > email.
And I also think that it is pretty hard to make these 1980's workstations secure -- that old DOS software was full of vulnerabilities, and it has no modern protections at all (usernames, kernel mode). I remember back at high school we had "1980s style set of workstations each accessing things from the floppy drive." and they were full of viruses. And once you have your code on target computers, you can exfiltrate data pretty easily (emit right patterns with pc speaker, memory access, display, etc..)
Because that shit cute.