Stuxnet Authors Made Several Basic Errors
threatpost.com
threatpost.com
† If that's really the "target"
This is direct action. It isn't script kiddies, it isn't Anonymous, it isn't a random 1337_h4xr pulling off some minor corporate sting. It's the real deal, it's programmers putting their lifeblood into an endeavor that changed the fate of nations.
So whatever flaws that happened to exist don't change the inherent absolute confidence of the maneuver, nor does it change the precision you praise in your post.
But it also means that it can't be perfect. Anything that's so grounded in reality will not be perfect. That's the rules of playing the big games--you can't please everyone, you can't perform to the theoretical maximum that the weak articles that call it "nothing special after all" espouse.
Because that theoretical maximum was out of the reach of stuxnet's writers from the beginning, and they fucking dealt with it. People writing articles now have had nothing to do with crippling Iran's nuclear capability, if even for a moment, and the hogwash in the blogosphere that exists is so much shallow posturing.
As someone who has actually read the code, my opinion is that yes it was special, but not because it was brilliant. It took a lot of resources, and although there was clearly a relatively high degree of skill involved for at least parts of it (finding 0days), there were not really any new techniques. So, I personally find it impressive because of the sheer amount of work that went into it.
I think it is more the principal of it that is noteworthy - if someone tried to make a movie plot about that a few years ago, we would have scoffed.
The reason that it was obviously a nation-state is because the number of people that worked on it, the amount of time they spent on it, and what the group would stand to gain (nothing), would not have been funded by any other entity. I won't go so far as to say it would be impossible to do by someone else, but that is improbable and really would not make much sense at all. Combine that with various external clues, and it is really obvious.
Sure, I could do that and I am nobody special. That's absolutely nothing compared to the "minimum requirements" stated in most job ads for jobs that pay crap.
Programming logic controllers is very simple. They are designed to be like Excel, something that non-programmers can program.
The hard part of this operation was getting the information about the Iranian labs, which was surely beyond top secret. There were probably dozens of special ops guys involved in that part. But that's nothing to do with the programming.
As far as zero day exploits, they are widely for sale to the highest bidder, one only needs money not skills. But if one has no money, that's not a problem either. It's not like there's a shortage of them, I've made plenty of vulnerability reports myself to various vendors. So have most people who are even moderately competent. There are thousands of vulnerabilities to choose from. I don't find it hard to believe there are people holding some back. If you're a government agency monitoring all the hacking boards though you already know about a bunch of unpublicized vulnerabilities.
I think to make his case that more than one person was involved, he left some important points off his list: 1) finding four 0-days to exploit and gain escalation of privilege on XP/2000 and Vista/7 machines (how long would it take you to do that?) and 2) Knowing HOW to program the PLCs so that they screw up the centrifuges without being detected.
Sorry if your comment was entirely a joke. Too early; not sure.
well isn't that hand-wavy.
>For example, the command-and-control mechanism is poorly done and sends its traffic in the clear and the worm ended up propagating on the Internet, which was likely not the intent.
this is part speculative and part, in my subjective mind, stupid. propagating on the Internet seems a highly reasonable method to me. what do you expect it to use, facebook? maybe the constraint is that it has to express itself on the internet and therefore 'in the clear?'
>"This was probably not a western state. There were too many mistakes made. There's a lot that went wrong,"
Is that really so western-centric? this guy is seriously just reaching for criticism in order to grab headlines.
>Lawson concludes that whoever wrote Stuxnet likely was constrained by time and didn't think there was enough of a return to justify the investment of more time in advanced cloaking techniques.
That's at least reasonable, because in all honesty maybe there wasn't enough of a return. Lawson seems a better analyst than this Parker fellow.
If all we know is that he wrote a tool that found the code to be of fairly low quality, he got up on stage in front of his peers and waved his hands.
You're cherry-picking my arguments anyway.
Seriously, what more could the authors want? Additional sophistication, just to keep some random bloggers happy?
I'm pretty sure their mission was "destroy some Uranium centrifuges" and not "create the perfect stealth cyber weapon". They succeeded at the former, so it doesn't matter that they "failed" at the latter.
Say it ain't so! ;)