Stuxnet was embarrassing, not amazing (2011)
rdist.root.org
rdist.root.org
The criticism here seems to be mostly academic about not using the most advanced obfuscation while completely ignoring the actual objective and just how many obstacles were overcome.
The mission used several 0-days and stolen signing keys to get into a secret foreign air-gapped nuclear arms laboratory under a deadline and ruin the machinery while it kept reporting everything was fine. I dont see how this is anything short of amazing.
https://smile.amazon.com/Countdown-Zero-Day-Stuxnet-Digital/...
Do you really think that a military operation that avoided nuclear proliferation without killing a single human life or causing environmental damage is something to be ashamed of?
Of course its authors didn't know how agressive antivirus researchers would be, agressive largely because of the fascinating complexity of the code. Almost all malware gets a cursory glance and thrown in the bitbucket after processing.
The first one of anything is always the crudest. Getting away with industrial, state-sponsored cyber-sabotage is a huge step.
I know the claim is disputed, but if the CIA did cause the Trans-Siberian pipeline to explode in the '80s then that would count as prior art. Even if true it was nowhere near as complicated as Stuxnet, of course.
If we want another example of high-profile security incident that was more embarrassing than impressive, Wannacry fits the bill.
"economy of producing the goods"
What does this mean? The amount of time it takes to produce another extra good?
E.g.
Enthusiast: 1 good per 5 hours -- quality level 85%
Professional: 1 good per 0.5 hours -- quality level 80%
Or something else?
The enthusiast produces goods which look pretty, but often don't work correctly, or need a lot more hours of work to surpass the professional.
In the context of Stuxnet, the professional identified that the problem at hand was to shutdown the Iranian nuclear enrichment facility. They ended up with a piece of code that executed that, but was not maximally obfuscated, because more obfuscation does not solve the problem at hand.
Quality of C: excellent, quality of the final product: nice demo, but falls apart when exposed to wind.
Professional: 2h for C, 1h for A,B,D each. 1h for testing. Quality of A,B,C and D: good enough. Quality of the final product: gets the job done, withstands winds up to the speeds required in the specs, plus some margin.
Why use (and give away) any more capabilities than required to do the job?
All in all, the post author just wanted some attention.
“For the first time, the Pentagon has decided that cyber attacks constitute an act of war, reports The Wall Street Journal. The U.S. military drafted a classified 30-page document concluding that the U.S. may respond to cyber attacks from foreign countries with traditional military force, citing the growing threat of hackers on U.S. infrastructure such as subways, electrical grids or nuclear reactors.”
https://www.theatlantic.com/technology/archive/2011/05/penta...
As others have said, the only real metric of whether or not something is good is if it works in live production.
Ease of maintaining, extending, or fixing bugs in the same software are not informed by that metric.
The military doesn't need to get an A+. It needs to win. Anything else is a bonus.
Which is why the A-10 is a better plane than the F-35. One shows up and BRRRTs the opposition into a fine red mist, when you need it to. the other makes it pilot motion sick as soon as they put the helmet on.
But it's taking forever and a day to get the damn thing out the door because it's too academically excellent.
It didn't meet the specified requirements. That's a bad product.
If I have a car motor which runs, but throws a piston 20k miles before it should, I didn't build to the production spec.
Stuxnet worked. Deal with it. Of course, for obvious reasons, it would be traced back to US/Israel and not to a kid in his mom's basement.
But also, what substantial gains would have come from adopting the techniques in this article?
Moreover, the virtual machine-based code obfuscation is being regularly pwned by software cracking teams so I can imagine that obfuscation would only postpone the publication of the tool’s code for a week max.
Just like the NSA Cisco exploit chain. According to armchair programmers it was ugly. But it worked it could take over every Cisco router. it doesn't have to always be pretty if it gets the job done.
The authors weighed the risk of not being successful vs the risk of someone analyzing the worm. The latter was inevitable but the former would have been disastrous. Those protections would have only slowed down malware analysts. If this was normal malware that would be the goal, exist for as long as possible without being detected. ‘Normal’ malware has a high tolerance for failure.
In this case the goal appears to be ‘break some sensitive equipment before a particular deadline hits’, with a razor thin margin for error. But your points are not lost, good post.