Nuclear weapons agency breached amid massive cyber onslaught
politico.com
politico.com
https://slate.com/technology/2014/04/huge-floppy-disks-and-o...
Reliable is not a word that comes to mind when recalling floppy disks of my youth.
It was just a kid trying to hack into a video game company. He accidentally started a war simulation. The US had recently turned over control of its entire nuclear arsenal to an AI because humans resisted launching weapons that would kill millions.
Anyway, the kid accidentally started a war simulation and now the AI wants to nuke everyone. Don’t worry though, as soon as the AI plays itself in tic-tac-toe, it will realize that peace is the only way.
If you aren’t old enough to understand this, you need to catch up on your 80s nerd movies. :)
And if some equitable retaliation is designed would there be public support for it if it were to include conventional warfare in some proxy fight.
Much of the country has been told that China is the enemy and investigations into Russian interference in our country is a hoax.
If this is more work from the fancy bear folks this is problematic.
The US is a month away from a new president.
The new president’s authority to act against this attack continued to be undermined by the sitting president who just fired the head of cyber command because he said the election itself was secure. Not because it wasn’t, but because he said it was to the public!
I can not think of a more sophisticated and long term military intelligence operation than the epic we are witnessing right now.
The United States could not be in a weaker position than now.
https://en.m.wikipedia.org/wiki/Cyberwarfare_in_the_United_S...
One way is to have your backdoor planted, but only use it in retaliation. I assume that's why EnergyBear was found on the US power grid - not because Russia wanted to preemptively strike our grid, but so that they'd have the retaliation option ready to go, just in case.
mentioned "Note (Updated December 18, 2020): CISA has evidence of initial access vectors other than the SolarWinds Orion platform."
This raised any eye that there are other attack vectors that have been found but which they have not or do not have information on.
They completely swept it under the rug, told the infosec guys that if they talked about the incident with anyone they would have their employment terminated and that it was to never be discussed because they were worried about their share price.
We also have laws here in Australia that says if this happens to a business it mandatory to disclose the breach to your customers.
> you must notify affected individuals and us when a data breach involving personal information is likely to result in serious harm.
A employee anonymously reported the breach to the government agency that handles this, who in turn contacted the business with a "Please explain. Right now."
The next day after they were contacted they fired every single IT department staff member. Helpdesk, Infosec, Networks... All fired, because they couldn't figure out who reported it.
Nothing ever happened to the business as they somehow convinced the government that the data that was stolen was "made up junk data used for testing" despite it being obviously clear that it was current customer info.
This crap happens all the time and businesses are continued to be allowed to get away with hiding breaches from people.
All it does is help the share price and disadvantage the customers.
Australian law provides almost no protection for speaking out against this kind of thing. Does not matter if it's true or not, it's still considered slander/defamation because you said something that makes the company look bad.
For some reason businesses prefer to cover up their vulnerabilities instead of fixing them. When you report a vulnerability as a white hat there is a big risk that the company will use you as a scapegoat and sue you. For a business it is much easier to claim that they "caught a hacker" rather than admit their weakness in public.
Hackerone is basically a "vulnerability blackhole as a service" because researchers are dependent on bounties for their income. Disclosing an ignored vulnerability publicly weeks or months after the hackerone report can lead to getting banned on hackerone and thereby ruin your ability to collect bounties.
However without knowing the extent of the incident, and going off of this part:
"At this point, the investigation has found that the malware has been isolated to business networks only..."
It is more than likely this news story is overblown.
Locking down devices is actually just giving up on security. Trusted code and centralized review don't scale. Real security implies effectively mediating between many different interacting parties, not simply reducing the number of them.
It's still sorely missing fine-grained control like network access (perhaps even fine-grained network access control), and access to various devices and folder locations; within reason, the more controlled and restricted the better.
Linux ought to make a move in this front and gain ground on security advantage: shouldn't we be able to give access to specific processes (say an installed game or text application) to specific folders and devices? Why should a game be able to read all my files (and not just its own folder), and why should any of those be able to use the network?
I'm really hoping to see an industrial-scale push to develop a solid headless unix-y userland for SeL4.
Regarding security. I think the problem is simply that neither Linux nor Windows is the right tool for this job. They are secure, but not nuclear arsenal secure. And there is where SeL4 and other formally verified components should come in.
If the Linux kernel is getting too heavy for you (there really is a lot going on in there now), you can always switch to FreeBSD or OpenBSD. (no snark intended, this is actually quite a viable option for many workloads.)
Microkernels with capabilities are the only way to go. L4, Fiasco, Genode, ...
I'm not sure about that. For example, FERC doesn't have a non-business network — they aren't a system operator. They do have all kinds of juicy data though, including details of various high voltage interconnects and the like that would be good stuff for an infrastructure attacker.
What Happened to My Nuclear Deterrent? Your abort codes are encrypted and your nuclear arsenal has been placed at DEFCON level 1.
Many of your ICBMs, submarines, launch silos, bombers and other facilities are no longer accessible because their communication channels have been encrypted. Maybe you are busy looking for a way to cancel the launch, but do not waste your time. Nobody can recover your abort codes without our decryption service.
Can I prevent thermonuclear war? We guarantee that you can recover all your nukes safely and easily. But you don't have enough time. If you do not pay within 7 days, you will not be able to recover from nuclear winter forever.
How do I pay? Payment is accepted only Bitcoin. Click for more information.
*opens AES 256 decryption toolkit
Movie recommendation: https://letterboxd.com/film/virus/ The better japanese version is also on youtube.
Maybe not much, though.
- ERCS: https://en.wikipedia.org/wiki/AN/DRC-8_Emergency_Rocket_Comm...
- Perimeter: https://en.wikipedia.org/wiki/Dead_Hand
All this to say, that it is unthinkably inhuman to have MAD be an automated response.
Even if the initial launch was a genuine mistake, there is some value in launching a retaliation because it prevents such mistakes (or "deliberate mistakes") from happening in the future. In fact, seeing how much the mistake costs the initiating party may be sufficient motivation for all the remaining countries to properly commit towards disarmament.
For that matter, non-internet-connected computers can still be networked to each other using internet protocols, so they can still need bug fixes for internet stuff.
This stuff was solved BEFORE the Internet was in widespread use.
>The U.S. government has not blamed any particular actor for the hacks yet, but cybersecurity experts have said the activity bears the hallmarks of Russia’s intelligence services.
"Their password was solarwinds123 and it was on their GitHub."
Can't imagine why the US government hasn't formed a strategic response under Trump. His foreign policy has been so good over the past 4 years.
https://www.washingtonpost.com/history/2020/06/26/russian-el...
If you think the president needs to actually "understand" anything subtle like (even physical) security, you are being deliberately obtuse or naive.
Sycophancy and dishonesty spread pretty quickly - two things you don't want in anything important.
Absolutely damning. Sadly even on HN some cybersecurity experts that will trash companies for breaches will turn a blind eye to this because of their politics.
The delusions of grandeur HN has about it's own culture is why is still has these biases. There is no politics on HN, ipso facto it cannot be biased.
What the "no politics" really means is no vaguely left-wing shibboleths allowed.
They accessed the business networks of the NNSA, the agency responsible for maintaining the nuclear stockpile, but did not access the networks managing the actual nuclear weapons, as the title half-implies.
There was no threat of random nuclear weapon exploits, those networks have not been compromised as far as we know.
That they know of / are admitting at this time.
The damage could really be far worse. It's hard to tell right now I think.
More shocking things have happened, like the nuclear launch codes being "00000000" for 15 years:
https://www.huffpost.com/entry/nuclear-missile-code-00000000...
In my opinion, these liars-in-practice are far more pernicious than the liars-in-fact. It's easy to disprove a fact, whereas it takes time, effort, and some analytical ability to unpack a carefully worded untruth.
Apologies for the rant.
(Of course, there is disagreement about what is true in many cases, but in this particular case, the reporter or editor presumably knew the difference and went forward with the title anyway.)
Or so, anonymous sources familiar with the matter tell me.
It might have been an honest mistake? Although it would be surprising to me that a Reuters editor would miss the implication of this headline.
And you could of course include the economic fallout of COVID under the same umbrella, which is nowhere close to being solved.
I do believe that President Trump deserves a Nobel Peace Prize, because with so many evidences, his precedents, including our be-loving Obama, would have bombed the hell out of our designated enemy.
/s
China growing in power and influence, flexing itself on the global stage. The US waning internationally, citizens divided and full of hate.
We're factory-less, fab-less, and have fewer educated. Fewer consumers. Lots of debt.
We have SpaceX, but China's pace of exploration and international cooperation is increasing faster than NASA's.
The only advantage I can think of us our military and navy, but China has carrier-killers and ICBMs.
Zoomers on TikTok hate capitalism and the military, and it seems like they're being indoctrinated by an "algorithm". Or maybe it's the lack of opportunity we're providing for them.
If and when our tech companies and entertainment companies get leapfrogged, what will we have to export that brings us wealth?
What happens to democracy and liberty when the top economy and producer in the world is a single-party state?
I hope we're hacking back just as hard. That's what the NSA should be doing rather than domestic spying.
He was bending over to yet another strongman dictator, e.g. fussing over getting him a Elton John CD for example.
Who was executed “willy-nilly”?
I don't see how that connects to your larger point. Can you please explain?
If younger generations grow up hating these structures, they might vote against them.
Yet, the quality of life in America, as well as around the world, has improved drastically. How many people have luxuries like cell phones, computers, TVs, cars, refrigerators, indoor plumbing and heating, as well as access to resources like ambulances and hospitals--the list goes on. How humans of centuries past would long to have lived at this time, if they could see how we live today.
And it's not just about material things. For example, in the past hundred years, although the world population increased from 2 billion to 7 billion, the number of people who die to natural disasters each year has greatly decreased.
This video shows how widespread these misconceptions about world situations are: https://www.youtube.com/watch?v=N1dvfH3s1Ak In this study, about 80% of people were wrong about more situations than if they had chosen an answer randomly.
This is not to say that there are no problems in the world, or in America. There will always be problems. But your characterizations are misleading, and your claim that capitalism has "completely failed" young people is extreme, and it fails to credit capitalism for the prosperity that it has enabled for most of the world's population compared to most of human history.
People are still told to go to expensive college. A cheap community college degree in STEM is worth much more than an expensive liberal arts education. A self-taught programmer has more marketable skills than a liberal arts degree holder. The freely available loans made the institutions money hungry, and they grew to absorb all of the new income.
We really need to fix education.
The post-war / post-energy boom is over, and the easy gains that yielded have faded. Today's economy is harder. The knowledge economy is not as accessible and requires more training. The US can't compete with the cost of manufactured goods as our standard of living and minimum wage are too high. By importing, we're moving that negative externality of hard or menial labor to economies that can handle it - bringing them up to our level, but destroying those opportunities domestically.
Housing is still affordable outside of major cities. I'm not sure what to do about the price of housing in major urban areas though. It's supply and demand, and wages for the average worker haven't increased.
You sound just like a politician with your empty, alarmist assertions ("failing! urgently address!"). Are you a Sanders staffer? I mean, it would explain your comments.
Capitalism is failing these people. There’s statistics all around. If you want to bury your head in the sand and lash out at random people on the internet, I feel sorry for you.
You: "Capitalism is failing people!"
Me: "Actually, it's enabled much prosperity around the world, so that only a small minority of the world population lives in poverty compared to a few decades ago. For example, here's a YouTube video showing how public perception differs from reality."
You: "Capitalism is failing people!"
Me: "You're not even making an argument. You're just repeating your assertion."
You: "Capitalism is failing these people! You're lashing out at me!"
It sounds like you're trying to convince yourself by sheer repetition.
Low-budget is something we'll get schooled on. International studios are just as good as we are.
China owns a number of US studios outright, and they also own a lot of the tooling (eg 40% of Epic Games, which is being used for Star Wars). They're cultivating our tech and using it themselves.
Most of the deep fake research amenable to use in films is coming out of China.
I'm not saying it's a sure thing, but China is in a very good position to attempt a takeover of the movie market if they want to.
edit: I'm now being greeted by "You're posting too fast. Please slow down. Thanks." on all messages I've attempted to post.
It appears my account got flagged for this thread. I've never seen this before in my ten year history of using HN. Not sure if this is automatic or manually added. Does anybody else know what this is about? [1]
[1] https://github.com/minimaxir/hacker-news-undocumented/issues...
https://www.mcvuk.com/business-news/publishing/tencent-acqui...
The British empire was good for the rulers and owners of the companies integrated into it, but not for the average brit.
Not only is China growing in power and influence, as you point out, it has been investing in American media and other industries. They're famous for playing their strategic game over a long span of time (the long game).
My pet theory is that Hollywood, Silicon Valley and the Left are thoroughly (and probably unwittingly) influenced by the infiltration, and are the medium for memes and messaging that divides us so much. It's as though we're about to re-fight the Civil War. China, the master that it is at cultural revolution and re-education, is playing a shrewd game.
I think they're about to beat us cold by causing us to implode from within. If so, it's beyond sad -- but in terms of military strategy, a brilliantly played hand by President Xi and the CCP.
Are they forcing Walmart and Amazon to carry those goods?
Are they responsible for the low wages Americans are making?
Did they move manufacturing overseas?
Otherwise a water tight theory ..
Your bias is showing, and you're totally blinded by propaganda as badly as you accuse some others.
Interesting you should attribute that to “Hollywood, Silicon Valley, and the Left” since the people spreading memes and propaganda literally advocating either a new Civil War and publicly advocating military overthrow of the lawfully elected government are on the Right (the former groups like the Boogaloo bois; the latter a number of prominent figures, including recently pardoned former National Security Advisor Gen. Michael Flynn.)
> China, the master that it is at cultural revolution and re-education, is playing a shrewd game.
Both the pro-Trump elites counselling extra-Constitutional violence and some of the more (superficially, at least) grassroots groups in the White nationalist/supremacist vein preaching race war have been well documented to have been engaged with and influenced by Russia; China less so.
You can sleep well. Spying is what every government does.
You really care about the ideals of "liberty" and "democracy" I see.
They're not going to stop trying. We shouldn't just let it happen.