How Stuxnet was deciphered
wired.com
wired.com
I am curious as to what in Stuxnet code and/or the client computer caused this. From the rest of the article, Stuxnet went to great lengths to stay undetected. Anyone has clues ?
I had the same bug in a worm I wrote. I was storing the marker in the local user part of the registry, which was being loaded from the domain controller, so the bit wasn't being retained.
I was disturbed by the implication that the researchers should stop investigating Stuxnet (or refrain from publishing) because of the possibility that it was a US or Israel covert op. There are so many problems with that reasoning, and I'm glad they weren't swayed by it.
Furthermore, even if Iran does make WMDs, they do not pose a serious threat to Israel or the United States. Their delivery systems (missiles/rockets) are very antiquated and can be reliably intercepted and a suitcase nuke has extraordinary low yield. And even if they somehow gain the capability to effectively use their WMDs they would not do so due to MAD.
You cannot say the same of True Religious Believers.
This is incredibly naive. A simple ship sailing into NY harbor could easily deliver a nuclear weapon, even if it was large and unrefined. This is especially the case for a U235 gun-type (ie Little Boy) weapon, which requires relatively little sophistication.
And even if they somehow gain the capability to effectively use their WMDs they would not do so due to MAD.
Nobody would fly airplanes into a buildings because human beings want to live, right?
Google now has a fully-functional driverless car and at least one US state has approved their use on the road.
Who needs polonium when you can send a virus out to seek a car?
One, you must have the knowledge of how to hack that specific car's ECU. You must know the make, model, and exact ECU of the car.
Two, you have to actually be familiar with reverse-engineering ECUs to begin with.
Three, you need special equipment to connect to an ECU diagnostically, let alone in a way to reprogram it.
This adds up to a lot of hassle, and greatly limits the number of people who have the skills to pull this off. Who would develop this method but a government with the time/manpower to create and test it? And, if the government wants you assassinated, why would the government allow a real/accurate investigation anyway?
It would be far simpler to create a small microcircuit to play havoc the the ECU, than to hack the ECU. But, even then you'd primarily just lose mileage (and a mechanic would quickly locate it).
And there are chips that can have their memory permanently burned into them (I don't know if ECUs use them, however). Patches are impossible, but there's no risk of infection either. Just test it rigorously first.
That's not necessarily true.
For example, my car's ECU can be reprogrammed using the instrumentation bus. The instrumentation bus can be accessed using the wires that interface with the CD changer. That means that the audio system is on the same network as the ECU -- and if I had a Bluetooth adapter, that'd likely be on the same network as well.
Indeed, researchers can disable electronically controlled brakes via Bluetooth: http://www.technologyreview.com/computing/35094/?ref=rss&...
>Patches are impossible
I've had to take my car in for patches a few times. Where there is software, there will be patches required.
At the end of the day, I doubt we will be seeing assassinations via car hacking. But I wouldn't call it impossible.
> Indeed, researchers can disable electronically controlled brakes via Bluetooth
That I didn't know. That's a major security problem, and another reason I'm glad for my 9 year old car.
organized crime has both the will and the funds to do something like this. so could an independent person... you're talking $50-$75k and 6 months of a persons time to figure out how to delete someone without anyone even thinking it was murder?
the advantage of "hacking" the ECU is that by making changes in software you can make changes that can't be detected by a mechanic or by a vigilant pre-drive screen of your car. after i read the autosec.org paper my first thought was "this is dumb, it requires physical access to the car to pull off, i already have that, i can perform hundreds of other types of physical sabotage to make the car crash. nothing new here."
a few weeks later i realized "wait a minute, if i make a change in software, it can theoretically remain undetected forever before i activate it. also, nothing the operator does to find it could work. also, if i die in a wreck on the freeway that looks like i just lost control of my car, will the state police rip apart the wreckage, find the ECU, and verify that it hasn't been tampered with? will they know how to? will they even think to do that? and even then it wouldn't matter because the software could erase itself from permanent storage just-in-time..."
there are a lot of advantages and i think the barrier to entry is a lot lower than you say it is.
But understand my position: I am not an advocate of automated cars, or even highly computerized cars. The more computerized the car becomes the more points of failure it gets, whether that be a dropped internet/GPS connection, a hardware glitch, or "cosmic rays" (which got the blame for the Prius brake issues).
It takes significant developmental effort to hack the ECU. And if you don't want the changes to be detectable by mechanics or a prescreen drive test, you need to be especially cautious in your changes. You must disassemble and analyze the ENTIRE codebase of the ECU to determine where you want your changes to reside, then pack it back in.
A simple countermeasure is to let the mechanics look at the ECU version checksum. Standardize the checksum across the model, with subsequent patches being listed as a different version number. Then the mechanic checks with the official manufacturer's guide and you know if there's a problem.
You are sounding paranoid.
Physical security is always the first, and most effective barrier. If the interface were better secured digitally, it wouldn't take a genius to access the ECU's circuitry and wire an extension. But again, it takes significant investment.
If the ECU is modified to accelerate at maximum speed at some random moment, the only thing necessary to defeat it is switching into neutral and pulling off the road! The range of destructiveness the ECU can cause is limited, though it can rack up your repair bills.
Crime syndicates usually buy shares in the local police force. If you meet a mysterious end in a car accident the investigation would be tampered with regardless of the method used to kill you.
Theory is wildly different from reality.
http://pikkupossu.1g.fi/tomi/projects/projects.html
And for the special equipment, that's not always the case -- my car's engine controller can be reprogrammed by tapping into a few wires on the CD changer harness in my trunk, and that's likely to go unnoticed by me, my mechanic, the police, you name it.
But again (see my other response to a similar statement), theory is wildly different from reality.
The ECU controls things like fuel-oxygen ratios, how much the throttle is open, etc. Steering, braking, and the transmission are almost strictly physical/mechanical interfaces.
Unless you drive a Prius, or like system where the brakes are digital, you can counter a sudden, massive acceleration with your steering, brakes, and by turning the car off—no matter what the ECU wants.
The applicability of this kind of sabotage for murder/assassination is limited.
Possibly. But I'm not sure I'd react all that well if, while driving in the middle of the night, my lights suddenly went out, my stereo started playing music at full volume, and my throttle went wide open.
And that's all a possibility on my 2003 car -- newer cars are moving towards doing much more with software. And where there's software, there will always be viruses.
Agreed.
I just hope that the car manufacturers will take developments like this into account, and make these systems very robust.
And it would be catastrophically poor planning on the part of car designers to make car firmware remotely modifiable. We're not talking about general purpose computers here.
However, I do presume that the victim is paying attention to their vehicle and not in a sudden emergency condition.
Who would have thought a centrifuge could be attacked in this way?
Are you sure about that? I can't imagine they'd put these autonomous driving systems on the network... Didn't Stuxnet itself require at least physical access by proxy in that it was propagated through USB drives being physically used in the victim's systems?
All it takes from there is the engineer putting the powertrain bus/ECU on the same network with the Bluetooth adapter.
As I posted below, my Saab's engine control unit can be reprogrammed by splicing a few wires onto the CD harness. That means the audio network can at least access the ECU. I don't have a Bluetooth adapter on my car, but if I did, I'd wager it can access the audio network...
http://www.reghardware.com/2011/07/06/review_cars_volvo_s60_...
Why? I'm sure they don't like recalling their cars every couple of months to fix a bug, and customers don't either.
Actually, depending how integrated are the subsystems in the car, one could just create a specially crafted MP3 and leave a CD or USB stick in the victim's car. This MP3 would work like the JailBrakeMe pdf and essentially put the victim's computer in the hands of the attacker. It's been done by security researchers, but I can't find the reference now.
Anybody else heard about that?
ps: also similar was setting "unfriendly" scanrates for unprepared CRT-s, Samsung notebook HDD "click of death".
memoryhole:
https://secure.wikimedia.org/wikipedia/en/wiki/Commodore_154...
though my all time favourite is the ping
He was often the first to break news about new understanding in the PLC related code, and at the time was given very little credit for it. Yet without him it would probably have taken a LOT longer to get to the bottom of this.
If you want an example of an interesting post from his blog: http://www.langner.com/en/2011/02/22/intercept-infect-infilt... Here he talks about a nice attack vector, that seems obvious if you have access to bits of the postal infrastructure in Germany...
And: http://www.langner.com/en/2010/11/15/417-attack-code-doing-t... Here he talks about the man in the middle attack, which meant that the PLCs reported back correct frequency/speeds to the operators, whilst doing something nasty underneath.
I'm waiting for a good book to come out that details all of the stuff in this attack. It's pretty stunning work.
When I write funny, I mean utterly tragic, wasteful and a result of a relentless propaganda campaign which has resulted in every political candidate falling over themselves to prove how committed they are to facing down the menacing Iranian threat.
Am I the only one who feels this way?
edit: not sure why opinion = downvoted.
but don't think tl;dr.
or instapaper. the design sucks indeed, suites paper format, not web.