Stuxnet is embarrassing, not amazing (2011)
rdist.root.org
rdist.root.org
Something like a botnet can run updates and patches, and you have a much easier time to iterate, optimize and also to fail in less than catastrophic ways. Sure, you lose some nodes, but you infect some nodes, so be it.
Something like Stuxnet is more like the mars rover. You eventually fire it off, and then it has to work correctly autonomously. Once the boosters are going, you cannot fix it anymore. Once Stuxnet is in that facility, there are no more patches. It has to work. And if it's discovered, you've probably blown your only chance.
In such a setup, simplicity and options with known and explored failure modes are good.
The virus itself was sophisticated in the way obfuscation was incorporated, using 4 zero-days.
https://www.thelancet.com/journals/lancet/article/PIIS0140-6...
The comments on the submitted article itself also point that out. They are worth reading.
Ironically, the author focuses on 'hiding the payload' as the thing that makes it embarrassing, as though that is self evident.
Stuxnet was a one-time operation with a very limited opportunity window. Target systems were airgapped. A large part of the success of the operation relied on a human penetrating that air gap. A successful operation would be attributed to either Israel or USA immediately. What is the benefit of obfuscation?
The benefits of being connected to the Internet are the same as before; but the benefits of the airgap are smaller than we expected them to be. Hence we would expect our preferred trade-off to swing in favour of more connections?
The list of countries America tells other countries to treat poorly is getting kinda long.
So I could actually rattle them off the top of my head once:
Myanmar
Sudan
Iran
North Korea
Cuba
That last one is a funny one, the original pariah. But like you can't go to these countries for contests, or accept prize money there, so for instance the Rubik's Cube championship can't be in Cuba, because Americans who are damned good at it can't win.
And it wasn't a very large amount of land. Sudan yeah, that was the biggest country in Africa before it split. But it was remote from where I was in Chile, much more than half the world away. Never met a Sudanese, nothing.
Now it's like Belarus, Russia, China soon, North Korea, Cuba always always, South Sudan, uh, Yemen, there's more...Libya for a while, like EVERYONE EVERYONE IS SANCTIONED.
When everybody's sanctioned, nobody's sanctioned. America is sanctioned.
A single shipment of 100 explosive rats was sent across the border and was intercepted. What resulted was a massive amount of German energy spent on trying to detect rat shipments and having to consider exploding rats in their threat model for every further operation.
Stuxnet not only delayed the the Iranian nuclear efforts, it made everything a hundred times more complex going forward because they realized not even air gapped computers were safe. Not to mention they no longer trust any of their monitoring or instrumentation, which Stuxnet made a point of faking... imagine trying to debug even the smallest issue when you don't trust a single piece of data.
I don't think it did more than delay production and destroy some really expensive centrifuges but it could have been a message like "we'll get you no matter what" in order to bring them to the table or something.
If you asked the leaders of this op, in retrospect, if they were starting off from scratch, would they accept the result we saw where Irans nuclear enrichment capabilities were delayed long enough for more information about their secret work to be known with more certainty. . .all of them would take it in a heartbeat.
It should be noted, however, that there apparently was a significant amount of animosity from the NSA towards unit 8200 for "turning up the volume" on the payload. Usually NSA really really really doesn't like catching attribution for stuff, and Mossad is more known for trying to send a message with obvious attributions (motorcycle assassinations etc). It was supposedly delivered from TAO to 8200 as a very covert weapon, and 8200 stripped off a bunch of the limitations in order to increase the odds of successfully completing the mission.
I'm not actually referencing the Wikipedia article, so I don't know if what I'm saying is reflected in there, but it's a good read either way: https://en.wikipedia.org/wiki/Operation_Olympic_Games
When the Israeli's pushed it to 11 they brought down a ton of scrutiny on the framework as a whole. Which is why people started discovering links to other sophisticated malware families - like Kaspersky's discovery that Stuxnet and Flame used the same LNK vulnerability which was not known to the public at the time. The "QWERTY" keylogger in the Snowden leaks was identified as part of the Regin malware family.
They effectively gave every nation on the planet a trail of breadcrumbs to either find western espionage tools, or strongly attribute tools they had previously found.
This also refutes most of the articles points, they _could_ have done all these things but SOP is to do the least amount of shady shit to get the job done. Being extra cool guy just makes it more likely to trigger an anti-virus system that detects a specific trick.
Snowden mentioned that they have some kind of a random operation name generator that they have to use, but people keep using it over and over to find a suitable name. I don't recall the specifics but it was in his book.
That's a smart-ass thought, and for that very reason would make it a horrible code name for such a project.
You want your code names to be totally arbitrary and have nothing to do with the project.
In WW2, the Brits managed to correctly guess quite a bit about the German anti-aircraft and anti-anti-aircraft systems from the 'clever' code names the Germans picked. See eg https://www.reddit.com/r/todayilearned/comments/bnkzdq/til_d...
Like I said Snowden did mention that NSA mandated the use of this code name generator in his book, and it was indeed random for this reason. But he also describes people used to game the system for a cool code name by simply running the generator over and over until they got one they liked :)
I would imagine that a cool name would also make it easier to sell a proposal to the brass. Prudence or not, people are easily influenced this way. It's why marketing works.
I remember thinking they could have at least used hashes of registry entries to detect the modules they were looking for if they wanted to protect the identity of target, but then again, the processor load of the hashing operations would have been a significant IoC. Stuxnet was a straight tactical hack to solve a specific problem, which was to delay that nuclear program. It was not just a threat or demonstration of capability to serve as a deterrent.
An example of a demonstration of capability was the silk road arrest, where the FBI mainly used it as a signal to create uncertainty about the absolute security of Tor hidden services, so that people understood they did not have impunity. They didn't break tor, but they showed tor wouldn't protect you if they wanted you. Stuxnet wasn't about demonstrating that they could get at you, it was to delay the nuclear program to give time to negotiations and potential outcomes other than iran achieving a weapons program.
What we call 'cyber' now is in support of variously tactical and strategic objectives, and while the criticisms of the code are valid, it's worth evaluating the tools in that higher level more abstract context as well.
So to offer an imperfect analogy, the author of this article is addressing how lame Google’s UI is, discounting the algorithm underpinning the search engine.
(I actually wouldn’t recommend Zetter’s book. It’s fairly dull, with several chapters enumerating every software failure of U.S. critical infrastructure she found during research. For once, the movie was better.)
I didn’t know there was a movie, but I found the book mostly boring too. She dived deep(ish) technically in three areas: malware, nuclear centrifuges, and policy.
Who exactly is that for? I enjoyed the long description of the program itself but I doubt most non-tech people would. The scientific background on centrifuges was painfully dry to me. By far the best part of the book was the human interest stories about the security researchers who found and reverse-engineered Stuxnet.
Alex Gibney did the adaptation, and while it’s necessarily far more superficial than the book, it’s much more engaging. It’s also nice to put faces to some of the names.
The charitable interpretation is that she wanted to write “The Book” on Stuxnet. But it seems like a weird thing for a journalist to attempt. It’s like if Carreyrou spent 100 pages describing micro-fluid physics in Bad Blood.
It's probably hard for people today to remember this, but in the heyday of "the blogosphere", blogs bounced stories back and forth between them the way you would Twitter threads today. Stuxnet was a topic like that. Lawson was just tying it to the stuff he wrote about.
We've all read Kim Zetter's book by now. Instead of bouncing thoughts she's already written about off the post --- thoughts the author probably by now agrees with? --- you'd do better to actually follow the links in the post back to Lawson's earlier posts about obfuscation, reversing, and content protection. They're still extremely interesting.
Regardless: saying that you have a better take on Stuxnet in 2022 than Nate Lawson did in 2011 is kind of an embarrassing flex.
You don't use more capability than necessary to achieve a goal.
I'm not agreeing with you about the quality of the take; I don't think we even reach that question.
If it's stupid but it works, it's not stupid. The author is missing the point by lambasting Stuxnet for not having a feature it didn't need.
Indeed. It's my understanding that to this day we don't officially know who built/launched it. Mission accomplished?
https://verveindustrial.com/resources/blog/what-is-stuxnet/
> "This second Stuxnet variant likely did not propagate from an initial infection on a susceptible PLC or controller, but rather gained access to one commodity Windows system through the use of zero-day exploits. From that one infected commodity Windows host, the malware moved laterally from one Windows box to another across the unsegmented network."
Once it had been done once, similar attacks followed by other nation-states:
> "From a historical perspective, the Stuxnet worm signaled that well-equipped, nation-state-sponsored actors possessed advanced capabilities that would set the stage for more serious cyber-physical attacks such as those in Ukraine, Estonia, and Saudi Arabia."
I suppose one positive effect has been the upgrading of security for everything relying on industrial controls systems and PLCs, from nuclear reactors to railways to water supply systems.
(That's also why the "there was no special obfuscation" commentary is silly -- they just don't care. Obfuscation is pointless window dressing in these scenarios.)
1) you never empty the barn on a nation state attack. If you know the systems you’re targeting are primitive, you don’t go in with the F-35 of initial compromise schemas. Aim for +10 over the enemies ability to counter, not +1000.
2) the level of overestimation of federal cyber weapons is too damn high. Is it impressive? Absolutely. Is it the best? No. Check in with your private Israeli intel firms for that kind of James Bond stuff. What sets nation states apart are their ability to acquire and perform highly redundant and critically targeted attacks. The NSA would be hamstrung without the cooperation of the CIA and so on. It’s not technical prowess, it’s money and coordination.
- have a large enough set of input parameters that it’s infeasible to guess-attack them, but risk even just a single parameter not being correct in your target system and therefore your payload never executed (completely undermining the entire operation)
- your key space has enough variability input to prevent the above, making it easy to guess or brute-force, and revealing the payload trivially.
Also, it would either way be easy for your target to reverse because they have full access to the target parameters.
Lots of other Stuxnet articles/revelations.
Here's some previous discussions:
11 years ago https://news.ycombinator.com/item?id=2112919
3 years ago https://news.ycombinator.com/item?id=21432467
Imagine the outrage "how dare you" and "attack on the constitution and national integrity of the country" and "causus belli" among other things but its being made as an achievement. Isn't this american propaganda?
That having been said, if Iranian agents were able to conduct a similar operation in the US on a US weapons-grade enrichment program, my personal opinion, as somebody categorically in favor of nuclear non-proliferation and long-term disarmament, would be "Well done, point to your team."
https://www.i24news.tv/en/news/middle-east/levant-turkey/165...
Of course you know this.
>i24NEWS is an Israeli-based international 24-hour news and current affairs television channel located in Jaffa Port, Tel Aviv, Israel.
"imminent" threat after the killing of a senior Islamic Revolutionary Guards Corps (IRGC) officer attributed to Israel's national intelligence agency, Mossad.
Being just like hundreds of other malware seems to be a pretty good idea. Blending in is a big part of spy tradecraft.
"Iran is closer than ever to a nuclear weapon as Biden runs out of options".
https://trumpwhitehouse.archives.gov/briefings-statements/pr...
https://foreignpolicy.com/2020/05/08/iran-advances-nuclear-p...
Okay? … simplicity is a virtue.
They also addressed that, to where we don’t know what most of their malware even does:
>> The name originated from the group's extensive use of encryption. By 2015, Kaspersky documented 500 malware infections by the group in at least 42 countries, while acknowledging that the actual number could be in the tens of thousands due to its self-terminating protocol.
> The longer they remained undetected, the more systems that could be attacked and the longer Stuxnet could continue evolving as a deployment platform for follow-on worms.
Stuxnet wasn’t meant as a long term penetration: they hit a specific target with a one-time cyber weapon.
For reference, when their tools leaked in 2016, exploits from 2013 were still zero-days.
>> In August 2016, a hacking group calling itself "The Shadow Brokers" announced that it had stolen malware code from the Equation Group. […] The most recent dates of the stolen files are from June 2013, thus prompting Edward Snowden to speculate that a likely lockdown resulting from his leak of the NSA's global and domestic surveillance efforts stopped The Shadow Brokers' breach of the Equation Group.
Source:
Sometimes, yeah, you need to rush things because your window of opportunity is now or never.
It’s not surprising that a small independent consultant would bikeshed over trivial imperfections in something like Stuxnet while ignoring the much bigger picture of the operation. I bet the vast majority of security holes he finds in his line of work are relatively minor exploits (e.g. poor key handling, unpatched software, etc.) that would be devastating to his small business client if exploited but totally irrelevant to an operation like Stuxnet. It is akin to a custom gunsmith criticizing an ICBM for its ugly paint job.
As Pauli would say, Lawson’s argument is not only not right, it is not even wrong.
[0] https://www.linkedin.com/in/natelawson
[1] http://www.rootlabs.com/ (yes, his own site ironically is not HTTPS)
Either way, for the mission goals it was a success.
I actually asked a criminal I was in contact with once why he didn't attempt to perform an attack a certain way that I thought would be very lucrative and significant. His answer was that there was no point, he made thousands of dollars a month with very little effort, and he was more interested in refining his existing work through improved C2 communications as opposed to what I had been suggesting (academically, I never supported that work).
The title's a bit clickbaity too of course. The end is more reasoned:
> However, I think the final explanation is most likely. Whoever developed the code was probably in a hurry and decided using more advanced hiding techniques wasn’t worth the development/testing cost.
Yes, naturally that is exactly what happened. There is no question at all that the NSA has people capable of doing more advanced work, they just really don't have to.
https://www.youtube.com/watch?v=bDJb8WOJYdA
Rob Joyce gives a great talk about his work on TAO. The short version is that TAO doesn't have to do anything crazy, they just have to know who their target is and spend the time figuring out the environment they'll be working in - then they meet the bar that's beyond what that environment is capable of handling.
Homomorphic encryption is gonna be pretty overkill. Then again, the NSA also leveraged the first publicly known attack that used an MD5 collision, which probably cost quite a bit of money, so they can flex when they decide it's worth it.
He also co-developed the content protection system for Bluray and was a FreeBSD committer.
Judge the words, not the person.
Also, with this encryption based approach, at some point the code needs to run on the systems it targets. So if someone is affected by your payload, by definition they can observe a key that unlocks the payload.