Obama Order Sped Up Wave of Cyberattacks Against Iran
nytimes.com
nytimes.com
All else aside, this is a clear pointer to government contractors.
This is a great read and very informative!
You have to consider the audience the NY Times is targeting. Just knowing what a compiler is puts one in relatively sparse company.
Incidentally, from friends who do serious malware reversing work (we do not do any malware work): the "50x bigger, feels like pro contractors" assessment rings true for several other reasons; for instance, the style of programming used in the worm itself.
In fact, both the Israelis and the Americans had been aiming for a particular part of the centrifuge plant, a critical area whose loss, they had concluded, would set the Iranians back considerably. It is unclear who introduced the programming error.
I guess it's naive to think they might be using git and could resolve this with a simple `git blame`...
The real question, is why did the administration leak the story, and why now? Is it politically motivated because Obama wants to seem tough on Iran in an election year? Is it to trick the Iranians into thinking the program is over? Maybe versions 2, 3, and 4 are already in place, and it will be demoralizing to Iran's program if they keep getting setback.
The timing makes sense.
The latest round of multi-lateral talks on Iran's nuclear program just concluded a few days ago in Baghdad. I think they're trying to send the message to Iran that they will never be able to have a clandestine nuclear weapons program. The world is going to know about it. So if a nuclear power option is on the table for Iran this might give them a little extra motivation to accept all international regulations/inspections as a precondition. What are they actually going to be able to hide? Not much apparently.
The other goal here is to make Iran's position that they only want nuclear power, not nuclear weapons, even more difficult to accept. They are enduring sanctions and refusing to accept all of the regulations/inspections for what purpose exactly? They could have had nuclear power years ago if they were willing to accept these conditions. The longer they hide behind 'nuclear power only' the harder it is to believe. At some crucial point I have no doubt we'll be leaking detailed information about their weapons program. When that happens Iran will have to probably admit they do want nuclear weapons and from there the war question pretty much resolves itself.
From the article: "Last year, the nation announced that it had begun its own military cyberunit..."
One could argue that a nation's citizens have a moral right to know that their government is exposing them to potential retaliation by sabotaging the facilities of another sovereign nation via cyberattack.
Also from the article: "But there has been scant evidence that it has begun to strike back."
Wasn't the DigiNotar hack used by Iran to obtain fake certificates for Google domains?
You might add UK in there and UK might have assisted the US in the creation of Stuxnet if the US had asked.
I have always assumed that the world's most talented hackers work in places like Silicon Valley and Wall Street, but Stuxnet was clearly the work of some brilliant minds, so I'm curious.
See: http://news.ycombinator.com/item?id=977176 for a bit more.
As for recruiting, you wouldn't ever get recruited directly to such a project - you'd already need a TS/SCI clearance and to have proven yourself within the NSA. As for recruiting into the general field of classified cybersecurity, it's not too much different from any other field; they post job ads, scour college campuses, probably advertise at defcon, etc. Generally if you're getting hired without a clearance it's not for a specific position - it takes upwards of half a year before you get cleared and can start, at which point they figure out which project to put you in.
As for the most talented hackers, keep in mind the subject area: Wall Street has very little demand for security researchers, and Silicon Valley's demand for them is minuscule compared to the government's.
I'm woefully clueless when it comes to this realm of software, so I'd love for some insight.
They also operate a nuclear program.
They have world class technical universities.
The military is a huge employer for engineers and researchers in Israel.
If they can create and market high-tech SIGINT / ELINT / EW / COMINT systems, a nation like Israel should be able to create programs such as STUXNET. They have the know how and expertise.
In response to your question. In Israel, a small country, you have mandatory military service, a close relationship between the private sector, government and military, I think the path for an engineer is very clear cut if he or she wants to enter this domain of work. Vice versa, the government will have no problem finding you.
"Olympic Games borrowed some for what they termed "destructive testing," essentially building a virtual replica of Natanz, but spreading the test over several of the Energy Department's national laboratories to keep even the most trusted nuclear workers from figuring out what was afoot."
The engineers working on the P-1s are employed by Sandia, ORNL, LANL, Mitre, RAND, SRI, etc and are in the dark about project specifics due to compartmentalization. Want a job:
http://www.sandia.gov/careers/students_postdocs/internships/...
To me this seems to qualify as terrorism and sabotage on all accounts. I'm pretty sure I know how the US would react if they had been on the receiving end of this sort of attack.
* Iran funds Hezbolla: http://en.wikipedia.org/wiki/Funding_of_Hezbollah
* Iran funds the Islamic Jihad: http://en.wikipedia.org/wiki/Islamic_Jihad_Organization
* Iran funds Hamas: http://en.wikipedia.org/wiki/Iran%E2%80%93Israel_relations#I...
* Example of suicide bombing by the Islamic Jihad: http://www.dailymail.co.uk/news/article-2145621/Family-Danie...
I understand this is a highly-loaded political issue in the states, but, for Israel, Iranian funded terrorism is a threat in and of itself, nuclear weapon or not.
And this sort of thing is nothing new, see http://en.wikipedia.org/wiki/Siberian_pipeline_sabotage for example, and there is lots more.
The way you react is with total silence - you don't want anyone to know you were vulnerable. And that's also why these types of activities tend not to escalate.
Personally, if countries have to fight I'd prefer they do it quietly like this rather than open war. It's a lot easier to ratchet down the tensions when there has been no rhetoric about the enemy.
For example: http://en.wikipedia.org/wiki/2007_Israeli_airstrike_in_Syria - mostly silence on both parties part and no increase in hostilities.
As per history, I believe the US is the only nation that cannot be trusted with nuclear weapons.
Nobody can be trusted with nuclear weapons.
Britain would have nuked Germany to save itself if it had the opportunity and the necessity to do so, and or to bring the war to an end and kill Hitler if the opportunity were there. France too would have nuked Germany to defend itself and kill Hitler if possible. Had the Jewish people been able to, they too would not have blinked at nuking Germany and trying to kill Hitler in the process.
Japan would have nuked the United States and the rest of the allies. Germany would have nuked everybody at their leisure to 'win.'
The Empire of Japan was an extraordinarily powerful nation. Their military technology was very advanced, and they demonstrated endlessly that they were willing to use it brutally in instigation of war. They slaughtered millions upon millions in their Chinese invasion. It took a very substantial portion of America's considerable industrial base to defeat Japan.
It took two nuclear bombs before Japan capitulated with an unconditional surrender. The first one wasn't enough, which more than proves they were willing to shed millions more lives to keep fighting. America would have had to invade Japan and would have killed millions in taking the island to stop the war.
America had nukes before everybody else, and if their desire had been to do so, could have wiped out every other capital and brought the entire planet to its knees, regularly nuking anybody that dared to twitch about a nuclear program.
America also could have allowed a war to proceed with the USSR immediately after WW2, and nuked the USSR repeatedly and instantly become the sole superpower.
And in the last 67 years, America has specifically chosen to not use nuclear weapons of any sort, despite the radical military advantage that it has possessed for most of that time. Nukes in Vietnam would have ended that conflict very quickly.
It's a tragedy that Hiroshima and Nagasaki were nuked. Japan instigated war, both in general in the Pacific, and against America. Japan joined with Nazi Germany in a pact to destroy the allies. It was absolute war. I hope nobody reading this today ever has to really come to understand what that means.
Obviously the bombs killed fewer people than a full scale invasion of Japan (and from the perspective of the US, the only casulities were Japanese, not American and Japanese). But many historians would argue that a full scale invasion of mainland Japan was never going to happen after the USSR decided to engage Japan as well. The writing was on the wall.
That said, I think you have a good point using the counterfactual of what would have happend if anyone else got to the nuclear weapon first. Germany would have absolutely nuked anyone and everyone if they could. Japan might have as well (not sure what they would have used it against, maybe the Panama canal? I don't see how they could have launched one against mainland USA without an ICBM). The UK and USSR probably would have if they could.
Basically anyone that showed the stomach to firebomb entire cities would also have used the nuclear weapons of the day if they could.
It also took a couple of years before the full appreciation of the dangers of nuclear fallout became apparent. Not to mention, the nuclear weapons used in WW2 have a tiny yield in comparison to modern nuclear weapons.
On a point of detail, ironically it isn't true that 'the only casualties were Japanese." In Nagasaki there were a large number of conscripted foreign workers as well as the native Japanese population (mostly women and children).
Another good point about the firebombing. The US and UK airforce leaders were clear that if they lost the war the 1000 bomber raids onto civilian targets would likely be classified as war crimes and that they personally would be tried as war criminals.
They probably could have nuked Hawaii as well with some effort, and pushed the US forces even further back to shore and reduced our visibility / force projection.
For example during WW2 all of the major participants had chemical warfare weapons. Several, including Germany, had significant stockpiles. (Germany actually had the most effective stockpiles, though they seem to have not believed this at the time.)
The only significant use of chemical warfare was by the Japanese against other Asian countries that did not have chemical weapons. Nobody else dared use those weapons on each other for fear of the response.
And so it has remained. A lot of countries have chemical weapons. There have been a lot of wars between countries armed with them. There have been a number of threats that they would be used (for instance Iraq threatened to use them on Israel during the first Gulf war). And yet the only time they get used is against opponents who are not similarly armed. (For instance Iraq fought a bloody war against Iran without using chemical weapons - then used them on parts of its own population who they thought had been disloyal in the war.)
This fact gives me hope that we will continue to not use nuclear weapons as well.
e.g., bombing trains, airports, buildings, poisoning food supplies, etc.
Actions against the military establishment of a country can hardly be qualified as terrorism.
That said, if the US had been on the pointy end of this stick I'm sure many politicians would not have hesitated to the use the T-word themselves...
http://www.guardian.co.uk/commentisfree/2012/jan/16/iran-sci...
http://rockcenter.msnbc.msn.com/_news/2012/02/09/10354553-is...
I'm pretty sure that if you happened to be a block away when a Livermore Lab nuclear scientist was killed by a focused car bomb delivered by a motorcyclist, you'd get a little jumpy and U.S. news reports would call it terrorism.
And, U.S. officials are claiming that the bombings are being carried out by the People’s Mujahedin of Iran, a terrorist organization, and Iran's own vice-president called it an act of terrorism.
For us to call this anything other than terrorism would be hypocrisy.
It's the same reason why people get in an uproar over a random murder, but barely care when the killing was targeting a specific person.
Terrorism is random. Killing a person because of how they help the military is not terrorism even if done in public. You can call it assassination if you wish (which plenty of people condemn), but it's not terrorism.
Remember Alexander Litvinenko? (The Russian spy who was killed with plutonium.) I don't remember any exclamations of terrorism.
While there is not an internationally-agreed-upon definition of "terrorism", according to U.S. law, terrorism is defined as "premeditated, politically motivated violence perpetrated against noncombatant targets by subnational groups or clandestine agents" [4]. Premeditated, politically-motivated violence perpetrated against noncombatant targets by clandestine agents ... the Iranian car bombings would legally qualify as terrorism under U.S. law.
This is a very silly argument to be having here. I'd really rather be reading about some interesting technical aspect of the technological warfare against Iran, and I really don't want to keep on cluttering up the comments here with silliness.
[1]: http://www.rasmussenreports.com/public_content/politics/gene...
[2]: http://www.scribd.com/doc/95190520/Assessing-the-Terrorist-T..., search for "Fort Hood"
[3]: http://en.wikipedia.org/wiki/Fort_Hood_shooting
[4]: http://www.law.cornell.edu/uscode/text/22/2656f, subsection (d), paragraph (2).
The whole point of picking a specific target is that you consider them a combatant. (You don't have to shoot a gun to be a combatant, helping the military is enough.) A civilian contractor for the military can be a combatant. So no, the Iranian car bombings would not legally qualify as terrorism under U.S. law - the bombings targeted a combatant.
Intent matters too: Are you are killing a person because of that specific person? (To prevent that person from contributing to the military.) Or are you killing so that other people see the killing and get scared?
You are right that it's a silly argument because your eyes appear to be closed on the matter (although to your credit you argue constructively). So lets turn this around, in your eyes in what scenario would it be assassination and not terrorism?
I don't think there are too many other technological details to be found, so this thread is likely to end up as a huge discussion of the morals of this action.
I can assure you all killings are done with noble intent. It just matters who you ask and or listen to.
As Justice Potter Stewart said in his concurrence in Jacobellis v. Ohio, "I shall not today attempt further to define the kinds of material I understand to be embraced within that shorthand description; and perhaps I could never succeed in intelligibly doing so. But I know it when I see it, and the motion picture involved in this case is not that." (that's his complete concurrence)
The same could be true for terrorism. We know it when we see it. No objective definition necessary, so we will make do with it as a political label.
http://en.wikipedia.org/wiki/Polonium#Famous_poisoning_cases
Assassinating Iranian nuclear scientists has the concrete and (for the presumed perpetrators) desired effect of denying Iran the service of those persons. Instilling terror in other nuclear scientists is a much lower order side effect.
But if a clear causation between removing a certain actor from the game and crippling the scientist assassination program is present, I don't see why not.
It got legally redefined by the government. Is now the unlawful use of force and violence against persons or property to intimidate or coerce a government, the civilian population, or any segment thereof, in furtherance of political or social objectives.
Is now any unlawful forceful act with any wider motive, basically.
> the unlawful use of force and violence against persons or property to intimidate or coerce the US government its allies, the US civilian population, or any segment thereof, in furtherance of political or social objectives.
See, when US does it is called "exporting democracy", "conducting an operation", "liberating", "collateral damage" -- basically anything but terrorism.
so how something is reported changes its reality how? I think the spin media put on the facts creates the fear, not the facts itself. Breaking equipment is certainly not going to cause what the media might've spun it into (which is OMG nuclear meltdown OMG).
They want to keep instigating hate towards the west. I believe the leaders of that country would like their population's rage to be directed at an external entity, and not cause unrest (among other things of course).
And in any case the Chinese national firewall is utterly useless for preventing this.
I know, nuclear plant don't blow up, but you get my point.
No I don't. A physical war can also blow things up. How is a cyberwar worse?
This is not a game, it's a covert attack.
Well of course, that's the entire point! They are not trying to do entirely virtual actions à la Star Trek's A Taste of Armageddon.
However, you have to concede that at least so far the physical damage is far lower, and therefor unlike you I do regard it as better.
Lets say you did blow Mastercard up.
Worst case, the government prints money to pay off all the debts (a 'bailout' if you will). We've done this for far less than a cyber attack. There is some inflation, a lot of hand wringing about cyber security, and the world goes on. GDP might drop a bit, maybe it triggers a recession, but a year later we're back on our feet.
15 nuclear bombs could kill millions of people. Entire cities could be wiped out with 300+ years of history, architecture, irreplacable museum artifacts, etc. People in general would flee cities en mass. It would fundamentally shake the country and likely lead to the US retaliating in a nuclear war, or at least a large scale general war not seen since WW2. The US would probably roll a million man plus army across the middle east or north korea to destroy whatever country allowed the bombs to be built. That war would not be the (relatively) white gloved affair that are the current rules of engagement.
I understand hyperbole, but that statement is just false.
As long as we heed the lesson from Star Trek, episode 23, "A Taste of Armageddon" and don't make cyberwars so clean that no one bothers to end them.
Not exactly confirmed, but at least there are a few more details being (intentionally?) leaked. Good ole NYT is always ready to spill the words of unnamed 'officials', but the more interesting question is why, or why now?
Good quote. And there seems to always be a Windows PC around that auto-runs anything you stick into it.
http://www.geek.com/articles/news/new-stuxnet-usb-exploit-th...
But they aren't. There are vulnerabilities far more insidious than autorun.
> In an interesting twist, it was discovered that the Stuxnet
> malware group makes use of device drivers which were digitally
> signed to make them appear as though they originated from
> hardware vendor Realtek Semiconductor Corp. The digital
> certificate has since been revoked but it is worrying that
> malware writers seemingly had access to a private key issued to
> a trusted supplier of device drivers.All IT is just gum and bailing wire. I don't even think its possible to truly secure a non-trivial OS. I'm just surprised at how infrequent stuff like this gets found out.
There was a TED talk by Ralph langer in which he was asked if he thought the Mossad was behind Stuxnet, as that was the common belief. His response was that it must be the only cyber superpower -- the US.
What has the world come to?
Edit: For stealing the private key, I mean.
First reference to Stuxnet being U.S. government produced?
They had a binary they believed was US produced. It was Stuxnet. It was 2009.
If this software is really done by military then it's development process was following some strict military standards and regulation. and should be similar to existing other software.
Regulations like : How is software partitioned to modules? What interfaces it is using? Are this novel or existing techniques? and things like that.
So this should surprise no one. He used technology to get elected, and he will use technology to try and stop Iran without a physical military conflict.