Hackers Plundered Israeli Defense Firms that Built ‘Iron Dome’ Missile Defense
krebsonsecurity.com
krebsonsecurity.com
That is why there are also things like the TROPHY system for Israel's Merkava tanks or lighter APC like vehicles:
http://www.youtube.com/watch?v=4eCUCBS1SVk
http://en.wikipedia.org/wiki/Trophy_(countermeasure)
Israel is no stranger when it comes to rocket threats and has multiple countermeasures. So far, it seems to work pretty well overall when you look at the number of Israeli casualties due to incoming rocket fire. For the number of shots fired into the country, it is remarkably low even with the horrible accuracy of the rockets being fired.
I mean there aren't that many places in the world where you could sell that. I still wonder if any tech developed by iron dome is really useful at all for terrorits, Russia or china.
I mean if hamas really has enough resource to build stealth rockets, or rockets than would be able to dodge iron dome, but I don't think they really have the resources to develop such thing.
Also, just copying is going to lead you down strange alleys. I can recall one proposed engineering change to a drawing so that the drawing had the actual bolt hole size on it, not some smaller size. Yes, that's right, the 15 year old drawing had smaller bolt holes specified than actually were on the real, physical hatches. Stuff like that happens all the time. A simple copy might not be flightworthy, much less fit to assemble.
You're grossly underestimating the amount of work that goes into fasteners and how hard it would be to choose ISO, or Russian or Chinese equivalents.
As for the psychology of your secrets being out there, we used to wonder who in the company was leaking info to "Aviation Week". Every project I worked on that had a feature in "Aviation Week" had no general secrets. It was all there, in detail.
It's similar to why there's a market for complete tear downs of electronics--competitors are interested in the guts and components even if they never intend to rip it off. Knowing how someone else solved the same problem you're working on is always valuable.
I suppose CAD has eliminated a lot of the need for iron bird-style copies, but maybe not.
And Mossad is a lot less fussy about using what one SIS officer called the "bumping off squad".
I've worked at several places who moved, changed and deleted projects on various servers on a regular basis during the course of a big project.
That being said, Israel and the US are a decade ahead of the Chinese in UAV technology and they know it. Letting us do the R&D and them steal the secrets is certainly an expedient way to close that gap.
I've no doubt a state might be able to come up with a counter-measure based on this, but it would not at all be cheap or easy to implement (and Iron Dome doesn't work well enough to justify it in a normal war situation).
This was the basic technology advantage the US had over the Soviets during the Cold War. Russians had access to our designs (the captured a lot of our weapons) but did not have the ability to fabricate the required materials at the precision required to effect their own copies of the capability.
Besides, it's never a purely technological advantage. There needs to be doctrine and well-trained troops in place too.
I was a Soldier for over a decade. Engineers and computer scientists are what makes our military great. Most nations have well-trained Soldiers. Many nations even have larger quantities of highly trained Soldiers than we do.
The average citizen seems to think of basic training like its the Special Forces selection course. Basic training is incredibly easy. Its supposed to be easy, that's why its called basic training.
Don't get me wrong, there are lots of good Soldiers in the U.S., but there is nothing inherently superior about the American fighting man. That kind of attitude makes it sound like we are some kind of master race.
I'm very familiar with the engineers and computer scientists you refer to.
It seems like you're scoffing at the idea that only a national government could produce software that is "that good," or maybe even that they could at all, but mere code quality is not the whole basis for the claim. It's also the (initially) extremely precise target, the intelligence needed to affect the physical results they were after (disruption of uranium enrichment centrifuges), and the unprecedented effort to cover all tracks of the worm.
Ralph Langner, whose team did a lot of the primary technical investigation into the worm, has said "the leading force behind Stuxnet is the cyber superpower – there is only one; and that's the United States."
Here's his hour-long technical breakdown (with code): http://www.digitalbond.com/blog/2012/01/31/langners-stuxnet-...
His TED talk on Stuxnet: http://www.ted.com/talks/ralph_langner_cracking_stuxnet_a_21...
A less technical article, which Schneier reposted as "the definitive analysis of Stuxnet [short version]": http://www.foreignpolicy.com/articles/2013/11/19/stuxnets_se...
There are also numerous bits of circumstantial evidence detailed on Wikipedia. A former Vice Chairman of the Joint Chiefs of Staff was put under investigation by the DoJ last year for allegedly leaking info on Stuxnet and "Operation Olympic Games." At this point it's all but certain, I think one would need a pretty good reason to be doubtful.
It's entirely the notion that it could only have been state sponsored that I have trouble with. While there may be no organization with resources comparable to the US government to throw at cyber security in general, there are certainly organizations which can throw large resources at any given particular problem.
Of course, other organizations that might have had the resources to create Stuxnet wouldn't have had the motive or the relevant context (knowledge of details of Iran's nuclear enrichment program) to do so. In that regard I don't doubt in the slightest that it was state sponsored malware, but I think it's dangerous to claim that anything could only have been state sponsored, as it accords a level of resourcing to the state that likely also applies to, e.g., organized crime or exceptionally large corporations who might not have our best interests at heart (not that I think the state always does either, mind you).
That said, my original question was genuine. I didn't follow Stuxnet after the initial speculation that it looked like a state sponsored project, and thus I didn't know whether we'd been officially caught or whether it was still (extremely well founded) speculation.
(Of course, this requires the intrusion to be detected before it is over.)
EDIT: See https://en.wikipedia.org/wiki/Siberian_pipeline_sabotage , with the caveat that it's not clear how real the story is.
The Americans (TV Series) had a couple of themes based around this - it's not exactly a secret strategy and receivers of information know to verify what they get before getting too excited.
Since we're talking about government actors here, nowadays they would not be easily fooled and would have skilled engineers checking stuff no matter what, so that is not going to add any 'cost' to the operation. People in the espionage game learn pretty quickly or they don't get to play for very long.
It might cause some confusion from time to time, such as with new staff, and of course some dumb person will end up mentioning the practice in a document, thus blowing the secret. But it will still make the intruders' job harder.
Too bad I can't find it, it was an interesting read.
...ya I don't think you'll phone home either.
You have to realize these hackers are people who have to deal with honeypots & law enforcement without getting infected/exposed/whatever. They are going to take some precautions if they are to be successful in the long run.
I've not seen them; if you have links handy I'd like to go read some more.
My understanding was that they were managing between 80-90% success rate for the targets they aimed for (which is pretty good) but also that they were deliberately leaving any rockets that were obviously not going to hit anything important.
https://www.google.com/search?q=postol+iron+dome
"all these articles" = commentary on that one article by Postol.
1: http://thebulletin.org/evidence-shows-iron-dome-not-working7...
For example, imagine if several rockets are fired at a hospital. Iron Dome intercepts the rockets, throwing them off course. The rockets then land in parks and parking lots, killing no one.
Under Postol's standards, that's a complete failure. Because the warheads weren't destroyed.
But most people would judge that as a major success.
Assuming the rockets are reasonably accurate and targeted to do the most damage possible, simply damaging the rockets and changing their path is a success.
I'm saying this hesitantly, because it has the potential for things to go off the rails into a flame war, but the rockets are very inaccurate -- literally hitting the side of a barn would be a good strike. Damaging them probably reduces the chances of them hitting a high-value target by a few percentage points, but they have no targeting systems on board. They are flung in a general area, and landing in place X or place Y in that general area isn't too much different.
There are also significant psychological factors at play.
Can you imagine the shitstorm that would come out of something like that leaking?
A necessary prerequisite to a missile defense system is a way of telling where rockets are going. Even if they don't have the first, they probably have the second.
Watching from the outside, I have no particular reason to believe one side or the other.
This whole argument smells like a modern military getting everybody to believe that "Iron Dome is 95% effective", just like everybody knows that the Patriot system was 95% or more effective during Desert Storm I. Or like everybody knows that WMD were found in Iraq after the USA invaded.
That is, Iron Dome is more of a propaganda tool than a real defense system, or maybe its more of a way to funnel money to Rafael and IAI than a real defense system. I doubt we'll ever know. Statistically speaking, there's only a few real secrets, but there's lots and lots of career-ending blunders, accounting oddities, and systems gaming.