Stuxnet worked. Very well. It was out in the wild, by best estimates, for over two years before it was detected. During that time it caused complete chaos within the Iranian nuclear program (to the point where some officials were executed on the suspicion of espionage).
This post and its backhanded compliments are very arrogant in a way that epitomizes everything that is wrong with the security industry. It is a game of one-upmanship amongst those who can talk the talk but not walk the walk. This blog post is basically:
Dear most successful team of virus and backdoor writers in history who completely changed the paradigm for what worms can do, I suggest you read this book that I probably know nothing about or haven't read and definitely do not understand.
Ps. here are a ton of links to stuff I googled that you didn't do,
pss. isn't it awesome that you are anonymous and can't respond to my criticism?
psss. Did you get the part about me being smart?
Pathetic. To make it worse, the entire industry is full of such assholes.
Nate Lawson is not trying to one-up anyone in the security industry. He works on a level above most of the rest of us, spending most of his time on hardware and cryptosystem projects. To imply that he's part of the Black Hat vulnerability research bugfinding rate race is to betray a comprehensive lack of understanding of how our field is structured.
I'd challenge you to find any reputable party in that field to challenge this summary. There's a whole Twitterverse of security experts that will back me up on this. Nate's not an egotist, and that's not where this post is coming from.
The place Nate is coming from is one of skepticism. He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins. If Stuxnet isn't particularly sophisticated, that doesn't mean it wasn't set into motion by nation-state actors, or that it was ineffective, but it does knock down one factor in most of the discussions about the importance of "cyber warfare". Maybe Iran's nuclear plants were simply absurdly exposed to IT-based attacks due to sheer incompetence.
He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins.
I thought this conventional wisdom was based on the success of stuxnet, once delivered, at having the desired effect on the centrifuge. The article appears to be based on techniques used in delivery of the payload, not the payload itself.
An expertly constructed industrial sabotage malware might have taken more steps to obscure itself simply so that it could leave the same avenue of attack open to itself in the future, perhaps at a different target. That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.
That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.
Noob question: is it widely believed in the security community that the US intelligence community has lots of 'the best and the brightest' when it comes malware construction?
I only ask because I recall a bit of Jane Mayer's book that explained that post-9/11, the CIA didn't have any professional interrogators on staff because they weren't in the business of holding prisoners in custody to interrogate. Just curious if a similar phenomena might be at work.
You inferred Nate's motives from his post and judged him an asshole for writing it. You are comprehensively wrong. I wouldn't be the only person in the industry to stay that you're wrong almost on the face of the matter just by implying that Nate's part of the vulnerability research "community"; he isn't.
I don't see how it could be interpreted in any other way. He referred to what is probably the most successful hack in history as 'embarrassing' without any real argument to back up his claim.
If Stuxnet fizzled out quickly, didn't work and exposed who was behind it, then I imagine it being an 'embarrassment' (in the way that the Dubai assassination could be referred to as an embarrassment). That situation could have called for a post outlining 'they did this part wrong, they could have tried this' (in the same way Schneier wrote about Dubai)
But the fact that Stuxnet was a blazing success, took years (unheard of) to be captured, months to be analyzed and totally broke new ground that everybody (lest the author of the post) didn't understand five months ago, nullifies all of the 20-20 hindsight theoretical feature improvement arguments made in the post.
The part I'm calling embarrassing is the lack of sophistication. If I were in the NSA and we had implemented this, I would be embarrassed.
What would make me proud is year upon year of subtle equipment failure that could not be attributed to any particular cause. When it was discovered years later, it would appear to be an innocent software bug. That's an overwhelming success.
When confronted with facts, you editorialize based on unsourced or anonymously sourced narrative journalism accounts in the mainstream press. Meanwhile, the points you make aren't even incompatible with his analysis.
Did you actually read the article, or are you too upset by the suggestion that Stuxnet was inexpertly constructed?
I don't happen to share Nate's opinion that Stuxnet is embarrassing, but I think your characterization of him based on his blog post is pretty off-base.
You said "This blog post is basically:", which I took to mean that you referring to him specifically (as he is the author of the blog post). I apologize if you weren't targeting him specifically.
Many in security are indeed condescending, although I don't find it to be more true than in the computer community at large; especially amongst programmers (who seem to feel an almost intrinsic need to disparage someone else's opinion about a language or design choice).
It might just be that we travel in different circles, but I actually am constantly impressed with how helpful and non-condescending most folks in the security community are. I frequently ask questions of people on Twitter who are among the best in the industry and I generally get really helpful replies (as helpful as you can be in 140 characters).
And I don't know Nate personally (I only refer to him by his first name because "Mr. Lawson" has a bit too much of a "Agent Smith" vibe to it), but I've never gotten the impression from anything he's written that he's smug or especially competitive about the infosec industry.
I got into tech via the security industry, so all my experience dates back to 10+ years ago when I left it. Since then I have only kept up with the more mainstream stories and the odd blog post.
I did make a sweeping generalization, and if it seems like I am holding a grudge it is probably because I am. I went through a lot of bad issues and arguments through the process of publishing articles, advisories, exploits etc. Enough to turn me (and many others) off for good.
I don't doubt that there are very good people out there in the netsec space, it just seems that every time a story floats up onto my radar it reminds me of the same issues we dealt with all that time ago (ie. pointless arguments, point-counter-point, one-upmanship, eliteness etc.). I recognized the template of that post pretty quickly, and it simply isn't constructive.
For all I know Nate could be awesome, but as somebody who only knows of him through the paragraphs I just read he fits the old stereotype that I am familiar with pretty well. But outside of the first line, the rest of what I wrote was more about that old template of how subjects, even as big and awesome as Stuxnet, are dealt with and written off by some in the sec industry.
You picked a uniquely bad person to use an example of the excesses of the security industry. It's too bad, because I probably could have agreed with most of your issues, but now I think you're a crank.
I opted out of software security ~10+ years ago too (I went from software vulnerability research to streaming media and multicast and then ISP operations software and then marketing). Coincidentally, that was about the same time Nate stopped being one of the world's better software vulnerability researchers and moved headlong into cryptography and hardware. He's a friend and I don't speak for him, but I'm guessing his move was made for similar reasons as yours.
I would hope the takeaway from my post is not "hey, this guy is so smart" but instead "hey, this hype about this malware sample is definitely overblown because he is citing really old work here".
I'm sorry you think it's arrogant. If I were to talk to the authors, I'm sure they'd say either: "yeah, it wasn't our cleanest work but we had a tight deadline" or "thanks for the tip, we never heard of secure triggers."
Any high-end agency would never say the latter, so either there were severe time pressures or this was Team B. The narrative that this is highly polished work of a high-end agency (4! I mean 3 0-days!) is not supported by evidence.
Stuxnet worked. Very well. It was out in the wild, by best estimates, for over two years before it was detected.
How long it was out in the wild doesn't matter though: what matters is how long it infected the target machines.
During that time it caused complete chaos within the Iranian nuclear program (to the point where some officials were executed on the suspicion of espionage).
How do we know that the people being executed were innocent as opposed to people committing espionage? I mean, if Stuxnet caused Iranian counterintelligence to discover an Israeli operative, then I'm not sure that's a win: delaying the program by an unspecified amount of time at the cost of lots of dollars and the loss of some operatives doesn't seem like a win to me. But this is all very speculative, so who knows.
Is there a good source justifying the "complete chaos" claim? Or the executions?
"I mean, if Stuxnet caused Iranian counterintelligence to discover an Israeli operative, then I'm not sure that's a win"
I should have clarified. The Iranians, according to reports, resorted to firing, jailing and executing their own scientists and engineers because they couldn't figure out why the operation was going so wrong.
Apparently they replaced all equipment, re-programmed the centrifuges etc. etc. until they thought they eliminated everything except for the actual people involved - at which point they became paranoid and the firing, jailing, executions started.
Here are some of the links I bookmarked, I didn't grab them all but as I find them in my history I will paste them here.
"“Intelligence sources report information reaching the West in the past week that Iran has put to death a number of atomic scientists and technicians suspected of helping plant the Stuxnet virus in its nuclear program.”
Note it says 'suspected', another source I recall was more firm on the employees not being involved (they innocently helped spread the virus through USB disks etc.) but the level of paranoia in Iran was so high that they needed a scapegoat.
This all started with the centrifuges wearing out, having to be replaced, debugged etc. and uranium production being set back by years. Two good sources on this aspect:
Comments
Stuxnet worked. Very well. It was out in the wild, by best estimates, for over two years before it was detected. During that time it caused complete chaos within the Iranian nuclear program (to the point where some officials were executed on the suspicion of espionage).
This post and its backhanded compliments are very arrogant in a way that epitomizes everything that is wrong with the security industry. It is a game of one-upmanship amongst those who can talk the talk but not walk the walk. This blog post is basically:
Dear most successful team of virus and backdoor writers in history who completely changed the paradigm for what worms can do, I suggest you read this book that I probably know nothing about or haven't read and definitely do not understand. Ps. here are a ton of links to stuff I googled that you didn't do, pss. isn't it awesome that you are anonymous and can't respond to my criticism? psss. Did you get the part about me being smart?
Pathetic. To make it worse, the entire industry is full of such assholes.
Nate Lawson is not trying to one-up anyone in the security industry. He works on a level above most of the rest of us, spending most of his time on hardware and cryptosystem projects. To imply that he's part of the Black Hat vulnerability research bugfinding rate race is to betray a comprehensive lack of understanding of how our field is structured.
I'd challenge you to find any reputable party in that field to challenge this summary. There's a whole Twitterverse of security experts that will back me up on this. Nate's not an egotist, and that's not where this post is coming from.
The place Nate is coming from is one of skepticism. He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins. If Stuxnet isn't particularly sophisticated, that doesn't mean it wasn't set into motion by nation-state actors, or that it was ineffective, but it does knock down one factor in most of the discussions about the importance of "cyber warfare". Maybe Iran's nuclear plants were simply absurdly exposed to IT-based attacks due to sheer incompetence.
He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins.
I thought this conventional wisdom was based on the success of stuxnet, once delivered, at having the desired effect on the centrifuge. The article appears to be based on techniques used in delivery of the payload, not the payload itself.
An expertly constructed industrial sabotage malware might have taken more steps to obscure itself simply so that it could leave the same avenue of attack open to itself in the future, perhaps at a different target. That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.
That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.
Noob question: is it widely believed in the security community that the US intelligence community has lots of 'the best and the brightest' when it comes malware construction?
I only ask because I recall a bit of Jane Mayer's book that explained that post-9/11, the CIA didn't have any professional interrogators on staff because they weren't in the business of holding prisoners in custody to interrogate. Just curious if a similar phenomena might be at work.
NSA is a hiring pipeline for software security. Some very, very talented exploit developers have come out of NSA.
I'd challenge you
I don't understand, what are you challenging me to? That was the entire point of my rant.
You inferred Nate's motives from his post and judged him an asshole for writing it. You are comprehensively wrong. I wouldn't be the only person in the industry to stay that you're wrong almost on the face of the matter just by implying that Nate's part of the vulnerability research "community"; he isn't.
I don't see how it could be interpreted in any other way. He referred to what is probably the most successful hack in history as 'embarrassing' without any real argument to back up his claim.
If Stuxnet fizzled out quickly, didn't work and exposed who was behind it, then I imagine it being an 'embarrassment' (in the way that the Dubai assassination could be referred to as an embarrassment). That situation could have called for a post outlining 'they did this part wrong, they could have tried this' (in the same way Schneier wrote about Dubai)
But the fact that Stuxnet was a blazing success, took years (unheard of) to be captured, months to be analyzed and totally broke new ground that everybody (lest the author of the post) didn't understand five months ago, nullifies all of the 20-20 hindsight theoretical feature improvement arguments made in the post.
The part I'm calling embarrassing is the lack of sophistication. If I were in the NSA and we had implemented this, I would be embarrassed.
What would make me proud is year upon year of subtle equipment failure that could not be attributed to any particular cause. When it was discovered years later, it would appear to be an innocent software bug. That's an overwhelming success.
When confronted with facts, you editorialize based on unsourced or anonymously sourced narrative journalism accounts in the mainstream press. Meanwhile, the points you make aren't even incompatible with his analysis.
Did you actually read the article, or are you too upset by the suggestion that Stuxnet was inexpertly constructed?
I don't happen to share Nate's opinion that Stuxnet is embarrassing, but I think your characterization of him based on his blog post is pretty off-base.
It wasn't a specific characterization of Nate, but rather a generalized, overly sarcastic and sweeping view of the security industry as a whole.
Many in security are just far too condescending, as this post was (not just wrong, but smug to boot).
For some reason there is a constant, tense competition between netsec bloggers and personalities for absolutely no reason. It is ridiculous.
You said "This blog post is basically:", which I took to mean that you referring to him specifically (as he is the author of the blog post). I apologize if you weren't targeting him specifically.
Many in security are indeed condescending, although I don't find it to be more true than in the computer community at large; especially amongst programmers (who seem to feel an almost intrinsic need to disparage someone else's opinion about a language or design choice).
It might just be that we travel in different circles, but I actually am constantly impressed with how helpful and non-condescending most folks in the security community are. I frequently ask questions of people on Twitter who are among the best in the industry and I generally get really helpful replies (as helpful as you can be in 140 characters).
And I don't know Nate personally (I only refer to him by his first name because "Mr. Lawson" has a bit too much of a "Agent Smith" vibe to it), but I've never gotten the impression from anything he's written that he's smug or especially competitive about the infosec industry.
I got into tech via the security industry, so all my experience dates back to 10+ years ago when I left it. Since then I have only kept up with the more mainstream stories and the odd blog post.
I did make a sweeping generalization, and if it seems like I am holding a grudge it is probably because I am. I went through a lot of bad issues and arguments through the process of publishing articles, advisories, exploits etc. Enough to turn me (and many others) off for good.
I don't doubt that there are very good people out there in the netsec space, it just seems that every time a story floats up onto my radar it reminds me of the same issues we dealt with all that time ago (ie. pointless arguments, point-counter-point, one-upmanship, eliteness etc.). I recognized the template of that post pretty quickly, and it simply isn't constructive.
For all I know Nate could be awesome, but as somebody who only knows of him through the paragraphs I just read he fits the old stereotype that I am familiar with pretty well. But outside of the first line, the rest of what I wrote was more about that old template of how subjects, even as big and awesome as Stuxnet, are dealt with and written off by some in the sec industry.
You picked a uniquely bad person to use an example of the excesses of the security industry. It's too bad, because I probably could have agreed with most of your issues, but now I think you're a crank.
I opted out of software security ~10+ years ago too (I went from software vulnerability research to streaming media and multicast and then ISP operations software and then marketing). Coincidentally, that was about the same time Nate stopped being one of the world's better software vulnerability researchers and moved headlong into cryptography and hardware. He's a friend and I don't speak for him, but I'm guessing his move was made for similar reasons as yours.
I would hope the takeaway from my post is not "hey, this guy is so smart" but instead "hey, this hype about this malware sample is definitely overblown because he is citing really old work here".
I'm sorry you think it's arrogant. If I were to talk to the authors, I'm sure they'd say either: "yeah, it wasn't our cleanest work but we had a tight deadline" or "thanks for the tip, we never heard of secure triggers."
Any high-end agency would never say the latter, so either there were severe time pressures or this was Team B. The narrative that this is highly polished work of a high-end agency (4! I mean 3 0-days!) is not supported by evidence.
Stuxnet worked. Very well. It was out in the wild, by best estimates, for over two years before it was detected.
How long it was out in the wild doesn't matter though: what matters is how long it infected the target machines.
During that time it caused complete chaos within the Iranian nuclear program (to the point where some officials were executed on the suspicion of espionage).
How do we know that the people being executed were innocent as opposed to people committing espionage? I mean, if Stuxnet caused Iranian counterintelligence to discover an Israeli operative, then I'm not sure that's a win: delaying the program by an unspecified amount of time at the cost of lots of dollars and the loss of some operatives doesn't seem like a win to me. But this is all very speculative, so who knows.
Is there a good source justifying the "complete chaos" claim? Or the executions?
"I mean, if Stuxnet caused Iranian counterintelligence to discover an Israeli operative, then I'm not sure that's a win"
I should have clarified. The Iranians, according to reports, resorted to firing, jailing and executing their own scientists and engineers because they couldn't figure out why the operation was going so wrong.
Apparently they replaced all equipment, re-programmed the centrifuges etc. etc. until they thought they eliminated everything except for the actual people involved - at which point they became paranoid and the firing, jailing, executions started.
Where are these reports? I haven't seen them in any of the more, ah, reputable media, but I may have missed them.
Here are some of the links I bookmarked, I didn't grab them all but as I find them in my history I will paste them here.
"“Intelligence sources report information reaching the West in the past week that Iran has put to death a number of atomic scientists and technicians suspected of helping plant the Stuxnet virus in its nuclear program.”
http://www.securityweek.com/did-iran-execute-nuclear-facilit...
Note it says 'suspected', another source I recall was more firm on the employees not being involved (they innocently helped spread the virus through USB disks etc.) but the level of paranoia in Iran was so high that they needed a scapegoat.
This all started with the centrifuges wearing out, having to be replaced, debugged etc. and uranium production being set back by years. Two good sources on this aspect:
* http://www.globalsecuritynewswire.org/gsn/nw_20101123_2990.p...
* http://www.haaretz.com/news/international/iran-pauses-uraniu...