Skip to content

Comment on Stuxnet is embarrassing, not amazingparent

Comments

Nate Lawson is not trying to one-up anyone in the security industry. He works on a level above most of the rest of us, spending most of his time on hardware and cryptosystem projects. To imply that he's part of the Black Hat vulnerability research bugfinding rate race is to betray a comprehensive lack of understanding of how our field is structured.

I'd challenge you to find any reputable party in that field to challenge this summary. There's a whole Twitterverse of security experts that will back me up on this. Nate's not an egotist, and that's not where this post is coming from.

The place Nate is coming from is one of skepticism. He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins. If Stuxnet isn't particularly sophisticated, that doesn't mean it wasn't set into motion by nation-state actors, or that it was ineffective, but it does knock down one factor in most of the discussions about the importance of "cyber warfare". Maybe Iran's nuclear plants were simply absurdly exposed to IT-based attacks due to sheer incompetence.

He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins.

I thought this conventional wisdom was based on the success of stuxnet, once delivered, at having the desired effect on the centrifuge. The article appears to be based on techniques used in delivery of the payload, not the payload itself.

An expertly constructed industrial sabotage malware might have taken more steps to obscure itself simply so that it could leave the same avenue of attack open to itself in the future, perhaps at a different target. That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.

That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.

Noob question: is it widely believed in the security community that the US intelligence community has lots of 'the best and the brightest' when it comes malware construction?

I only ask because I recall a bit of Jane Mayer's book that explained that post-9/11, the CIA didn't have any professional interrogators on staff because they weren't in the business of holding prisoners in custody to interrogate. Just curious if a similar phenomena might be at work.

NSA is a hiring pipeline for software security. Some very, very talented exploit developers have come out of NSA.

I'd challenge you

I don't understand, what are you challenging me to? That was the entire point of my rant.

You inferred Nate's motives from his post and judged him an asshole for writing it. You are comprehensively wrong. I wouldn't be the only person in the industry to stay that you're wrong almost on the face of the matter just by implying that Nate's part of the vulnerability research "community"; he isn't.

I don't see how it could be interpreted in any other way. He referred to what is probably the most successful hack in history as 'embarrassing' without any real argument to back up his claim.

If Stuxnet fizzled out quickly, didn't work and exposed who was behind it, then I imagine it being an 'embarrassment' (in the way that the Dubai assassination could be referred to as an embarrassment). That situation could have called for a post outlining 'they did this part wrong, they could have tried this' (in the same way Schneier wrote about Dubai)

But the fact that Stuxnet was a blazing success, took years (unheard of) to be captured, months to be analyzed and totally broke new ground that everybody (lest the author of the post) didn't understand five months ago, nullifies all of the 20-20 hindsight theoretical feature improvement arguments made in the post.

The part I'm calling embarrassing is the lack of sophistication. If I were in the NSA and we had implemented this, I would be embarrassed.

What would make me proud is year upon year of subtle equipment failure that could not be attributed to any particular cause. When it was discovered years later, it would appear to be an innocent software bug. That's an overwhelming success.

When confronted with facts, you editorialize based on unsourced or anonymously sourced narrative journalism accounts in the mainstream press. Meanwhile, the points you make aren't even incompatible with his analysis.

Did you actually read the article, or are you too upset by the suggestion that Stuxnet was inexpertly constructed?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.