Skip to content

Comment on Stuxnet is embarrassing, not amazingparent

Comments

He's challenging the near-hagiographic conventional wisdom that Stuxnet's sophistication is a clear sign of its intelligence lab origins.

I thought this conventional wisdom was based on the success of stuxnet, once delivered, at having the desired effect on the centrifuge. The article appears to be based on techniques used in delivery of the payload, not the payload itself.

An expertly constructed industrial sabotage malware might have taken more steps to obscure itself simply so that it could leave the same avenue of attack open to itself in the future, perhaps at a different target. That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.

That alone seems argue against this being the handiwork of the "best & brightest" in the US intelligence community.

Noob question: is it widely believed in the security community that the US intelligence community has lots of 'the best and the brightest' when it comes malware construction?

I only ask because I recall a bit of Jane Mayer's book that explained that post-9/11, the CIA didn't have any professional interrogators on staff because they weren't in the business of holding prisoners in custody to interrogate. Just curious if a similar phenomena might be at work.

NSA is a hiring pipeline for software security. Some very, very talented exploit developers have come out of NSA.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.