That's a nice-sounding narrative, but no assessment of Stuxnet indicates that it foreclosed on Iran's nuclear capability, and if it actually is an intelligence service attack on a foreign industrial process, the fact that it's been analyzed in the New York Times seems to suggest that it wasn't very competently done.
A big part of Nate's point in this article is that the virus and DRM communities have known for over a decade how to take programs like this and make them hard to analyze. Nate is pointing out that nothing like that seems to have been done here.
Note that Nate was a key contributor to the as-yet-unbroken† Blu-Ray BD+ DRM scheme, which he worked on in his last couple years at Paul Kocher's infamous Cryptography Research. Here he is going out of his way to cite well known, public sources for methods that would have allowed an intelligence agency to carry out this attack without broadcasting to the world "AIR GAP ALL YOUR NUCLEAR FACILITIES IMMEDIATELY OR YOU WILL LOSE YOUR CENTRIFUGES". He's not even suggesting that the authors needed to be world-class content protection experts; only that they would have benefited greatly from a book you can get off the shelf at Barnes and Noble.
The C.W. on Hacker News might be that it makes sense for Iran's enemies to brag about destroying centrifuges without a costly military intervention. But real intelligence services don't brag, if only because they'd like to be able to repeat the same trick against Myanmar or Belarus or Syria or whoever the next proliferation threat is.
† BD+ is interesting because it was designed to be broken easily and then renewed easily; there are numerous individual disk breaks, but so far as I know no break against the whole BD+ scheme that would enable a bypass of any studio update. BD+ may be the first such renewable content protection scheme ever deployed.
Not being heads of state, I don't think either of us is qualified to guess on the 8-dimensional chess being played here. Israel, if they are indeed behind this, is home to some of the brightest computer scientists on the planet. They already pulled off an impressive feat. It's pretty obvious that accomplishing the obfuscation described would not be outside their abilities.
So if they didn't bother, I have a hunch they had their reasons. They could be technical, and that would be the simplest explanation. They could just as well be political or otherwise strategic. I don't know, and neither does anyone else outside of the Israeli and US intelligence communities.
But whatever their reasoning, it's cheap, Monday morning quarterbacking to call an unprecedented and successful operation like Stuxnet embarrassing. Its exposure in the Times has nothing to do with technical competence and everything to do with the fast pace of information flow in the 21st century.
We all know about Operations Opera, Spring of Youth or Wrath of God, it's possible to read about them at length and I'm not sure anyone can dispute the competence on display there.
The US is home to more of the world's brightest computer scientists, but they aren't apportioned evenly throughout all the intelligence services and their contractors. Even presuming that this was carried out by "Mossad" --- and despite breathless reporting in the mainstream media and our inherent narrative bias about cyberwarfare stories, that's still a presumption --- that doesn't mean the best & brightest actually worked on this.
I guess the point is that it is simply impossible to distinguish between a mediocre team and a brilliant one that has chosen to disguise its capabilities.
If that was his point then title of the article shouldn't have been "Stuxnet is embarrassing, not amazing" rather "Here's how Stuxnet could have been even better"
I think "teenagers have written tfiles that are markedly more sophisticated than this virus" justifies the title, but this is a difference of opinion and a classic example of an unproductive HN argument. If you think his title sucks, fine.
Comments
That's a nice-sounding narrative, but no assessment of Stuxnet indicates that it foreclosed on Iran's nuclear capability, and if it actually is an intelligence service attack on a foreign industrial process, the fact that it's been analyzed in the New York Times seems to suggest that it wasn't very competently done.
A big part of Nate's point in this article is that the virus and DRM communities have known for over a decade how to take programs like this and make them hard to analyze. Nate is pointing out that nothing like that seems to have been done here.
Note that Nate was a key contributor to the as-yet-unbroken† Blu-Ray BD+ DRM scheme, which he worked on in his last couple years at Paul Kocher's infamous Cryptography Research. Here he is going out of his way to cite well known, public sources for methods that would have allowed an intelligence agency to carry out this attack without broadcasting to the world "AIR GAP ALL YOUR NUCLEAR FACILITIES IMMEDIATELY OR YOU WILL LOSE YOUR CENTRIFUGES". He's not even suggesting that the authors needed to be world-class content protection experts; only that they would have benefited greatly from a book you can get off the shelf at Barnes and Noble.
The C.W. on Hacker News might be that it makes sense for Iran's enemies to brag about destroying centrifuges without a costly military intervention. But real intelligence services don't brag, if only because they'd like to be able to repeat the same trick against Myanmar or Belarus or Syria or whoever the next proliferation threat is.
† BD+ is interesting because it was designed to be broken easily and then renewed easily; there are numerous individual disk breaks, but so far as I know no break against the whole BD+ scheme that would enable a bypass of any studio update. BD+ may be the first such renewable content protection scheme ever deployed.
> real intelligence services don't brag
Not being heads of state, I don't think either of us is qualified to guess on the 8-dimensional chess being played here. Israel, if they are indeed behind this, is home to some of the brightest computer scientists on the planet. They already pulled off an impressive feat. It's pretty obvious that accomplishing the obfuscation described would not be outside their abilities.
So if they didn't bother, I have a hunch they had their reasons. They could be technical, and that would be the simplest explanation. They could just as well be political or otherwise strategic. I don't know, and neither does anyone else outside of the Israeli and US intelligence communities.
But whatever their reasoning, it's cheap, Monday morning quarterbacking to call an unprecedented and successful operation like Stuxnet embarrassing. Its exposure in the Times has nothing to do with technical competence and everything to do with the fast pace of information flow in the 21st century.
We all know about Operations Opera, Spring of Youth or Wrath of God, it's possible to read about them at length and I'm not sure anyone can dispute the competence on display there.
The US is home to more of the world's brightest computer scientists, but they aren't apportioned evenly throughout all the intelligence services and their contractors. Even presuming that this was carried out by "Mossad" --- and despite breathless reporting in the mainstream media and our inherent narrative bias about cyberwarfare stories, that's still a presumption --- that doesn't mean the best & brightest actually worked on this.
I guess the point is that it is simply impossible to distinguish between a mediocre team and a brilliant one that has chosen to disguise its capabilities.
If that was his point then title of the article shouldn't have been "Stuxnet is embarrassing, not amazing" rather "Here's how Stuxnet could have been even better"
I think "teenagers have written tfiles that are markedly more sophisticated than this virus" justifies the title, but this is a difference of opinion and a classic example of an unproductive HN argument. If you think his title sucks, fine.