Powered by WebAds

Tuesday, August 20, 2013

Surprise: White House was source of Stuxnet leaks

The sources for a book by New York Times reporter David Sanger regarding the development of the Stuxnet computer worm by the United States and Israel, and for a New York Times story by the same reporter that was based on the book, were senior members of the White House staff, according to a report in Monday's Washington Times (Hat Tip: Shy Guy via Jawa Report).
The scores of State Department emails from the fall of 2011 to the spring of 2012 do not reveal which officials told Mr. Sanger, but they do show an atmosphere of cooperation within the administration for a book generally favorable toward, but not uncritical of, President Obama. For example:

“I’m getting a bit concerned about the pace of our interviews — or lack of pace, to be more precise — for the book,” Mr. Sanger said in an email Oct. 30, 2011, to Michael Hammer, a senior State Department public affairs official. “The White House is steaming away; I’ve seen [National Security Adviser Thomas E.] Donilon many times and a raft of people below. Doing well at the Pentagon. But on the list I sent you starting on Sept. 12 we’ve scheduled nothing, and chapters are getting into final form.”

Mr. Sanger’s book debuted in June 2012 and brought an immediate call from Republicans to investigate the leaks. They charged that administration officials jeopardized an ongoing secret cyberattack by tipping off Iran’s hard-line Islamic regime about war plans.

They also charged that Obama aides were leaking sensitive materials on other issues, such as the Navy SEAL-CIA raid to kill Osama bin Laden, to burnish Mr. Obama’s credentials as commander in chief as the 2012 election approached.

...

Mr. Sanger wrote a June 1, 2012, article on Stuxnet that was adapted from his book, which debuted later that week. In the story, he quoted “participants” in White House meetings on whether to continue attacking Iran with Stuxnet, which somehow had broken free into the Internet.

“At a tense meeting in the White House Situation Room within days of the worm’s ‘escape,’ Mr. Obama, Vice President Joseph R. Biden Jr. and the director of the Central Intelligence Agency at the time, Leon E. Panetta, considered whether America’s most ambitious attempt to slow the progress of Iran’s nuclear efforts had been fatally compromised,” the story said. “Should we shut this thing down?” Mr. Obama asked, according to members of the president’s national security team who were in the room.”

Republicans said those passages alone are evidence that Obama aides broke the law by publicly disclosing a covert program. With the story and book in print, State Department public affairs on June 7 sent to department officials a transcript of a floor speech delivered by Sen. John McCain that week. The Arizona Republican accused the administration of deliberately leaking secrets to portray Mr. Obama as a “strong leader on national security issues” in an election year.

“What price did the administration apparently pay to proliferate such a presidential persona highly valued in an election year?” he said. “Access. Access to senior administration officials who appear to have served as anonymous sources divulging extremely sensitive military and intelligence information and operations.”

...

Asked on CBS’ “Face the Nation” on June 3, 2012, whether the administration leaked to him to bolster the president’s image, Mr. Sanger said:

“I spent a year working the story from the bottom up, and then went to the administration and told them what I had. Then they had to make some decisions about how much they wanted to talk about it.

“All that you read about this being deliberate leaks out of the White House wasn’t my experience. Maybe it is in other cases,” he said. “I’m sure the political side of the White House probably likes reading about the president acting with drones and cyber and so forth. National security side has got very mixed emotions about it because these are classified programs.” Said Mr. McCain: “I don’t know how one could draw any conclusion but that senior members of this administration in the national security arena have either leaked or confirmed information of the most highly classified and sensitive nature.”
I think there was more to this than Obama trying to portray himself as a strong President on national security. Around the time that the administration started leaking seriously to Sanger (note the December 2011 date above - Stuxnet was discovered in late 2010), the Senate rejected Obama's attempts to stop sanctions against Iran 100-0. It was known that Obama was pressuring Israel (and continues to pressure Israel to this very day) not to attack Iran. It was known that the Obama was having problems raising campaign funding from Jewish donors. This wasn't just about portraying Obama as strong on national security. It was also about portraying Obama as pro-Israel and as willing to do something to stop Iran.

It was an attempt to fool people. And it worked.

Labels: , , ,

Tuesday, July 09, 2013

Snowden: NSA and Israel co-wrote Stuxnet

In an interview excerpted in Der Spiegel, former NSA analyst turned whistleblower Edward Snowden says that the NSA and Israel jointly developed the Stuxnet worm, which attacked Iran's nuclear facilities (Hat Tip: Memeorandum).
Shortly before he became a household name around the world as a whistleblower, Edward Snowden answered a comprehensive list of questions. They originated from Jacob Appelbaum, 30, a developer of encryption and security software. Appelbaum provides training to international human rights groups and journalists on how to use the Internet anonymously.

...

"In mid-May, documentary filmmaker Laura Poitras contacted me," Appelbaum said. "She told me she was in contact with a possible anonymous National Security Agency (NSA) source who had agreed to be interviewed by her."
"She was in the process of putting questions together and thought that asking some specific technical questions was an important part of the source verification process. One of the goals was to determine whether we were really dealing with an NSA whistleblower. I had deep concerns of COINTELPRO-style entrapment. We sent our securely encrypted questions to our source. I had no knowledge of Edward Snowden's identity before he was revealed to the world in Hong Kong. He also didn't know who I was. I expected that when the anonymity was removed, we would find a man in his sixties." 
"The following questions are excerpted from a larger interview that covered numerous topics, many of which are highly technical in nature. Some of the questions have been reordered to provide the required context. The questions focus almost entirely on the NSA's capabilities and activities. It is critical to understand that these questions were not asked in a context that is reactive to this week's or even this month's events. They were asked in a relatively quiet period, when Snowden was likely enjoying his last moments in a Hawaiian paradise -- a paradise he abandoned so that every person on the planet might come to understand the current situation as he does."
"At a later point, I also had direct contact with Edward Snowden in which I revealed my own identity. At that time, he expressed his willingness to have his feelings and observations on these topics published when I thought the time was right."

...

Interviewer: Did the NSA help to create Stuxnet? (Stuxnet is the computer worm that was deployed against the Iranian nuclear program.)
Snowden: NSA and Israel co-wrote it.
 I suppose this is no great surprise - we suspected it all along.

Labels: , , ,

Friday, June 14, 2013

'Stuxnet was out of control. We had to reveal it'

Israel HaYom interviews Eugene Kaspersky, the man who discovered Stuxnet.

Let's go to the videotape.



Here's the highlight of the interview in text:
How many large-scale cyberattacks have taken place to this day?
“You can count them on one hand, but the pace of attacks is growing. Today there are various kinds of cyberattacks, and criminal organizations are entering this field and offering their services to governments and commercial companies. They have their own forums, their own social networks, and they run their own parallel world. Unfortunately, many countries suffer from these cyberwars.”
You are supposed to help the good guys stop the bad guys. If so, why did you reveal the Stuxnet [The Stuxnet computer worm of 2010, which destroyed several Iranian nuclear centrifuges, was revealed as a joint U.S.-Israeli cyberweapon aimed at specific Iranian nuclear facilities]?
“That virus spun out of control. Although it was intended to stop the progress of Iran’s nuclear program, it also damaged 100,000 computers all over Europe. There was a need to stop it. Cyberwars act like boomerangs. In the real world, when you launch a missile, it hones in on a target and then it is completely destroyed. A virtual missile, however, is not destroyed. The attacking side could intercept it, change a few lines of code, and send it back to whoever launched it in the first place. So it would be advisable for governments not to enter cyberwars because in a boomerang war there are no winners.”
The Stuxnet worm, which allegedly attacked the Natanz plant by altering the frequency at which motors connected to gas centrifuges that separate uranium isotopes turn, formed part of a wave of digital attacks on the country in 2009 and 2010.
Hmmm.

Labels: , ,

Monday, May 20, 2013

Stuxnet may have helped - rather than hindered - Iran's nuclear program

I've been meaning to post this since Friday. Ruthie Blum explains how Stuxnet, the computer worm that afflicted Iran's nuclear program three years ago, may have helped, rather than hindered, Iran's nuclear ambitions.

Indeed, according to a new report, published in the Royal United Services Institute journal, Stuxnet may have done more harm to the West than good.

The study, "Are Cyberweapons Effective? Assessing Stuxnet's Impact on the Iranian Enrichment Program," was conducted by King's College academic Ivanka Barzashka and calls into question commonly held assumptions about the famous computer worm and the consequences of its performance.

"Considering Stuxnet's destructive potential, it is surprising that more machines were not affected," writes Barzashka. "Clearly, the Iranian operator managed to contain the problem … Iran's ability to successfully install and operate new centrifuges was not hindered."

Barzashka based her detailed report on International Atomic Energy Agency physical inventory data showing that "uranium-enrichment capacity grew during the time that Stuxnet was said to have been destroying Iranian centrifuges."

"An increase in enrichment capacity or centrifuge performance shortens the time Iran needs to manufacture the nuclear material for a bomb," Barzashka says. "If anything, the malware, if it did in fact infiltrate Natanz, has made the Iranians more cautious about protecting their nuclear facilities, making the future use of cyberweapons against Iranian nuclear targets more difficult."
In a funny yet predictable twist coming from a British academic, Barzashka's conclusion from her own research is that cyberwarfare is not the way to go about extending goodwill gestures toward Iran while engaging in talks. What the rest of us can and should glean from her study is that even Stuxnet seems to have sped up, rather than retarded, Iran's nuclear program.
What could go wrong?

Labels: , , ,

Wednesday, July 18, 2012

First return fire from Iran in cyberwar?

Russia's Kaspersky Lab, the same group that analyzed the Stuxnet, Duqu and Flame worms, has uncovered evidence of what might be the first return fire from Iran in the Middle East's cyberwar.
Kaspersky Lab researchers have today announced the results of a joint-investigation with Seculert, an Advanced Threat Detection company, regarding “Madi,” an active cyber-espionage campaign targeting victims in the Middle East. Originally discovered by Seculert, Madi is a computer network infiltration campaign that involves a malicious Trojan which is delivered via social engineering schemes to carefully selected targets.

Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified more than 800 victims located in Iran, Israel and select countries across the globe connecting to the C&Cs over the past eight months. Statistics from the sinkhole revealed that the victims were primarily business people working on Iranian and Israeli critical infrastructure projects, Israeli financial institutions, Middle Eastern engineering students, and various government agencies communicating in the Middle East.

In addition, examination of the malware identified an unusual amount of religious and political ‘distraction’ documents and images that were dropped when the initial infection occurred.

“While the malware and infrastructure is very basic compared to other similar projects, the Madi attackers have been able to conduct a sustained surveillance operation against high-profile victims,” said Nicolas Brulez, Senior Malware Researcher, Kaspersky Lab. “Perhaps the amateurish and rudimentary approach helped the operation fly under the radar and evade detection.”

“Interestingly, our joint analysis uncovered a lot of Persian strings littered throughout the malware and the C&C tools, which is unusual to see in malicious code. The attackers were no doubt fluent in this language,” said Aviv Raff, Chief Technology Officer, Seculert.
Hmmm.

Labels: , , ,

Wednesday, June 20, 2012

Obama administration leaks more information on cyber war, blames Israel

Desperate for votes, the Obama administration has once again leaked information about the American-Israeli cyber war against Iran, this time to the Washington Post. And they're trying to pin the blame for the program's exposure on Israel (Hat Tip: Memeorandum).
The United States and Israel jointly developed a sophisticated computer virus nicknamed Flame that collected critical intelligence in preparation for cyber-sabotage attacks aimed at slowing Iran’s ability to develop a nuclear weapon, according to Western officials with knowledge of the effort.

The massive piece of malware was designed to secretly map Iran’s computer networks and monitor the computers of Iranian officials, sending back a steady stream of intelligence used to enable an ongoing cyberwarfare campaign, according to the officials.

The effort, involving the National Security Agency, the CIA and Israel’s military, has included the use of destructive software such as the so-called Stuxnet virus to cause malfunctions in Iran’s nuclear enrichment equipment.

The emerging details about Flame provide new clues about what is believed to be the first sustained campaign of cyber-sabotage against an adversary of the United States.

“This is about preparing the battlefield for another type of covert action,” said one former high-ranking U.S. intelligence official, who added that Flame and Stuxnet were elements of a broader assault that continues today. “Cyber collection against the Iranian program is way further down the road than this.”

Flame came to light last month after Iran detected a series of cyberattacks on its oil industry. The disruption was directed by Israel in a unilateral operation that apparently caught its U.S. partners off guard, according to several U.S. and Western officials, speaking on the condition of anonymity.

...

Despite their collaboration on developing the malicious code, the United States and Israel have not always coordinated attacks. Israel’s April assaults on Iran’s Oil Ministry and oil export facilities caused only minor disruptions. The episode led Iran to investigate and ultimately discover Flame.

“The virus penetrated some fields — one of them was the oil sector,” Gholam Reza Jalali, an Iranian military cyber official, told Iranian state radio in May. “Fortunately, we detected and controlled this single incident.”

Some U.S. intelligence officials were dismayed that Israel’s unilateral incursion led to the discovery of the virus, prompting countermeasures.

The disruptions led Iran to ask a Russian security firm and a Hungarian cyber lab for help, according to U.S. and international officials familiar with the incident.

Last week, researchers with the Kaspersky Labs, the Russian security firm, reported their conclusion that Flame — a name they came up with — was created by the same group or groups that built Stuxnet. Kaspersky declined to comment on whether it was approached by Iran.
Isn't it convenient for Obama that Israel has a policy of not commenting on these kinds of reports?

Labels: , , ,

Sunday, June 17, 2012

'Stuxnet is so deeply embedded in Iran, their counterstrike plans are already known'

Here's a blog that the 'anti-virus experts' at Symantec and Kaspersky (and others) ought to be reading. They claim - and back it up - to have known about Stuxnet and Flame (which they call Stuxnet 3.0) since 2009 (Hat Tip: Jawa Report).

If they are correct, Flame is not automatically uninstalling on every computer in Iran, but only on computers where the Iranians start to look for it. And just because it disappears doesn't meant it can't come back. Here's the key part:
Stuxnet/flame puts USA in same position
as when US was only one with atom bomb,
MAD NOT APPLICABLE, first strike
can take out everything, leaving enemy nothing
to retaliate WITH.

Stuxnet is so deeply embedded in Iran
their counterstrike plans are already known.

This powerful weapon is so comprehensive
it is a deterrent in and of its self,
You don't slap someone who has you
by the balls like stuxnet has Iran.

The flip side of the suicide function,
as the press calls it, isn't suicide at all.
Its artificial intelligence, if you start looking
for Flame it knows and disappears.
Flip side is its so easy to penetrate PCs
dumping all traces of its self isn't a problem
it will revisit later.
Read it all. It's fascinating.

Labels: , , ,

Monday, June 11, 2012

Confirmed: Flame and Stuxnet developed by related groups

Based on similarities in their code, the Russian Kaspersky Labs, which discovered Flame, confirms that Flame and Stuxnet were developed by groups that worked together. Flame was actually developed first. Flame has been used to gather intelligence from computer systems, particularly in Iran, while Stuxnet was used to force Iranian nuclear centrifuges to destroy themselves. As noted on this blog on Sunday, while the Obama administration has attempted to take credit for developing Stuxnet to enhance the President's reelection bid, Stuxnet was likely developed by the Mossad, possibly in coordination with the IDF's unit 8200. It would therefore follow that Flame was a Mossad and/or IDF project.
There were two independent developer teams, with Flame development preceding Stuxnet and each team developing its own code platform since 2007-2008 at the latest, the researchers said. Both projects were state-sponsored, and Stuxnet was specifically designed to sabotage Iran's nuclear program, experts believe.

In addition, a previously undiscovered elevation-of-privilege Windows exploit is in Stuxnet.A, an early variant of the malware, Roel Schouwenberg, senior researcher at Kaspersky Lab, said in a Web conference with reporters.

"We have a new old Zero-Day," he said, referring to an attack that exploits a previously unknown and unpatched vulnerability. "It was a Zero-Day at the time of creation and most likely at the time of deployment." That brings to five the number of Zero-Day exploits Stuxnet used. The exploit, created in February 2009, is "strikingly similar" to one that was patched by Microsoft in June 2009, researchers said.

Stuxnet.A, which dates to about June 2009, contains a module known as "Resource 207, which is an encrypted dynamic-link library file that has an executable file that Kaspersky researchers say shares code with Flame. Resource 207 was not in Stuxnet.B, which came out in 2010. The primary functionality of the code in Stuxnet is to distribute the infection from one machine to another via removable USB drives and exploit the vulnerability in Windows kernel to obtain escalation of privileges within the system, according to a Kaspersky news release. The code responsible for distributing malware via USB drives is completely identical to the one used in Flame, the researchers said. They both use the Autorun function in Windows.

Initially, Kaspersky researchers speculated that the projects were parallel but were hesitant to say they were developed or commissioned by the same party. Now a more definite link has been established and a timeline is more clear.

"We firmly believe the Flame platform predates the Stuxnet platform. It looks like the Flame platform was a kick-starter of sorts to get the Stuxnet project going," Schouwenberg said. "The operations went separate ways, maybe because Stuxnet code was mature enough to be deployed in the wild. Now we are 100 percent sure that the Stuxnet and Flame groups worked together."
Read the whole thing.

In a blog post, Kaspersky discusses the missing link.
Despite the fact that Stuxnet has been the subject of in-depth analysis by numerous companies and experts and lots has been written about its structure, for some reason, the mysterious “resource 207” from 2009 has gone largely unnoticed. But it turns out that this is the missing link between Flame and Stuxnet, two seemingly completely unrelated projects.

...

In October 2010, our automatic system received a sample from the wild. It analyzed the file thoroughly and classified it as a new Stuxnet variant, Worm.Win32.Stuxnet.s.

With Stuxnet being such a big thing, we looked at the sample to see what it was! Sadly, it didn’t look like Stuxnet at all, it was quite different. So we decided to rename it to Tocy.a and thought “silly automatic systems!”.

When Flame was discovered in 2012, we started looking for older samples that we might have received. Between samples that looked almost identical to Flame, we found Tocy.a.

Going through the sample processing system logs, we noticed it was originally classified as Stuxnet. We thought, how was it possible? Why did the system think that this Flame sample was related to Stuxnet? Checking the logs, we discovered that the Tocy.a, an early module of Flame, was actually similar to “resource 207” from Stuxnet. It was actually so similar, that it made our automatic system classify it as Stuxnet. Practically, Tocy.a was similar to Stuxnet alone and to no other sample from our collection.

Going back to the story, this is how we discovered the incredible link between Flame and Stuxnet.
Read the whole thing.

ABC News adds.
After Stuxnet's discovery, a Congressional report in December 2010 put the U.S. and Israel on a short list of countries believed to be capable of carrying out that attack -- a list that also included Russia, China, the U.K. and France. A month later, The New York Times reported Stuxnet may have been the result of a joint U.S., Israeli project to undermine Iran's nuclear program.

Five different U.S. government agencies declined to comment to ABC News about allegations they were involved in Flame and the Israeli government has reportedly denied any link to the virus.

News of the new connection between the two programs came just days after a U.S.-based cyber security firm, Symantec, reported Flame appears to have been given a "suicide" command that would wipe any trace of it from an infected computer.
I don't believe that Israeli denial for a minute. Our government just doesn't like to look guilty so it wouldn't say 'no comment' like the Americans. For example, to this day, Israel has never officially admitted that it destroyed the Syrian nuclear plant in 2007. And we've never told anyone whether we have nuclear weapons, even though I'm sure you all think that we do.

But don't tell Forbes that. They think the CIA did it. Heh.

Labels: , , , , ,

Sunday, June 10, 2012

Mossad: 'Stuxnet is our baby; Obama disclosed it for his reelection campaign'

A group of Mossad agents speaking with Haaretz's Yossi Melman on condition of anonymity have said that the Mossad - and not the Bush administration - developed Stuxnet, and that President Obama is now trying to take credit for it in a bid to help his reelection campaign (Hat Tip: MFS - The Other News via Atlantic Wire). Please recall the David Sanger piece in the New York Times about Stuxnet, which I blogged last week, which claimed that the Bush administration had begun developing Stuxnet, that President Obama had ordered it accelerated, and that Israel had only joined in later. Now, look at what Melman has to say about it.
The Israeli officials actually told me a different version. They said that it was Israeli intelligence that began, a few years earlier, a cyberspace campaign to damage and slow down Iran’s nuclear intentions. And only later they managed to convince the USA to consider a joint operation — which, at the time, was unheard of. Even friendly nations are hesitant to share their technological and intelligence resources against a common enemy.
Melman, and his writing partner Dan Raviv, promise more details on Mossad - CIA cooperation in their upcoming book (maybe if I'm really lucky they'll send me a review copy), which is due out next month. But they do give a hint as to the timing of the New York Times article.
Yet my Israeli sources understand the sensitivity and the timing of the issue and are not going to be dragged into a battle over taking credit. “We know that it is the presidential election season,” one Israeli added, ”and don’t want to spoil the party for President Obama and his officials, who shared in a twisted and manipulated way some of the behind-the-scenes secrets of the success of cyberwar.”
There's nothing Obama won't do to be reelected. Nothing at all.

UPDATE 4:02 PM

Welcome Power Line readers.

UPDATE MONDAY 2:05 AM

Welcome to readers from Breitbart.com, Gateway Pundit and PJ Tatler and several others. Thanks for all the linky love.

Labels: , , , , ,

Monday, June 04, 2012

Krauthammer: Outrageous Obama leaking cyberwar details to boost reelection bid

Charles Krauthammer thinks the same I said last week: That the Obama administration is purposely leaking details of the United States' cyber war in order to boost the President's chances for reelection in November.

Let's go to the videotape.

Labels: , , , , ,

Tuesday, April 17, 2012

Report: Israel used MEK agent to load Stuxnet directly into Natanz

Citing US intelligence sources, an online industrial security publication is reporting that Stuxnet was placed directly into Iran's Natanz nuclear power plant by a member of the MEK, acting on behalf of Israel, using a corrupted memory stick.
These sources, who requested anonymity because of their close proximity to investigations, said a saboteur at the Natanz nuclear facility, probably a member of an Iranian dissident group, used a memory stick to infect the machines there. They said using a person on the ground would greatly increase the probability of computer infection, as opposed to passively waiting for the software to spread through the computer facility. “Iranian double agents” would have helped to target the most vulnerable spots in the system,” one source said. In October 2010, Iran’s intelligence minister, Heydar Moslehi said an unspecified number of “nuclear spies” were arrested in connection with Stuxnet.33 virus.

Former and senior U.S. officials believe nuclear spies belonged to the Mujahedeen-e-Khalq (MEK), which Israel uses to do targeted killings of Iranian nationals, they said. “The MEK is being used as the assassination arm of Israel’s Mossad intelligence service,” said Vince Cannistraro, former head of the CIA’s Counterterrorism. He said the MEK is in charge of executing “the motor attacks on Iranian targets chosen by Israel. They go to Israel for training, and Israel pays them.” Other former agency officials confirmed this.

As ISSSource reported, Stuxnet was a comprehensive U.S.-Israeli program designed to disrupt Iran’s nuclear technology. This joint program first surfaced in 2009 and worked in concert with an earlier U.S. effort that consistently sabotaged Iran’s purchasing network abroad.

But the United States never indulged in targeting killings of Iran scientists, and former senior U.S. officials said the U.S. public remained unaware of a separate Israeli program, independent of the United States, that has for ten years been assassinating key Iranian nuclear scientists and sabotaging key Iranian facilities using a proxy group of Iranian dissidents. These dissidents have a functioning, effective network inside Iran and they have access to officials in the nuclear program.

...

Meanwhile, going back to Stuxnet, once the memory stick was infected, the virus was able to infiltrate the network and take over the system. U.S. officials said they believe the infection commenced when the user simply clicked on the associated icon in Windows. Several reports pointed out this was a direct application of one of the zero-day vulnerabilities Stuxnet leveraged.

Building and deploying Stuxnet required extremely detailed intelligence about the systems it was supposed to compromise, and has made reprogramming highly specific installations on legacy systems more complex, not less. According to reports, the Stuxnet mystery was unveiled in June 2010, when a small company called VirusBlokAda in Minsk, the capital of Belarus was emailed by a dealer in Tehran about an irritating problem some of his clients were having with their computers.

The company analyst saw the computers were constantly turning off and restarting. At first the analyst thought it was just a problem with the hardware. But when they said several computers were affected, not just one, VirusBlokAda understood it was a problem with the software the computers were running.
Hmmm.

Read the whole thing.

Labels: , ,

Wednesday, February 15, 2012

Iran has neutralized Stuxnet?

Reuters is reporting that Iran has neutralized the Stuxnet computer worm that had infected its nuclear facilities.
US and European officials, who insisted on anonymity when discussing a highly sensitive subject, said their governments' experts agreed that the Iranians had succeeded in disabling Stuxnet and getting it out of their machinery.

The officials declined to provide any details on how their governments verified that the Iranians had ultimately defeated the virus. It was not clear when it occurred but secrecy on the subject has been so tight that news is only now emerging.

Some officials said they believe that the Iranians were helped in their efforts by Western cyber security experts, whose detailed technical analyses of Stuxnet's computer code have circulated widely on the Internet.

...

Private experts say that however well-crafted the original Stuxnet was, whoever created it probably would have to be even more clever if they want to try to supplant it with new cyber-weapons directed at Iran's nuclear program.

"Aspects of Stuxnet could be re-used, but it is important to understand that its success depended not only on 'clever coding' but also required a great deal of specific intelligence and testing. It was the first known highly-targeted cyber-weapon, as opposed to more usual cyber weapons which are more diffuse in their targeting," Sommer said.

David Albright, a former United Nations weapons inspector who has extensively investigated Iran's nuclear program for the private Institute for Science and International Security, which he leads, said that spy agencies would have to go back to the drawing board if they're intent on continuing to try to hobble Iran's nuclear program via cyber-warfare.
Unfortunately, cutesy solutions like Stuxnet aren't likely to carry the day anymore anyway. We need another approach.

Labels: ,

Monday, February 13, 2012

Iran claims its nuclear facilities are immune to cyberattack

Iran claims that its nuclear facilities are immune to cyberattacks.
A senior Iranian military official said Monday that Tehran's nuclear and other industrial facilities suffer periodic cyber attacks, but that the country has the technology to protect itself from the threat, an official news agency reported.

Iran considers itself to have been waging a complicated cyber war since 2010, when a virus known as Stuxnet disrupted controls of some nuclear centrifuges.

"Most enemy threats target nuclear energy sites as well as electronic trade and banking operations," said Gholam Reza Jalali, who heads an Iranian military unit in charge of combatting sabotage.

Jalali said that in addition to Stuxnet, Iran has discovered two espionage viruses, Stars and Doku, but that the malware did no harm to Iran's nuclear or industrial sites.

Iran says Stuxnet and other computer virus attacks are part of a concerted campaign by Israel, the U.S. and their allies to undermine its nuclear program.
Sounds overconfident to me.

Heh.

Labels: , ,

Friday, November 18, 2011

Video: Stuxnet

Here's a video about the mother of all computer worms.

Let's go to the videotape (Hat Tip: Zvi S).

Labels:

Thursday, July 14, 2011

How Stuxnet happened

It will take a long time to read this one, and I must admit that I don't understand it all, but here's the fascinating story of how the Stuxnet worm infected Iran's nuclear program and how it was discovered.

Heh.

Labels: ,

Sunday, May 01, 2011

Stuxnet preventing Iran from opening Bushehr

An internal report issued by Iran's intelligence services warns that due to the Stuxnet computer worm, attempts to start the Bushehr nuclear power plant could lead to the country's entire electronic grid being shut down. Iran is blaming the US and Israel.
The report, written by the Iranian Passive Defense Organization, chaired by Revolutionary Guards Gen. Gholam-Reza Jalali, states that Stuxnet has so thoroughly infected the operating systems at the Bushehr power plant that work on the plant must be halted indefinitely.

If the Bushehr power plant were to go on line, “the internal directives programmed into the structure of the virus can actually bring the generators and electrical power grid of the country to a sudden halt, creating a “heart attack type of work stoppage,” the report states.

The report was obtained by the “Green Liaison news group,” Iranian journalists affiliated with presidential candidate Mir Hussein Mousavi, and was translated into English by Reza Kahlili, a former Revolutionary Guards officer who spied on behalf of the CIA for over a decade while inside Iran.

The report claims that Stuxnet “has automatic updating capabilities in order to track and pirate information,” and that it “can destroy system hardware step-by-step."

Gen. Jalali has held two press conferences in recent weeks where he has given tantalizing glimpses into the conclusions of his top-secret task force to analyze and defuse the Stuxnet computer worm.

At one, he blamed Israel for collaborating in developing the worm and claimed that his experts had traced “reports” sent by the worm back to Texas.

“Enemies have attacked industrial infrastructure and undermined industrial production through cyberattacks. This was a hostile action against our country,” Jalali said. “If it had not been confronted in time, much material damage and human loss could have been inflicted.”
Oh - remember that new worm called Stars I reported on last week? Here's a hint of what it might do....
On Monday, Jalali claimed that his intelligence unit, which merges computer analysts from the intelligence ministry and the Revolutionary Guards intelligence service, had found a new computer virus attacking Iran’s nuclear facilities called “Stars.”

He called “Stars” an “espionage virus,” and said that it copied government files and was difficult to destroy in its early stages.
Read the whole thing. Heh.

Labels: , , , , ,

Tuesday, April 26, 2011

After Stuxnet come the Stars

And to think that I haven't even mentioned Stuxnet on this blog since March 1....

It seems that those Jews computer engineers were even smarter than we thought they were. Yes, they've managed to send Iran yet another computer virus.
"Fortunately, our young experts have been able to discover this virus and the Stars virus is now in the laboratory for more investigations," Jalali was quoted as saying. He did not specify the target of Stars or its intended impact.

"The particular characteristics of the Stars virus have been discovered," Jalali said. "The virus is congruous and harmonious with the [computer] system and in the initial phase it does minor damage and might be mistaken for some executive files of government organizations."

...

Jalali said Stuxnet might still pose a risk. "We should know that fighting the Stuxnet virus does not mean the threat has been completely tackled, because viruses have a certain life span and they might continue their activities in another way."

He urged the government to take action against the enemies he said were waging cyber war on Iran.

"Perhaps the Foreign Ministry had overlooked the options to legally pursue the case, and it seems our diplomatic apparatus should pay more attention to follow up the cyber wars staged against Iran," Jalali said.
Good luck with that. How are you going to prove who is responsible? Heh.

Labels: , ,

Tuesday, March 08, 2011

The gray ponytails

I am sure that some of you who grew up in the '60's and '70's like I did watched that video of interviews from the J Street conference and wondered why so many of the people attending look so old. I grew up believing that young people are Leftists and Democrats, and that after growing older and getting mugged by reality they become conservatives and Republicans.

But when it comes to Israel, it seems that the generation from which most of the anti-Israel crowd is drawn is one that begins a few years older than I am and ends around retirement age. Let's call it the 60-70 crowd. Why is that? Hillel Stavis tries to explain.
You see them in every University town in America, the aging, angry and disaffected children of the ’60′s, grandchildren of Jewish socialism and communism of the ’30′s – in perpetual mourning for the Soviet Union, Cuba and all the other failed socialist experiments of the last 100 years. Like dinghys floating on the surface of the water waiting in vain for the mother ship that will never come back for them, they band together to find an enemy, the passion that will breathe life into them again, the resurrection of the unfinished revolution. And as we’ve seen for the past 20 years, the most convenient enemy and scapegoat is Israel and the Jews. The 1930′s was the Right’s turn, now the hatred spews from the Left.

This time, many of the Hamas support groupies are PWJN (Persons with Jewish Names), the “as-a-Jew” antisemites. You know them – from Berkeley to Madison to Ann Arbor – the ones who preface every Israel hating remark with statements like: “As a Jew I deplore and abhor what Israel is doing to that nation of Ghandis, the Palestinians…” They lend credibility and energy – by simple virtue of a last name – to the most inaccurate, mendacious and vicious campaigns against the Jewish people since the Nuremberg rallies of the 1930′s. I once asked one of the AAJ’s (as-a-Jew) what connection she had with her local Jewish community; did she regularly got to Synagogue, support local Jewish community groups, keep kosher, or was she knowledgeable about Jewish history? Stunned, she answered that she was an active fighter for “Social Justice.” Asked if that included the right of her Jewish brothers and sisters to exist in their own historical country, she abruptly turned on her heel and laughed, saying that she considered them “cousins” only. Of course, her real brothers and sisters sport keffiyahs (as did she) and followed the teachings of the Koran.

The latest chapter in the grey ponytails was recently written in Cambridge, MA, a “city of refuge” for any and all Jew hating Muslims and one of the mirror image cities that are associated with University PC culture. This time it involved an ADL initiative inviting police and fire department administrators to visit Israel to learn the latest counter terrorism tactics. Like El Al’s highly successful program to keep U.S. airports safe from Al Qaeda and its copycat would-be killers, the ADL should be commended in its efforts to lend Israeli expertise to the U.S.

Redefining chutzpah, this group, in the words of its leader, Cathy Hoffman, former director of The Cambridge Peace Commission (I kid you not-along with trash removal, the City aspires to remove war from the global landscape) characterized the Israeli invitation as further proof that the Jewish state opposes multiculturalism and is an example of Apartheid – ho hum.
Read and watch (lots of video here) the whole thing, and learn who the enemy really is.

By the way, to the best of my knowledge, the guy at the top of this post (who is pushing 58) was not at the J Street conference. Dan Rather wouldn't let him go.

Labels: , , , , ,

Tuesday, March 01, 2011

The trouble at Bushehr

The New York Times reports that the Russians have succeeded in diagnosing the problem with Iran's Bushehr nuclear reactor.
The Russian explanation seems far more prosaic, although experts cautioned that the full capabilities of the Stuxnet virus remain unclear.

The Russian statement on Monday said the trouble arose as pressure mounted in the reactor during tests. The pump vibrated and joints broke, the statement said. As a result, metal shards smaller than three millimeters — or less than a tenth of an inch — could have shot into cooling pipes and lodged in fuel assemblies.

“The joints broke down under conditions of high vibration and pulsing pressure,” the statement said.

“If metal particles are found on the fuel assemblies,” it added, “they will be washed, the body of the reactor cleaned, and after this the fuel will again be loaded into the reactor.”

The statement said the failed pump dated to the 1970s, when West Germans began building the reactor. The Russians, who took over in 1995, have said for years that integrating the old German equipment posed more challenges than initially anticipated.

An article on Monday in Nezavisimaya Gazeta, a Moscow newspaper, cited an unidentified Russian official as saying that in the worst case, if metal shards were found in the fuel assemblies, the delay would amount to no more than two months.
That's what you think. Heh.

Labels: , , ,

Sunday, February 27, 2011

The work of the righteous is carried out by the Hands of Heaven

Our rabbis tell us that the work of the righteous is carried out by the Hands of Heaven. That might explain a notice from the Iranian government to the International Atomic Energy Agency (IAEA) on Wednesday that it planned to unload nuclear fuel from its Bushehr reactor, which was supposed to come on line this month.
In a report on Friday, the International Atomic Energy Agency said Iran told inspectors on Wednesday that it was planning to unload nuclear fuel from its Bushehr reactor — the sign of a major upset. For years, Tehran has hailed the reactor as a showcase of its peaceful nuclear intentions and its imminent startup as a sign of quickening progress.

But nuclear experts said the giant reactor, Iran’s first nuclear power plant, now threatens to become a major embarrassment, as engineers remove 163 fuel rods from its core.

Iran gave no reason for the unexpected fuel unloading, but it has previously admitted that the Stuxnet computer worm infected the Bushehr reactor. On Friday, computer experts debated whether Stuxnet was responsible for the surprising development.

Russia, which provided the fuel to Iran, said earlier this month that the worm’s infection of the reactor should be investigated, arguing that it might trigger a nuclear disaster. Other experts said those fears were overblown, but noted that the full workings of the Stuxnet worm remained unclear.

In interviews Friday, nuclear experts said the trouble behind the fuel unloading could range from minor safety issues and operational ineptitude to serious problems that would bring the reactor’s brief operational life to a premature end.

“It could be simple and embarrassing all the way to ‘game over,’ ” said David A. Lochbaum, a nuclear engineer at the Union of Concerned Scientists and a former official at the Nuclear Regulatory Commission, which oversees nuclear reactors in the United States.

Mr. Lochbaum added that having to unload a newly fueled reactor was “not unprecedented, but not an everyday occurrence.” He said it happened perhaps once in every 25 or 30 fuelings. In Canada, he added, a reactor was recently fueled and scrapped after the belated discovery of serious technical problems.

“This could represent a substantial setback to their program,” David Albright, president of the Institute for Science and International Security, a private group in Washington that tracks nuclear proliferation, said of the problem behind the Bushehr upset.

“It raises questions of whether Iran can operate a modern nuclear reactor safely,” he added. “The stakes are very high. You can have a Chernobyl-style accident with this kind of reactor, and there’s lots of questions about that possibility in the region.”
Hmmm.

There was also some bad news in Friday's report: Iran continues to make progress toward nuclear weapons.
The report alluded to “new information recently received,” suggesting continuing work toward a nuclear warhead.

But the inspectors provided no details about the new information or how it was received. The I.A.E.A. frequently gets its data from the intelligence agencies of member countries, including the United States, but it also tries to collect data from its own sources.

The report on Friday referred directly to concerns that Iran was working on “the development of a nuclear payload for a missile.” But it noted that all of its requests for information had been ignored for years, with Iranian officials arguing that whatever information the agency possessed, it was based on forgeries.
Iran can still be stopped.

Labels: ,

Google