« POPE Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next

Re: Duh? 

By: DGpeddler in POPE | Recommend this post (1)
Tue, 12 Jun 12 10:52 PM | 48 view(s)
Boardmark this board | (The) Pope's for real stock market report
Msg. 60809 of 65535
(This msg. is a reply to 60798 by Decomposed)

Jump:
Jump to board:
Jump to msg. #

Decomposed, when Flame first hit the news it was said that it had attacked several countries in the Middle East, including Isreal. KTC was blaming it on Israel and I pointed out to him that Israel was on the list. KTC HATES Jews with a passion and tries to blame Israel for anything he sees as bad. Most of his arguments are based on his personal feelings and have nothing to do with facts. This conversation started off about Stuxnet and KTC, as usual, posted that I had said stuff I had not said. My post was about Flame, not Stuxnet. While the U.S. has been blamed for Stuxnet, Flame has not been blamed on anyone. It seems that the two have simular parts in their programs, their creators have not actually been identified and they may or may not have come from the same source. One of the few connections between the two is that they both use an error in Windows programing. I just said "Windows did it" because there is as much 'proof' they did it as there is 'proof' Israel did it. Let me ask you one question that backs up my thinking. Do you think that America would design a program to cause harm and then unleash it on America? After Flame was discovered, it was found operating in Israel as well as other countries. Would you consider that proof that Israel did it? How many folks do you know that go around shooting themselves in the foot for the fun of it.


- - - - -
View Replies (3) »



» You can also:
- - - - -
The above is a reply to the following message:
Re: Duh?
By: Decomposed
in POPE
Tue, 12 Jun 12 9:02 PM
Msg. 60798 of 65535

re: "Windows DID it."

I'm not sure what you mean by that, DGpeddler, but it sounds like you ascribe the blame to Microsoft.

Stuxnet incorporated not one, but three, zero-day vulnerabilities. That is, it took advantage of three system flaws that no one in the world had previously known. Obviously, there were no patches or antivirus signatures to guard against them. They were unknown, even to the manufacturers/developers of the products. And although Stuxnet ran on Windows, the vulnerabilities it exploited were not all Microsoft's.

When a company markets software internationally, most countries require the company to provide the code prior to granting it permission to sell the product. The governments then go about analyzing the code, looking for anything that might be a concern, but also identifying vulnerabilities which they typically keep to themselves.

Such zero-day vulnerabilities are rare gems. Stuxnet had three.

Rogue hackers could never have implemented it. They don't have access to the product code. From that alone, it is clear that Stuxnet was the work of one or more nations, not individuals, confederations or companies.

Whoever designed Stuxnet had an OUTSTANDING understanding of the Bushehr nuclear power plant, its layout, its construction, its security, its people, and the automated systems within. They built the first product to ever attack programmable logic controllers, the Siemens mechanisms that regulate industrial hardware, ensuring that the hardware operates within specified boundaries.

It's said that the attackers had to have understood the Iranian facility better than the Iranians themselves - which is actually possible since the facility was built with extensive foreign assistance, and stocked with foreign technology.

Finally, whoever was behind Stuxnet compromised Verisign digital certficates for TWO high tech companies far removed from Iran. No hacker could have pulled that off. In fact, the compromises almost had to have involved breakins at Verisign itself, altering Verisign's records so that the certificates would give Bushehr the 'thumbs up' to communicate with the Command and Control servers from which Stuxnet received guidance and delivered findings.

Could one company (Microsoft) have been behind such an attack? Not a chance. Stuxnet went far beyond the resources available to Microsoft. It is not even likely that Israel or the United States could have been behind it. Not by themselves. Stuxnet was probably a coordinated effort by several determined governments.


« POPE Home | Email msg. | Reply to msg. | Post new | Board info. Previous | Home | Next