Amazing or Scary?

Heard this story about David Sanger's new book "Confront and Conceal: Obama's Secret Wars and Surprising Use of American Power" on the radio the other day and was pretty flabbergasted.  Sanger touches on a number of things in the book, but it's the cyber-warfare that caught my attention.  So it looks like the US was behind Stuxnet all along...and that it worked.  A few highlights:


Last week, The New York Times reported that Stuxnet, the computer worm that infected computers around the world in 2010, was developed by the United States in conjunction with Israel to destroy Iran's nuclear centrifuges.


Before they could attempt to take down Iran's Natanz nuclear enrichment plant, however, U.S. and Israeli officials needed to know what it looked like. Sanger explains that they initially sent a bit of computer code called a beacon into Natanz to map the plant's electronic infrastructure.

"This beacon went in and basically built a blueprint for how the Iranians had designed the electronics of this plant and then came back out and phoned home, back to the National Security Agency and Unit 8200, the Israelis' equivalent of the NSA," says Sanger. "And from the data that they gathered there, the U.S. and the Israelis designed a computer worm that would replicate within the system."
But U.S. officials first wanted to test the worm. So they built a full-scale replica of the Natanz plant on the grounds of the Department of Energy's national laboratories.


Initially Sanger and his colleagues at The New York Times thought Stuxnet had been released on the Internet by intelligence officials hoping to get the worm inside Iran's nuclear facilities.

"In fact, we had it backward," he says. "It had started in Natanz and escaped like a zoo animal."When U.S. and Israeli officials learned that Stuxnet had escaped, they met with Obama in the Situation Room. The president asked if the code could damage computers outside the plant. After security officials assured him that was not the case, the Obama decided the program could go forward. A week later, another iteration of the code brought down 1,000 centrifuges within Iran.

"The official internal estimate is that [this code] delayed Iran's progress and weapons capability by 18 months to two years," says Sanger. "I had some outside experts who believe that that is not true — that Iranians have recovered fairly quickly. But what we don't know — and will never know — is whether they would have been able to build far better centrifuges and far more sophisticated centrifuges had this not happened. Because as their centrifuges were literally blowing up, they ended up firing people, taking centrifuges offline — because they were trying to figure out what was going wrong. As one official said to me, 'It was to make them feel stupid.' "



We actually took down 1,000 Iranian centrifuges with a computer virus!  Possibly setting them back 2 years!  That's just crazy to me.  Then we find the Flame Virus (apparently developed by the same people) that can go in and access of webcams, microphones, and host of other things on a computer.  Maybe someone is watching you on your webcam right now.

On the one hand it's pretty cool that these tools are in our hands and that we can try to thwart Iran's nuclear program without having to bomb their facilities.  On the other hand you have to think that other countries can learn some tricks by looking at our code and increase the sophistication of their cyber attacks.  And seeing as we have more computer controlled infrastructure than anyone else, are we developing weapons that are most suited to be used against ourselves?

Comments

Ryan said…
Shows what you know. I don't have a web cam attached to my computer.
Brett said…
That's what they want you to think.
Ryan said…
Way to get this post just under the year mark.

Couldn't it be both scary and amazing?

I'm kind of amazed government made this work. Of course, they kind of screwed it up, too.

Popular posts from this blog

2019 Stats - Solar

Two Speeches

Books (2022 and 2023)