Best Defense
Thomas E. Ricks' daily take on national security.

Good article, but the big question is what happens when we get hit by a Stuxnet

I asked Jay Holcomb what he made of the big article about Stuxnet that ran in Sunday’s New York Times. Here is his response. By Jay Holcomb Best Defense infowar article critic I enjoyed reading the New York Times article, "Israeli Test on Worm Called Crucial in Iran Nuclear Delay" published Jan. 16. Everyone seems ...

By , a former contributing editor to Foreign Policy.
Markusram/Flickr
Markusram/Flickr
Markusram/Flickr

I asked Jay Holcomb what he made of the big article about Stuxnet that ran in Sunday's New York Times. Here is his response.

I asked Jay Holcomb what he made of the big article about Stuxnet that ran in Sunday’s New York Times. Here is his response.

By Jay Holcomb
Best Defense infowar article critic

I enjoyed reading the New York Times article, "Israeli Test on Worm Called Crucial in Iran Nuclear Delay" published Jan. 16. Everyone seems to agree that this was by far the most complex cyber event ever seen in the wild. By complex I’m referring to the number of technical features, such as zero-day exploits, industrial control system expertise, intelligence on target configurations, number of cyber exploits used on the target, such as root kits, botnet-type command and control, user view manipulation, etc.

I believe that the more media exposure we can generate from complex cyber events like this one, the better. However, I still believe we are missing the bigger picture with regard to these types of complex events. While I realize many folks really want to know where the Stuxnet package originated, I propose that we should be spending as much (or more) time looking around at what these events mean today, and in the near future, with regard to our cyber exposure — federal/state/local government resources, critical infrastructure, civilian industries, and even our own personal exposure.

I agree with Mr. Langner’s quote in the article, referring to the Stuxnet package, that, "It’s like a playbook…. Anyone who looks at it carefully can build something like it." Langner makes an important statement that I have not seen many people outside the industrial control system and cybersecurity industries mention or highlight. We can assume it is not only nation-states that are looking at events like these; terrorists and common criminals are most likely very busy right now looking at this too!

Many of the items highlighted in the article potentially read like a fortuneteller’s glass ball: "The vulnerability of the controller to cyberattack was an open secret. In July 2008, the Idaho lab and Siemens teamed up on a PowerPoint presentation on the controller’s vulnerabilities that was made to a conference in Chicago at Navy Pier, a top tourist attraction." This is not unusual, as significant vulnerabilities in software will often be publicly known. The vulnerabilities often are not addressed until (what seems like) enough public pressure is applied for a fix/patch to be produced and/or applied. While I have no specific information on "Smart Meters," recent articles which point out potential security concerns related to the deployment of "Smart Meters" make me wonder whether we’re not looking into a fortuneteller’s glass ball. I’ll include some reference links about this at the bottom of this note.

One final thought: While the Stuxnet event and associated reports have generated some public media exposure on complex cyber events, I find myself looking back on a report released by the U.S.-China Economic and Security Review Commission, dated Oct. 9, 2009, which does a great job explaining a very complex cyber intrusion — I wonder if that was a cyber building block to our current Stuxnet discussion?

Smart Meters:

"Money trumps security in smart-meter rollouts, experts say"

"Security Pros Question Deployment of Smart Meters"

"More Researchers Point to Smart Meter Security Holes"

"UK business electricity supplier reaches 12,000 smart meter installations"

"PSO says Owasso customers will be converting to smart grids as part of pilot program"

"The three stages of SmartMeterTM technology"

 

The U.S.-China Economic and Security Review Commission, "Capability of the People’s Republic of China to Conduct Cyber Warfare and Computer Network Exploitation" (p. 59, "Operational Profile of An Advanced Cyber Intrusion"), Oct. 9, 2009

Thomas E. Ricks is a former contributing editor to Foreign Policy. Twitter: @tomricks1

More from Foreign Policy

The USS Nimitz and Japan Maritime Self-Defense Force and South Korean Navy warships sail in formation during a joint naval exercise off the South Korean coast.
The USS Nimitz and Japan Maritime Self-Defense Force and South Korean Navy warships sail in formation during a joint naval exercise off the South Korean coast.

America Is a Heartbeat Away From a War It Could Lose

Global war is neither a theoretical contingency nor the fever dream of hawks and militarists.

A protester waves a Palestinian flag in front of the U.S. Capitol in Washington, during a demonstration calling for a ceasefire in Gaza. People sit and walk on the grass lawn in front of the protester and barricades.
A protester waves a Palestinian flag in front of the U.S. Capitol in Washington, during a demonstration calling for a ceasefire in Gaza. People sit and walk on the grass lawn in front of the protester and barricades.

The West’s Incoherent Critique of Israel’s Gaza Strategy

The reality of fighting Hamas in Gaza makes this war terrible one way or another.

Biden dressed in a dark blue suit walks with his head down past a row of alternating U.S. and Israeli flags.
Biden dressed in a dark blue suit walks with his head down past a row of alternating U.S. and Israeli flags.

Biden Owns the Israel-Palestine Conflict Now

In tying Washington to Israel’s war in Gaza, the U.S. president now shares responsibility for the broader conflict’s fate.

U.S. President Joe Biden is seen in profile as he greets Chinese President Xi Jinping with a handshake. Xi, a 70-year-old man in a dark blue suit, smiles as he takes the hand of Biden, an 80-year-old man who also wears a dark blue suit.
U.S. President Joe Biden is seen in profile as he greets Chinese President Xi Jinping with a handshake. Xi, a 70-year-old man in a dark blue suit, smiles as he takes the hand of Biden, an 80-year-old man who also wears a dark blue suit.

Taiwan’s Room to Maneuver Shrinks as Biden and Xi Meet

As the latest crisis in the straits wraps up, Taipei is on the back foot.