US Military 'Hacked' by Emails
An anonymous reader writes "Two of the US Military's most important science labs were apparently 'hacked'. Phishing mail was sent to a pair of research labs, where trojan programs allowed interlopers access to the otherwise secure networks. One of the sites was the infamous Los Alamos, which has been discussed many times here at Slashdot for its string of security breaches. 'Los Alamos has a checkered security history, having suffered a sequence of embarrassing breaches in recent years. In August of this year, it was revealed that the lab had released sensitive nuclear research data by email, while in 2006 a drug dealer was allegedly found with a USB stick containing data on nuclear weapons tests. "This appears to be a new low, even drug dealers can get classified information out of Los Alamos," Danielle Brian, executive director of the Project On Government Oversight (POGO), said at the time. Two years earlier, the lab was accused of having lost hard disks.'"
Unclassified networks get viruses and trojans often, this is not really news. Nor is it "omg huge security breach" that an unclassified network would get a virus. That is the the whole reason classified and unclassified networks and physically separated.
This simply further illustrates the need for better IT proffessionals. Most IT departments are looked at like maintence departments(In non IT firms). Something they are REQUIRED to have but not greatly to there advantage. Yes we introduce newer better software to increase productivity but we do it at a cost. So when it comes to IT security the budget is always smaller then should be. No one wants to pay more for the janitors to clean the locks every week. The locks still require keys and that is good enough. No one cares that the locks can be picked in 2 seconds.. as long it needs a key its fine. The same with IT. No one cares that you can be hacked because you send all you're data through unencrypted ethernet and that same network segment has a wifi-AP. You can't access either without a username or password.. right?!
So basically, -1 troll/offtopic is really slashdots way of saying "I hate that you thought of something before me."
I kid.
those ICBMs don't have ethernet jacks for their firmware updates ;)
Both labs in question are actually U.S. Department of Energy, not Department of Defense. Technically, they're not "military" labs.
More to the point, if they were military labs, the schlubs responsible for the security cockups would have been in the brig and awaiting a court-martial long ago. The knowledge that your "employer" can clap you in prison and then have you shot for almost a trivial incident is, to borrow a phrase, tremendously attention-focusing.
Yeah, yeah, I know, nuclear weapons and technology, blah, blah, blah... but really. Historically, these labs have always been run a little bit like the average academic research lab at any mainline university, and the stereotypes about egghead scientist types hating military-style regimentation (including security processes) rings very true. Read up about the Manhattan Project. (Which is fitting, since these labs are the direct descendants of that program.)
Welcome to the Panopticon. Used to be a prison, now it's your home.
People in a company I was working for awhile ago received a phishing email that was targeted to us and our environment. I, and a few other people noticed something weird. I did research and realized it was phishing fairly quickly and got the network people to immediately block that site and send out mail to everybody asking anybody who visited that site before it was blocked to have their computer fully checked for malware.
I think we narrowly avoided disaster that day, and I suspect none of the security people (I was not among them) quite realized exactly what happened. I was immensely surprised by how targeted it was.
I can easily understand why a user might've been taken in, and I don't blame them at all. I found the whole thing very unsettling.
Need a Python, C++, Unix, Linux develop
Mushroom clouds be in order, beeyach!
A feeling of having made the same mistake before: Deja Foobar
No one can hack into a classified (Secret or above) network from the outside by sending them emails or anything else - *because classified networks are not connected to the outside world*.
Brett
Don't believe him. Conspiracy theorists aren't for real. They are government agents pretending to be conspiracy theorists, in order to distract us, to keep us from discovering their great conspiracy.
Terrorists can't threaten a country's freedom and democracy. Only lawmakers and voters can do that.
Note that the
More recently, we're moving to some different networking configurations to help cut down on some of these breaches. It may help; it may not. Foreign nationals are losing administrator priveleges on their own (unclassified, mind you) computers, which is causing LOTS of headaches and won't solve a damned thing. Many of them have sent messages saying, "Yeah, remove my access, and see how much work gets done." If we had a moderation system here, those would be +5 Damned Right.
Which type of aliens though? Fom space or those just seeking a job?
There is no "disagree" moderation, and troll, flamebait and overrated are not valid substitutes
Is it really worth pouring more money into this idiotville if every bit of scientific progress they make is practically public knowledge soon after?
Exactly, because scientific progress is so worthless if it's made public.
You just got troll'd!
Shouldn't there be a large *Poof!* now, and the faint tinge of logic hanging in the air?
Actually conspiracy theorists are more like trolls. They take advantage of the gullible nature of most people.
HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
I live fairly near the Oak Ridge (TN) area. The National Labs there have done the same sort of work as Los Alamos since both sites were founded in the 40's. Contracts keep tending to go preferentially to Los Alamos - it currently gets roughly 4 times the government dollars overall, 5 times the spending on specifically Nuclear Deterrent related research, and is getting over 10 times the historical preservation funding to preserve its historic buildings. (That's just from the public record, without taking black budget spending into account. I don't know if that distorts the figures or not, obviously).
The Oak Ridge labs safety and security records are both far superior to Los Alamos. (While neither location has a perfect record, even non-serious rated incidents at ORNL have averaged many years apart. There has never been a security incident involving the ORNL facilities that didn't end up with the FBI at least knowing exactly what information was compromised, who did it, and who got it in the end, while there are three incidents on record for LA that no investigator can tell the congressional oversight committee just what may have been stolen, if they are confident they found everyone who did it or not, or if a particular hostile foreign government may possibly have ended up getting the info.).
There's also the Argonne labs in the Chicago area. Arguably, if there's some reason not to transfer more of LAs work to OR, they are also a better prospect if the US really cares about security. Los Alamos has had several opportunities to clean up their act - the problems are apparently systemic, and nothing short of major funding losses seems at all likely to motivate them at this point.
Who is John Cabal?
I've worked with a couple of the National Laboratories, and where Los Alamos really shines is basic research, while the others are better at engineering and have (somewhat) better security track records. This makes some sort of sense given the fact that they were operated by a university for so long while Sandia and Livermore have been over-seen by corporate entities. While it may make sense to move some of the more sensitive stock-pile stewardship programs away from there if they can't improve their security, it would be an absolute shame to shut the lab down altogether.
Actually, if you weren't an idiot trolling, you'd realize that the vast majority of foreign researchers in the US are in the country by virtue of the O1 visa, not the H1. This visa requires documentation and proof that the person is a world-renowned expert in their field, possesses world-class skills in the arts or sciences, and in short is nothing short of an absolutely unique and brilliant individual.
Or would you rather leave all those Pakistani, Chinese, and other brilliant scientists in their homelands, helping their repressive regimes?
I will grant that cybersecurity problems at national labs should be taken seriously. But there are at least 10,000 people doing at least part of their research at national labs, much of it inherently internet-based and hardly any of it has military applications. It is unreasonable to expect that no computers at a national lab will ever get hacked. Any computer that is connected to a network has a non-zero probability of getting hacked. I am doing my doctoral research at a national lab (Brookhaven) and have been in far too many meetings where we had to figure out how to work with security measures implemented in response to stories like this, which tend to paper over important details. The story says nothing about what information was actually acquired through the attack, for instance. And it neglected to mention that the "drug dealer" didn't actually have the USB stick with classified information, but rather lived with a person who worked at LANL and had illegally brought it home. He didn't even know he had anything classidied. (As usual, *people* are the weakest point in security, not computers.) As someone already commented, this is a Department of Energy Lab, not a "military" lab. Much, if not most, of the research at LANL is not classified. Just because someone at LANL got hacked does not mean classified information got hacked, nor does it mean that the computers that got hacked were remotely related to anything with the word "nuclear" in the subject. Among the measures which were proposed to remedy Brookhaven's "problems" with cybersecurity were banning all non-US citizens from logging in to any computer outside of BNL. There is a collider at BNL which has, overall, cost about $1B to build and run. This rule would have essentially stop this collider from running, costing the government about $1B, along with ending a promising scientific program. There were other rules proposed that we had to password-protect every computer - which is very dangerous if that computer controls an apparatus that operates at high voltage so someone who forgets or doesn't know the password can't turn it off. The slew of cyber-security updates imposed on BNL by DOE in response the the hysteria over cyber security caused me personally to lose two weeks of productivity because it was so hard to get into the computer clusters I needed to use for my research. There were about 1000 scientists affected by the same thing - we easily lost 20 person-years of labor, if not more. Even if you assume that everyone earned a grad student salary, that's $500,000. Overall, I have been in meetings which consumed about 40 hours of roughly 20 PhD scientists' time trying to figure out how to work around these rules. None of this includes the lost time because all of our computer experts were working on security instead of supporting the research goal of the lab. And what is at risk at Brookhaven? Data on relativistic heavy ion collisions. I personally think that if someone were really interested enough in our data to try to steal it, it would be a major development for the field. Oh man, and if they analyzed it - find those lambda baryons! - it would really decrease the work load in our collaboration. Please, take our data and analyze it for us! There's essentially no risk of permanent data loss because of multiple backups on various types of media in different geographical locations - you'd have to take out everything at once. The biggest real risk is that we would get hacked and turned into a porn server. Embarrassing, yes. Catastrophic? No. It happens to servers all the time. And indeed the one time I'm aware of BNL getting hacked, at least while I've been there, and all they did was sneak links to porn sites into an obscure webpage, not host porn on any BNL computers. (Which none of the stories mentioned... They all said BNL was hosting porn.) So what am I saying? 1. Simply because of the size and number of national labs, it is unreasonable to expect that national labs will never get hacked. 2. The response needs to be proportional to the risk. If the rules are too strict, this costs money, with no benefit.
Frankly, I'd rather the government spend tax money on this than on "securing for limited times to authors and inventors the exclusive right to their respective writings and discoveries". The second is far too easily abused by the MPAA/RIAA (notice how long copyright terms are now? Notice the DMCA?).
OSx86 FTW