Slashdot Mirror


Pentagon Confirms 2008 Computer Breach — 'Worst Ever'

jowifi writes "The New York Times reports that the Pentagon has confirmed that, in 2008, a foreign agent instigated 'the most significant breach of US military computers ever' using a USB flash drive. While the breach was previously reported on Wired and the LA Times, this is the first official confirmation of the attack that led to the banning of USB drives on government computers."

19 of 157 comments (clear)

  1. This is likely why MS has GPOs in W7 by mlts · · Score: 4, Insightful

    This is likely why Windows 7 has explicit GPOs to either set USB flash drives read-only, or deny them the ability to mount whatsoever. Other programs that have this functionality are PGP Universal, and Symantec Endpoint Protection.

    Now, if MS can put autoplay/autorun to rest six feet under with Clippy and Bob, that would be a good security advance.

    1. Re:This is likely why MS has GPOs in W7 by rikkards · · Score: 3, Interesting

      The thing that is stupid about it is that sure block exes from being run from a USB, then the user will copy it to the machine and run it there.
      BTW, GPOs from day one have had the ability to disable Autoplay and autorun.

    2. Re:This is likely why MS has GPOs in W7 by rickb928 · · Score: 3, Interesting

      I have this dim recollection that we could do this with GPOs in Win XP.

      And we could use ZenWorks to do it also. Much nicer editor, and volatile accounts are a blessing in school labs.

      Disabling removable media isn't new, just overlooked.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    3. Re:This is likely why MS has GPOs in W7 by Lehk228 · · Score: 4, Interesting

      there should be a way to restrict execution to only code signed by the owning organization's IT security.

      --
      Snowden and Manning are heroes.
    4. Re:This is likely why MS has GPOs in W7 by Ethanol-fueled · · Score: 4, Insightful

      There are ways to hide stuff like that from view on Windows. They magically show up when the USB device is plugged into a Linux box.

      Related note: A similar piece of malware and the ensuing hassle is what prompted me to switch to Linux for good.

    5. Re:This is likely why MS has GPOs in W7 by dgatwood · · Score: 4, Insightful

      There should never have been a way to enable autorun in the first place. The very notion of automatically executing code or installers form a piece of media without the user explicitly taking any action is antithetical to proper security.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

    6. Re:This is likely why MS has GPOs in W7 by Mr+44 · · Score: 3, Informative

      Like "Software Restriction Policies" in windows XP and AppLocker in Windows 7?

  2. The right reaction? by mangu · · Score: 4, Insightful

    the attack that led to the banning of USB drives on government computers.

    This reminds me of the joke of the man that, having learned that his wife was fucking other men in the couch in the living room, moved the couch to the garage.

    USB drives have a purpose for legal uses. Wouldn't it be better to improve their systems so that USB drives couldn't be used in harmful ways?

    1. Re:The right reaction? by Dahamma · · Score: 4, Informative

      From TFA...

      In an early step, the Defense Department banned the use of portable flash drives with its computers, though it later modified the ban.

      Fixing the vulnerabilities takes time. It was just an emergency measure until they could investigate and come up with better policy.

    2. Re:The right reaction? by Beardo+the+Bearded · · Score: 5, Informative

      They have.

      Look, they have two completely separate computer networks. They've got a network that can access all the Classified Military Shit, and then they have the computers that can access Everything Bad in the Multiverse. (My terms, not theirs.) The two never meet. Never ever ever, and not even then.

      99% of the time, you work with the Unclassified stuff. It's a PITA to work with Classified documents. You've got to go to a secure room, you can't make a copy unless you've signed off a billion times, you have to work on a special computer, you have to have a buddy / guard / watcher, and you've got to go through a debriefing after you've goofed around with it.

      If your average worker / troop / contractor picked up a USB drive and put it into their EBitM network and it took over every machine in a billionth of a second and sent all the info on the EBitM network to China, Russia, and Zork the Evil, the risk to National Security would be zilch. Yeah, it would be a PITA to fix the compys, but it would be no worse than the same PITA you'd get in any large civilian network. The only difference is that it's a huge fucking PR nightmare. Think about how embarrassing it would be if Norton was taken down due to a worm. Now go up two orders of magnitude.

      The computers you see the troops using are almost always personal property used for emailing back home, watching movies, playing games, and otherwise fucking around. The work computers are usually tied into the EBitM network and they use them for work. Unless you are one of The Anointed Few, you haven't even seen a computer that's handled Classified information.

      --

      ---
      ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.
    3. Re:The right reaction? by guruevi · · Score: 4, Insightful

      After actually having implemented such a methods, it is noticed that nobody ever uses the classified network except for highly official stuff, when the project is done. It seems that all work in progress is just being saved on the non-classified network.

      Trust me, I have implemented just about any security method in a variety of settings (medical, financial, ...). The fact remains that people can't be bothered to lock their screens when they step out because it's "too difficult" and "too complicated" let alone click the button to encrypt their e-mail or their USB sticks.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    4. Re:The right reaction? by Anonymous Coward · · Score: 3, Funny

      Wow! It sounds like Internet information clearinghouse sites like wikileaks stand no chance of ever getting their hands on sensitive information with a system as strong as you describe.

  3. Where there's a USB port ... there's a way by PolygamousRanchKid+ · · Score: 4, Interesting

    A US Army dental surgeon told me that their computers were "fixed", so they could not copy pictures of their operations to any external media. The surgeons needed anonymous pictures of operations that they had performed, for preparing for their careers after their service. Like, applying for a job somewhere.

    One of them figured a way to use the USB port in the Canon printer that they had. They could toss pictures at the printer, and land them on the USB stick. Circumventing any blocks on the PCs from accessing the PCs' USB ports.

    So any unprotected port is, well, a potential source of a leak.

    --
    Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
    1. Re:Where there's a USB port ... there's a way by countSudoku() · · Score: 3, Funny

      That's a good work-around!

      So any unprotected [USB] port is, well, a potential source of a leak.

      Along with any camera, copier, cell phone, human with a memory, network accessible device, etc. Every kind of access restriction can be circumvented. *Every* kind.

      I would suggest mounting all laptops in cement, then chaining the cement block down to the cube frame structure. Close off all connectivity, embed in a Faraday Cage, then keep anyone, including the approved user, from accessing it, and you're all set! Bob's your uncle! Otherwise, expect your data to escape. Because it will. :) Have a nice day!

      --
      This is the NSA, we're gonna geet U h@x0r5! Also, what is a h@x0r5?
  4. More Self-Serving Hype by yourpusher · · Score: 3, Insightful

    Rob Rosenberger at VMyths notes:

    et’s cut to the chase. U.S. Deputy Defense Secretary William J. Lynn III wrote an op-ed for a commercial publication in which he claims a single USB thumb drive caused the worst military data breach in history. And according to Wikipedia, that one little USB stick led to the creation of the Pentagon’s new Cyber Command.
    [. . .]

    I’ll bet it took so long only because it was a classified operation. This malware would have blown over in a week if DoD-CERT had issued an email saying “hey, there’s a new virus running around, please scan your PCs for agent.btz.”

    {sniff} I can definitely smell a lot of groupthink here. Not to mention hype, which goes hand in hand with groupthink.

    Lynn suffers from a short memory span. We know this because he thinks the Pentagon got “a wake-up call” when agent.btz slithered into classified networks. If Lynn’s brain had more RAM, he would recall the Melissa virus did EXACTLY the same thing in 1999. It infected classified U.S. networks at a depth & scope even I myself would label “impressive.”

    So why this story? Well (from the same source):

    You can see I’ve got a healthy dose of skepticism over Lynn’s “Buckshot Yankee” revelation. And I’m not alone: Wired filed a story with the headline “Insiders Doubt 2008 Pentagon Hack Was Foreign Spy Attack.”

    Waitaminit. GCN’s breathless story includes the phrase “Lynn said Wednesday in a teleconference with reporters.” You mean to say he gabbed with the media on top of all the hype he wrote in an official capacity for a commercial publication? {sniff} I smell a book deal in the works when Lynn’s boss retires next year.

  5. Not the worst ever... by d474 · · Score: 4, Funny

    In 1983, a high school kid named David Lightman hacked his way into DOD computer @ Norad called the W.O.P.R. which almost resulted in an all out nuclear war between the U.S.A. and Russia. I believe they made a movie about it.

    So until I hear a story that tops that, keep your "worst ever" superlatives to yourself. Oh, wait...

    --
    Authority questions you. Return the favor.
  6. Re:Haven't I seen this movie before? by PitaBred · · Score: 3, Funny

    Didn't you read? He said magmetic field. I assume it has to do with magma, maybe burning the user alive. That sounds pretty secure to me.

  7. Re:Still vulnerable by Beardo+the+Bearded · · Score: 4, Funny

    It's always someone's first day. It took you years to get to the point you could even post on /.

    --

    ---
    ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.
  8. This is why DoD needs to put a bullet in M$ by SgtChaireBourne · · Score: 3, Interesting

    In 2008 any standard issue Army computer would've...

    But were they able to track down and deal with the individual(s) that deployed Microsoft products?

    The military procurement procedures produce a solid paper trail even if on some occasions they produce nothing else. Had they deployed properly engineered products rather than brands infamous for bad design the problem would not have arisen. The US Navy will focus on open systems only, if it can stay clear of the old M$ contractors and M$ resellers.

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.