Slashdot Mirror


Pentagon Confirms 2008 Computer Breach — 'Worst Ever'

jowifi writes "The New York Times reports that the Pentagon has confirmed that, in 2008, a foreign agent instigated 'the most significant breach of US military computers ever' using a USB flash drive. While the breach was previously reported on Wired and the LA Times, this is the first official confirmation of the attack that led to the banning of USB drives on government computers."

11 of 157 comments (clear)

  1. This is likely why MS has GPOs in W7 by mlts · · Score: 4, Insightful

    This is likely why Windows 7 has explicit GPOs to either set USB flash drives read-only, or deny them the ability to mount whatsoever. Other programs that have this functionality are PGP Universal, and Symantec Endpoint Protection.

    Now, if MS can put autoplay/autorun to rest six feet under with Clippy and Bob, that would be a good security advance.

    1. Re:This is likely why MS has GPOs in W7 by Lehk228 · · Score: 4, Interesting

      there should be a way to restrict execution to only code signed by the owning organization's IT security.

      --
      Snowden and Manning are heroes.
    2. Re:This is likely why MS has GPOs in W7 by Ethanol-fueled · · Score: 4, Insightful

      There are ways to hide stuff like that from view on Windows. They magically show up when the USB device is plugged into a Linux box.

      Related note: A similar piece of malware and the ensuing hassle is what prompted me to switch to Linux for good.

    3. Re:This is likely why MS has GPOs in W7 by dgatwood · · Score: 4, Insightful

      There should never have been a way to enable autorun in the first place. The very notion of automatically executing code or installers form a piece of media without the user explicitly taking any action is antithetical to proper security.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

  2. The right reaction? by mangu · · Score: 4, Insightful

    the attack that led to the banning of USB drives on government computers.

    This reminds me of the joke of the man that, having learned that his wife was fucking other men in the couch in the living room, moved the couch to the garage.

    USB drives have a purpose for legal uses. Wouldn't it be better to improve their systems so that USB drives couldn't be used in harmful ways?

    1. Re:The right reaction? by Dahamma · · Score: 4, Informative

      From TFA...

      In an early step, the Defense Department banned the use of portable flash drives with its computers, though it later modified the ban.

      Fixing the vulnerabilities takes time. It was just an emergency measure until they could investigate and come up with better policy.

    2. Re:The right reaction? by Beardo+the+Bearded · · Score: 5, Informative

      They have.

      Look, they have two completely separate computer networks. They've got a network that can access all the Classified Military Shit, and then they have the computers that can access Everything Bad in the Multiverse. (My terms, not theirs.) The two never meet. Never ever ever, and not even then.

      99% of the time, you work with the Unclassified stuff. It's a PITA to work with Classified documents. You've got to go to a secure room, you can't make a copy unless you've signed off a billion times, you have to work on a special computer, you have to have a buddy / guard / watcher, and you've got to go through a debriefing after you've goofed around with it.

      If your average worker / troop / contractor picked up a USB drive and put it into their EBitM network and it took over every machine in a billionth of a second and sent all the info on the EBitM network to China, Russia, and Zork the Evil, the risk to National Security would be zilch. Yeah, it would be a PITA to fix the compys, but it would be no worse than the same PITA you'd get in any large civilian network. The only difference is that it's a huge fucking PR nightmare. Think about how embarrassing it would be if Norton was taken down due to a worm. Now go up two orders of magnitude.

      The computers you see the troops using are almost always personal property used for emailing back home, watching movies, playing games, and otherwise fucking around. The work computers are usually tied into the EBitM network and they use them for work. Unless you are one of The Anointed Few, you haven't even seen a computer that's handled Classified information.

      --

      ---
      ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.
    3. Re:The right reaction? by guruevi · · Score: 4, Insightful

      After actually having implemented such a methods, it is noticed that nobody ever uses the classified network except for highly official stuff, when the project is done. It seems that all work in progress is just being saved on the non-classified network.

      Trust me, I have implemented just about any security method in a variety of settings (medical, financial, ...). The fact remains that people can't be bothered to lock their screens when they step out because it's "too difficult" and "too complicated" let alone click the button to encrypt their e-mail or their USB sticks.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
  3. Where there's a USB port ... there's a way by PolygamousRanchKid+ · · Score: 4, Interesting

    A US Army dental surgeon told me that their computers were "fixed", so they could not copy pictures of their operations to any external media. The surgeons needed anonymous pictures of operations that they had performed, for preparing for their careers after their service. Like, applying for a job somewhere.

    One of them figured a way to use the USB port in the Canon printer that they had. They could toss pictures at the printer, and land them on the USB stick. Circumventing any blocks on the PCs from accessing the PCs' USB ports.

    So any unprotected port is, well, a potential source of a leak.

    --
    Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
  4. Not the worst ever... by d474 · · Score: 4, Funny

    In 1983, a high school kid named David Lightman hacked his way into DOD computer @ Norad called the W.O.P.R. which almost resulted in an all out nuclear war between the U.S.A. and Russia. I believe they made a movie about it.

    So until I hear a story that tops that, keep your "worst ever" superlatives to yourself. Oh, wait...

    --
    Authority questions you. Return the favor.
  5. Re:Still vulnerable by Beardo+the+Bearded · · Score: 4, Funny

    It's always someone's first day. It took you years to get to the point you could even post on /.

    --

    ---
    ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.