Iran Forced To Replace Centrifuges To Stop Stuxnet
Trailrunner7 writes "Reports that Iran had recovered from the infection of the Stuxnet worm may have been overblown, as a new report suggests the country is being forced to replace thousands of expensive centrifuges damaged by the worm. The report from the website DEBKAfile cites 'intelligence sources' in claiming that Stuxnet was not purged from Iran's nuclear sites and that the country was never able to return its uranium enrichment efforts to 'normal operation.' Instead, the country has said in recent days that it is installing newer and faster centrifuges at its nuclear plants and intends to speed up the uranium enrichment process, according to the country's foreign ministry."
Iran believes they need nuclear weapons to be taken seriously. Why? Because they have seen that when a country has nuclear capability no one, especially the US, fucks with them.
The World is going to have to pay for generations the complete and utter fucked up foreign US policy - even when we're a broke run down ex-Super Power.
Windows has a lower total cost of ownership.
DEBKAfile is not a credible source of news. I remember in Gulf War 2 when they were reporting on the imminent launch of WMD gas my Saddam on US forces. This should not be on slashdot.
How can replacing thousands of expensive centrifuges be cheaper than replacing the infected computers??!! Dude, WTF?!
The centrifuges were damaged (due to the worm) and would remain damaged even when you replace/clean the infected computers.
STUXNET did real physical damage to the centrifuges by playing with their operating speeds.
Sounds fun as hell, and pretty probable too, TBH. Number one is hat Stuxnet got in there -before-; nothing keeps it from being re-inserted, possibly with modifications to avoid re-detection. Secondly is - think back to your corporate IT department and how often they make all their fixes right. They screw up sometimes, don't they?
Trust me, the Iranian government's a lot worse. They've got less expertise, less experience, less skills, and a language barrier to deal with most the time. I'd consider it a safe bet that they could've screwed up the cleanup, especially since they also tend to go cheap compared to other militaries (Look at rifles for a basic example here).
Either way, whoever's doing Stuxnet, good job here. I've got more faith in this then I do our diplomat's efforts for the reasons mentioned before - we bend over backwards for anyone who DOES have nukes and invade people who give 'em up. Doesn't take much IQ to see that throwing out your weapons program is a boneheaded idea if you're not going to take that 500 million bribe straightaway and retire before you get bit in the ass.
Some of the research says that there is executing code in the embedded controllers of the centrifuges, not just in the computers that control them at a high level. I'm not sure that they can be certain that the infected centrifuges themselves won't cause a reinfection of other systems. They may need to kill the patient to cure the disease.
http://en.wikipedia.org/wiki/Debka.com
I'm picturing some Israeli air-force tech with a Sharpie writing "StuxNet 2.0" on a hardened spike as it gets loaded onto an aircraft...
DEBKA is a known source of Israeli military and intelligence disinformation.
Any claim from this source is science fiction.
http://www.informationdissemination.net/2008/08/debka-makes-us-dumber-again.html
"Flyin' in just a sweet place,
Never been known to fail..."
Whether it is or is not an intelligence disinformation tool, DEBKA is generally regarded as being very unreliable. I wouldn't trust anything written there unless it were confirmed by at least two other independent sources.
Nearly fifty percent of all graduates come from the bottom half of the class!
It's an editorial, for crying out loud. Of course it's biased.
The real news is that Iran is scrapping somewhere between 5,000 and 6,000 centrifuges and replacing them with "faster" and "improved" ones. They supposedly announced this in a press conference, so I presume this can be independently verified apart from DEBKA's claim?
The rest of the article is conjecture, so feel free to come up with a better theory of why Iran is rebuilding their enrichment program from scratch.
Stuxnet is a really complex and well thought out windows worm but it's not magic and it can be beaten. Abusing holes in windows isn't some new thing that stuxnet invented.
Dealing with windows worms isn't nearly as complex as creating them.
Easy clean up process:
1) Disconnect affected windows machines from your network.
2) Overwrite the disks on these machines with zeros at least once.
3) Physically break the USB, firewire, sound, floppy connectors, extra disk connectors, serial ports, parallel ports on the motherboard of these computers. Break them in such a way they can't be fixed without significant effort.
4) Reinstall windows from clean CDs. Do not connect the machine to any network.
5) Reinstall SCADA software from clean CDs. Do not connect the machine to any network.
6) Setup one OpenBSD filtering bridge per SCADA control system to filter traffic to and from your new control machine and only allow traffic you have to. That means SCADA control traffic only. No windows update, no anti-virus updates, no domain authentications, no STP, and if possible not even ARP. Test with tcpdump and if 1 single network packet you don't fully understand gets though start again from step 1.
Done.
BTW I'm not a US citizen, a US visa holder, or in US controlled territory. I suspect that any US citizen or anyone in US controlled territory who assists Iran in any way is committing a criminal act. US export laws.. land of the free.. my arse.
Pakistan's nuclear arsenal most likely consists of warheads with yields comparable to Fat Man and Little Boy. It's delivery systems are most likely limited to those that can deliver these warheads to their immediate neighbors. The intention of the arsenal isn't to deter a super-power that sits on the other side of the world but to deter India.
The US could bomb Pakistan at will and not face any consequences it does not already face. What's Pakistan going to do, promulgate information on how to build nuclear warheads to foes of the US? Or maybe they might fund beligerents who are actively in state of war against the US?
Dont use industrial machines that run Windows....
Just saying.....
I agree totally. However if that's what the retards at Siemens give customers Iran has the choice to use it or reverse engineer it and setup their own software. Reverse engineering this stuff might well take years.
If you're going to discount a source, do it right. The article you cited just says they were employing faulty math when reporting one bit of information. I guess 34 knots is ridiculously fast for a naval group? I'll take your word for it, but it doesn't seem like a smoking gun for "This is a biased source." It's from 2008, maybe they learned what a reasonable speed for a naval group is since then?
The wiki page is somewhat more damning. The -real- reason to reject this specific article as pure rumor is the unnamed sources bit.
This just in: unnamed sources revealed to me that Iran's secret Death Star is not actually behind schedule for completion, it's actually fully functional!
Comment removed based on user account deletion