Iran Forced To Replace Centrifuges To Stop Stuxnet
Trailrunner7 writes "Reports that Iran had recovered from the infection of the Stuxnet worm may have been overblown, as a new report suggests the country is being forced to replace thousands of expensive centrifuges damaged by the worm. The report from the website DEBKAfile cites 'intelligence sources' in claiming that Stuxnet was not purged from Iran's nuclear sites and that the country was never able to return its uranium enrichment efforts to 'normal operation.' Instead, the country has said in recent days that it is installing newer and faster centrifuges at its nuclear plants and intends to speed up the uranium enrichment process, according to the country's foreign ministry."
Iran believes they need nuclear weapons to be taken seriously. Why? Because they have seen that when a country has nuclear capability no one, especially the US, fucks with them.
The World is going to have to pay for generations the complete and utter fucked up foreign US policy - even when we're a broke run down ex-Super Power.
DEBKAfile is not a credible source of news. I remember in Gulf War 2 when they were reporting on the imminent launch of WMD gas my Saddam on US forces. This should not be on slashdot.
How can replacing thousands of expensive centrifuges be cheaper than replacing the infected computers??!! Dude, WTF?!
The centrifuges were damaged (due to the worm) and would remain damaged even when you replace/clean the infected computers.
STUXNET did real physical damage to the centrifuges by playing with their operating speeds.
http://en.wikipedia.org/wiki/Debka.com
DEBKA is a known source of Israeli military and intelligence disinformation.
Any claim from this source is science fiction.
http://www.informationdissemination.net/2008/08/debka-makes-us-dumber-again.html
"Flyin' in just a sweet place,
Never been known to fail..."
It's an editorial, for crying out loud. Of course it's biased.
The real news is that Iran is scrapping somewhere between 5,000 and 6,000 centrifuges and replacing them with "faster" and "improved" ones. They supposedly announced this in a press conference, so I presume this can be independently verified apart from DEBKA's claim?
The rest of the article is conjecture, so feel free to come up with a better theory of why Iran is rebuilding their enrichment program from scratch.
Stuxnet is a really complex and well thought out windows worm but it's not magic and it can be beaten. Abusing holes in windows isn't some new thing that stuxnet invented.
Dealing with windows worms isn't nearly as complex as creating them.
Easy clean up process:
1) Disconnect affected windows machines from your network.
2) Overwrite the disks on these machines with zeros at least once.
3) Physically break the USB, firewire, sound, floppy connectors, extra disk connectors, serial ports, parallel ports on the motherboard of these computers. Break them in such a way they can't be fixed without significant effort.
4) Reinstall windows from clean CDs. Do not connect the machine to any network.
5) Reinstall SCADA software from clean CDs. Do not connect the machine to any network.
6) Setup one OpenBSD filtering bridge per SCADA control system to filter traffic to and from your new control machine and only allow traffic you have to. That means SCADA control traffic only. No windows update, no anti-virus updates, no domain authentications, no STP, and if possible not even ARP. Test with tcpdump and if 1 single network packet you don't fully understand gets though start again from step 1.
Done.
BTW I'm not a US citizen, a US visa holder, or in US controlled territory. I suspect that any US citizen or anyone in US controlled territory who assists Iran in any way is committing a criminal act. US export laws.. land of the free.. my arse.