Predator Drone 'Virus' Could Be Military's Own Monitoring
jjp9999 writes "The virus that hit Predator and Reaper UAVs could be an internal monitoring system employed by the military. According to security researcher Miles Fidelman, there are vendors that sell security monitoring packages to the Defense Department which are 'essentially rootkits that do, among other things, key logging.' The virus is a keylogger that was found at pilot stations, and could be keeping tabs on keystrokes used by pilots to control the UAVs, found Wired's Danger Room blog. Fidelman adds, 'I kind of wonder if the virus that folks are fighting is something that some other part of DoD deployed intentionally.'"
If they meant to do it, it's still incompetence, since they apparently just FORGOT TO MENTION it to the people whose job it is to detect actual outside attacks.
To anyone who's spent any time dealing with military computer security, unfortunately, this really isn't a surprise.
The correlation between ignorance of statistics and using "correlation is not causation" as an argument is close to 1.
Why install a rootkit to log keystrokes when you have full control over the application whose keystrokes you want to log?
Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
To anyone who's spent any time dealing with military computer security, unfortunately, this really isn't a surprise.
To anyone who's spent any time dealing with computers, unfortunately, this really isn't a surprise.
Digital warfare style.
"Didn't you get the memo?"
Or they could just do what they've been doing all along and label anyone on the wrong end of their detached and indiscriminate bombings as "enemy combatants." It works well enough at home and I sincerely doubt that the people living in fear of drone strikes respect appreciate their presence to begin with. "It wasn't me that upset the bear I put in your house, it was those guys over there!"
must be a sony drone. oooh burrrn on sony!
-- Flame me and I will happily flame you back. Bring it!
Sorry, can't do that. It is classified.
I'd rather be riding my '63 Triumph T120.
No no it's not a virus. Its... unannounced monitoring services. Double plus good.
The centrifuges were designed to act that way.
Why install a rootkit to log keystrokes when you have full control over the application whose keystrokes you want to log?
Maybe the code of the main application is such a mess that you don't want to touch it if you don't need to.
The Tao of math: The numbers you can count are not the real numbers.
Haven't killing machines been guilt free since the invention of the bow and arrow? Not having to look your enemy in the eye makes things a lot easier.
The machines always have been guilt-free. It was always the humans who were guilty.
The Tao of math: The numbers you can count are not the real numbers.
Reminds me of one of the de-motivational posters from Despair, Inc entitled CONSULTING "If you aren't part of the solution there is great money to be made in prolonging the problem"
Luckily, there's a simple test for that. Does the virus bring up the following dialog box?
[Virus Message]
This is not a drill.
[OK] [Cancel]
If so, then it's definitely a DoD virus.
He's a security researcher and so are the Beagle boys. The guy is a well known crank with a rich fantasy life. Slashdot just keeps getting worse.
I have no issues what so ever eliminating hate filled hypocritical pustules
When do you plan to set drones loose on Washington?
"I've got more toys than Teruhisa Kitahara."
When do you plan to set drones loose on Washington?
Well, they found my key logger, so that plan is on the back burner for the time being...
If you want news from today, you have to come back tomorrow.
I have no issues what so ever eliminating hate filled hypocritical pustules
When do you plan to set drones loose on Washington?
That is the other one, the creditor drone.
The whole story can be summarized with the following quote:
Miles Fidelman: "I kind of wonder if..."
That's about it. Let's have some more fun.
Predator Drone 'Virus' Could Have Been Planted By Dick Cheney.
Predator Drone 'Virus' Could Be Product of Iran Intelligence Agency.
Predator Drone 'Virus' Could Be Designed to Target Nude Beaches.
etc.
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
I would think that if you have people whose job it is to push keys, the results of those key pushes being missiles firing and possibly killing other humans, one would insist on logging those key strokes:
Officer: "The drone you're operating just launched a missile into a school yard and killed 30 children! What did you do?"
Drone operator: "I dunno. I was pushing some keys and, well, it just kinda happened."
Officer: "Which keys did you push?"
Drone operator: "I'm not sure. I was kinda distracted eating a donut. You know how it is when you're eating a donut: you really want to focus in on it."
Officer: "Hmmm. OK. Back to work. Got any more of those donuts?"
Argh... we're building weapons systems based on windows or mac or linux? What are these people, nuts?
If there was ever a place where capability based security should be used, this is it. An application that has the ability to literally kill people should not be run in an environment which defaults to permissive... this means that ANY application on that system could potentially kill someone.
With the exception of a few wise souls here and there, nobody else seems to get the idea that this kind of thing can be stopped, dead, in its tracks. (Pun intended)
Capability based security offers a path forward to computers that trust nothing by default... the exact opposite of what we have now. They don't have to be unusable, nor layered with ineffective anti-spyware, anti-malware, etc...
Just stop trusting applications, and specify what they can do, as a maximum extent, before you execute them. This limits the damage a rogue (or just confused) application can incur before it's even run.
Now... I've obviously made some typos and a few things could be made clearer in the above... unfortunately /. doesn't allow editing or clarification of a post after it's written... nor does it offer any voting other than a popularity contest... so let the inefficient commenting begin.
A big story goes out about how the drone control system are really seriously compromised. Not only have they detected malware, but they're unable to get rid of it. A few days later, a new story comes out. "Yeah, we totally meant to do that." Only it doesn't even say that. Instead, it says, "Wouldn't it be interesting if they totally meant to do that?"
Even if the malware was installed by some shadowy arm of our government, it's a giant screw up if the guys who are in charge of running the systems didn't keep it out and can't remove it once it's detected. If the guys running the system were competent, the shadowy arm of our own government shouldn't be able to install this crap and more easily than anyone else.
it must have been those pesky hackers; the virus did it.
No, I'm not buyin it.
The military is the military, they do not "do" plausible deniability: they receive orders, and execute them.
My guess is that these are nested "rootkits", if you will, reflecting the various levels of clearance that exist in a military foodchain. One can then log in and spy on all the others that his clearance allows him to.
The three laws of thermodynamics:(1) You can't win. (2) You can't break even. (3) You can't even quit.