DHS Mistakenly Releases 840 Pages of Critical Infrastructure Documents
wiredmikey (1824622) writes The Operation Aurora attack was publicized in 2010 and impacted Google and a number of other high-profile companies. However, DHS responded to the request by releasing more than 800 pages of documents related to the 'Aurora' experiment conducted several years ago at the Idaho National Laboratory, where researchers demonstrated a way to damage a generator via a cyber-attack. Of the documents released by the DHS, none were related to the Operation Aurora cyber attack as requested. Many of the 840 pages are comprised of old weekly reports from the DHS' Control System Security Program (CSSP) from 2007. Other pages that were released included information about possible examples of facilities that could be vulnerable to attack, such as water plants and gas pipelines.
Why I vote Democrat
I vote Democrat because I believe it’s okay if our federal government borrows $85 Billion every single month.
I vote Democrat because I care about the children but saddling them with trillions of dollars of debt to pay for my bloated leftist government is okay.
I vote Democrat because I believe it’s better to pay billions of dollars to people who hate us rather than drill for our own oil, because it might upset some endangered beetle or gopher.
I vote Democrat because I believe it is okay if liberal activist judges rewrite the Constitution to suit some fringe kooks, who would otherwise never get their agenda past the voters.
I vote Democrat because I believe that corporate America should not be allowed to make profits for themselves or their shareholders. They need to break even and give the rest to the federal government for redistribution.
I vote Democrat because I’m not concerned about millions of babies being aborted, so long as we keep all of the murderers on death row alive.
I vote Democrat because I believe it’s okay if my Nobel Peace Prize winning President uses drones to assassinate people, as long as we don’t use torture.
I vote Democrat because I believe people, who can’t accurately tell us if it will rain on Friday, can predict the polar ice caps will melt away in ten years if I don’t start driving a Chevy Volt.
I vote Democrat because Freedom of Speech is not as important as preventing people from being offended.
I vote Democrat because I believe the oil companies’ profit of 3% on a gallon of gas is obscene, but the federal government taxing that same gallon of gas at 15% isn’t obscene.
I vote Democrat because I believe a moment of silent prayer at the beginning of the school day constitutes government indoctrination and an intrusion on parental authority .. but sex education, condom distribution and multiculturalism are all values-neutral.
I vote Democrat because I agonize over threats to the natural environment from CO2, acid rain and toxic waste .. but I am totally oblivious of the threats to our social environment from pornography, promiscuity and family dissolution.
I vote Democrat because I believe lazy, uneducated stoners should have just as big a say in running our country as entrepreneurs who risk everything and work 70 hours per week.
I vote Democrat because I don’t like guns .. so no one else should be allowed to own one.
I vote Democrat because I see absolutely no correlation between welfare and the rise of illegitimacy.
I vote Democrat because I see absolutely no correlation between judicial leniency and surging crime rates.
I vote Democrat because I believe you don’t need an ID to vote but you do to buy beer.
I vote Democrat because I believe marriage is obsolete, except for homosexuals.
I vote Democrat because I think AIDS is spread by insufficient funding.
I vote Democrat because I think “fairness” is far more important than freedom.
I vote Democrat because I think an “equal outcome” is far more important than equal opportunity.
I vote democrat because I would rather hide in a class room while others fight for my freedom.
I vote democrat because I’m not smart enough to own a gun and I need someone else to protect me.
I vote democrat because I would rather have free stuff than freedom.
And lastly, I vote Democrat because I’m convinced that government programs are the solution to the human condition, NOT freedom.
"Mistakenly" Sure...
Coder's Stone: The programming language quick ref for iPad
From what the article shows, it seems like a lot of this information is public knowledge - where substations and water plants are and how they operate. Pretty much everyone in my town knows where the local substations are, and it doesn't take a genius to know that an attack that disables or destroys a substation would have a massive impact on the people living there. None of these documents appear to be classified, which means they don't contain anything that DHS was afraid of the general public knowing.
It would be a different story if these were classified documents containing things like the floor plans for nuclear plants and gaps in security at said plants that could actually be useful in an attack, but this seems like a non-story other than that DHS's FOIA officer got lazy and just CTRL+F'd for "Aurora" and blindly copied anything with that word in the name.
that nothing can be kept secret anymore? Whatever you want not to be exposed, whether diplomatic communications or technical documents or "intellectual property", will eventually reach the internet either by whistle-blowing or human error? And once it reaches the internet, if anyone cares about it then it will be perpetuated forever?
There are advantages to such a situation, of course, but also disadvantages.
HANG THEM!
Er...ya...or something.
Do it in the name of whistleblowing, and your treasonous. Do it 'mistakenly', and it's 'OK'. Just an 'oopsie'. What's the fine, or charge, for 'accidentally' enabling the terrorists again? That's right. Nothing!
Can I get a new Government? Possibly one where incompetence is a disqualification for anything having to do with infrastructure, security, or Civil Liberties?
A honeypot by itself won't be attracting any bee
An advertised honeypot, on the other hand ...
/. says a lot !
and the involvement of
You see, those dept.'s want even more of your money, and what with terrorists keeping quiet these days and the extremists
being ID''ed by whether or not they read Linux Journal, the DHS, TSA, NSA and any other acronym that's got the coveted 'S',
are starting to look pathetic.
Can't have that!
The requestor obviously was looking for information on the "operation aurora" hacking that occurred in 2010. DHS confused this with the "aurora" vulnerability from 2007 which sought to prove that an ICS attack could break a generator. I think that is all and the 2007 aurora info is long public.
Gee, shock surprise that the Department of Hardons for Stasiism fucks up like this.
What does any one expect from a newly formed "law" enforcement that supercedes
all other "law" enforcement of the land? It's bound to be full of fuckups and n00bs
who don't know what the fuck they are doing. And this just proves this...
...in a perfect world.
Recall the inadvertent Gmail slip, and the doctor SSN fail ...
Buy then books and send them to school and they bite the teacher.
It little behooves the best of us to comment on the rest of us.
This documentation relates to vulnerabilities which were presumably identified about 4 years ago, if they haven't already been fixed they SHOULD be advertised to shame those responsible into fixing them. Its disturbing how often society/government cringes at the "unauthorized" release of information instead of the lack of action & accountability that they so often show.
Were the missing IRS emails in there?
Why I vote Republican
I vote Republican because I believe it’s okay if our federal government borrows $85 Billion every single month...as long as it's spent by the Department of Defense.
I vote Republican because I claim to care about the children but don't want any money spent on education or healthcare.
I vote Republican because I believe it is okay if conservative activist judges rewrite the Constitution to suit some fringe kooks, who would otherwise never get their agenda past the voters.
I vote Republican because I believe that corporate America should be allowed to make profits for themselves, by outsourcing American jobs, busting unions, destroying the environment and lobbying corrupt politicians.
I vote Republican because I’m concerned about millions of babies being aborted, but don't care what happens after they're born.
I vote Republican because I don't know the difference between weather and climate.
I vote Republican because The Right To Bear Arms is not as important as preventing people from being murdered.
I vote Republican because I believe lazy, uneducated rednecks should have just as big a say in running our country as entrepreneurs who risk everything and work 70 hours per week.
I vote Republican because I see absolutely no correlation between corporate welfare and the rise of income inequality.
I vote Republican because I see absolutely no correlation between lenient gun laws and surging crime rates.
I vote Republican because I believe you don’t need an ID buy a gun, but do to vote.
I vote Republican because I think AIDS is prevented by keeping children ignorant about safe sex.
I vote Republican because I think “freedom” is far more important than fairness.
I vote Republican because I think an “equal opportunity” means anyone can apply for a job but only white males will get one.
I vote Republican because I would rather hide in a boardroom while others fight for my freedom.
I vote Republican because I’m not smart enough to own a gun but think I should be allowed to anyway.
And lastly, I vote Republican because I’m convinced that government is the source of all our problems... and prove it every time we're in office.
Support Right To Repair Legislation.
Step one: Release a bunch of 'critical' documents by 'mistake'.
Step two: Twiddle thumbs while terrorists / criminals abuse information released in step one.
Step three: Point to attack in caused by step two, argue that DHS should be exempt from FOI Request because 'national security'.
Step four: DHS can do anything they like without the public oversight.
Everything in the world is controlled by a small, evil group to which, unfortunately, no one you know belongs.
There's nothing mysterious about this. The problem is that if someone gets control of circuit breakers for large rotating equipment, they may be able to disconnect it, let it get out of sync, and reconnect it. This causes huge stresses on motor and generator windings and may damage larger equipment. This is a classic problem in AC electrical systems. A more technical analysis of the Aurora vulnerability is here.
The attack involves taking over control of a power breaker in the transmission system, one that isn't protected by a device that checks for an in-phase condition. Breakers that are intended to be used during synchronization (such as the ones nearest generators) have such protections, but not all breakers do.
Protective relaying in power systems is complicated, because big transient events occur now and then. A lightning strike is a normal event in transmission systems. The system can tolerate many disruptive events, and you don't want to shut everything down and go to full blackout because the fault detection is overly sensitive. A big inductive load joining the grid looks much like an Aurora attack for the first few cycle or two.
There's a problem with someone reprogramming the setpoints on protective relays. This is the classic "let's make it remotely updatable" problem. It's so much easier today to make things remotely updatable than to send someone to adjust a setting. The Aurora attack requires some of this. There's a lot to be said for hard-wired limits that can't be updated remotely, such as "reclosing beyond 20 degrees of phase error is not allowed, no matter what parameters are downloaded."
Does anyone have a better link to the document to download and view? The browser on that Muckrock site is supremely annoying.