By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - General - US 'to view major cyber attacks as acts of war'

Galaki said:
mrstickball said:
Galaki said:

Sometime, people forgot that not everything has to be connected to the interwebz.

Doesn't need to be.

The stuxnet attack against the nuclear facility in Iran was a hardwired intranet that had no external access points. They got in via an infected (from my understanding) USB key which was put into a local computer at the facility, which then infected the entire system and heavily damaged the facility.

Isn't that due to employee negligence? You don't just plug any usb into your mainframe...

I don't quite know if one could consider it employee negligence. From my understanding, it infected 16 million PCs in hopes to hop on any computer that would interact with the plants.

Here's the writeyp from Symantec: http://www.symantec.com/connect/blogs/stuxnet-breakthrough



Back from the dead, I'm afraid.

Around the Network
mrstickball said:
Galaki said:
mrstickball said:
Galaki said:

Sometime, people forgot that not everything has to be connected to the interwebz.

Doesn't need to be.

The stuxnet attack against the nuclear facility in Iran was a hardwired intranet that had no external access points. They got in via an infected (from my understanding) USB key which was put into a local computer at the facility, which then infected the entire system and heavily damaged the facility.

Isn't that due to employee negligence? You don't just plug any usb into your mainframe...

I don't quite know if one could consider it employee negligence. From my understanding, it infected 16 million PCs in hopes to hop on any computer that would interact with the plants.

Here's the writeyp from Symantec: http://www.symantec.com/connect/blogs/stuxnet-breakthrough

The worm was from a usb from an employee.

That employee brought the worm in, be it unknowningly. It was the employee's responsibility to not be careless and use the same usb stick for important and home-uses (assuming).

Plus, shouldn't they have an autoscan system in place on anything plugging into their important systems?

IMO. It's multiple oversight that caused the spread.



Its about time.