http://www.businessinsider.com/the-7-deadliest-computer-hacks-known-to-mankind-2013-8
****

** **
The 7 Deadliest Computer Hacks Known To Mankind****

Geoffrey Ingersoll<http://www.businessinsider.com/author/geoffrey-ingersoll>
****

Aug. 8, 2013****

As long as companies and governments continue investing in cyber
militarization, there will be bigger, more catastrophic computer hacks.****

There is no bottom to the rabbit hole when it comes to potential exploits
in computer software, Professor Peter Ludlow, an Internet culture expert
and professor of philosophy at Northwestern University recently told
Business Insider.****

Time to dive into that rabbit hole and take a close look at the seven most
destructive, scary computer hacks that could come to be.****
The Industrial Hack****

More vulnerable than you might think. ****

The networks that control industrial systems — natural gas, water,
electricity, nuclear — are all incredibly
vulnerable<http://www.businessinsider.com/hackers-could-shut-down-the-us-2013-8>
.****

One can only imagine what it would be like if natural gas lines started
exploding, or high-voltage transformers started to blow — simply by
"spoofing" meters to give operators the wrong readings.****

The results would be catastrophic — one disaster expert told Business
Insider that long-term damage to these systems would make the fallout
from<http://www.businessinsider.com/cyber-attack-utilities-katrina-2013-5>Katrina
look light.
****

The Defense Science Board — a Pentagon think tank — concluded about
infrastructure 
hacks,<http://www.acq.osd.mil/dsb/reports/ResilientMilitarySystems.CyberThreat.pdf>"the
cyber threat is serious, with potential consequences similar in some
ways to the nuclear threat of the Cold War."****
The Market Hack****

Nobody wants to see this happen again.****

The so-called "flash crash" of 2010 was caused by a "computer
glitch<http://www.thedailybeast.com/newsweek/blogs/wealth-of-nations/2010/05/06/the-computer-glitch-felt-round-the-world.html>"
not a hack, but it shows devastating possibilities.****

With high frequency traders adding algorithms and increasingly complex
software to the market equation, there's a
need<http://online.wsj.com/article/SB10001424052748704709304576124502351634690.html>for
reciprocal cyber security.
****

CNBC recently covered a cyber crime
report<http://www.cnbc.com/id/100892575>that stated at least 53
percent of major trading hubs around the globe had
become targets of cyber criminals.****

>From CNBC:****

"Cybercrime also appears to be increasing in terms of sophistication and
complexity, widening the potential for infiltration and large-scale
damage," said the report, released Tuesday. It warned that a major attack
could result in widespread public mistrust and a retreat from the markets. *
***
Pacemaker Hack****

Late hacker Barnaby Jack exposed how a pacemaker could be hacked and
basically manipulated to kill the user. Jack exploits an unencrypted
wifi-like signal that doctors typically use to harvest information in order
to diagnose the state of the pacemaker.****

Pacemakers, as they are now, cannot be updated with new firmware without
another invasive surgery.****

>From 
>Forbes:<http://www.forbes.com/sites/singularity/2012/12/06/yes-you-can-hack-a-pacemaker-and-other-medical-devices-too/>
****

Implanted devices have been around for decades, but only in the last few
years have these devices become virtually accessible. While they allow for
doctors to collect valuable data, many of these devices were
distributed<http://www.theregister.co.uk/2011/10/27/fatal_insulin_pump_attack/>without
any type of encryption or defensive mechanisms in place.
****

Even scarier: Jack demonstrated how the malware used to hack pacemakers is
infectious<http://www.businessinsider.com/highly-contagious-malware-could-cause-mass-murder-by-hacking-pacemakers-to-send-deadly-jolt-2012-10>,
meaning everyone in range of the originally hacked pacemaker that is also
using one, also gets the malware, and also dies.****

Spooky.****
Ground Control Hack****

"Looks like I picked a bad day to quit encryption."****

There are three major problems with the air transit system in the U.S., and
all of them stem from the same thing: absolutely no encryption.****

First, aircraft can be hacked into directly ... and controlled:****

>From Escapist 
>Magazine:<http://www.escapistmagazine.com/news/view/123256-Hacker-Demonstrates-Android-Aircraft-Hijacking-App>
****

Pilots can counteract that attack by switching off autopilot, but the
greater problem is that many planes no longer have analog flight
instruments and are thus susceptible to other kinds of manipulation.
[Information Technology expert Hugo] Teso said he could control most
aircraft systems, put planes on collision courses and even give passengers
a fun and exciting surprise by forcing the oxygen masks to drop.****

Not quite done yet.****

Second, is that the ground control systems are also totally unencrypted and
unprotected. Third, is that the update to these systems (projected
completion date 2020) is equally unencrypted and unprotected.****

"The mere fact that someone could inject a fake air plan into the air
traffic control screens is pretty serious," Andrei Costin, an Information
Security specialist who gave a presentation at the Black Hat conference
earlier this month, told Airport
Technology<http://www.airport-technology.com/features/featureair-traffic-control-easy-target-hackers>.
"The main problem ... is the possibility to inject these fake messages or
to try to modify real messages sent by real planes as they're sent over the
air."****
Car Hack****

It's the same kind of exploit as the pacemaker hack, except inside a car.***
*

At the Black Hat conference in Vegas, hackers Charlie Miller and Chris
Valasek showed off how they could hack into the computer of a
car<http://www.businessinsider.com/defcon-harlie-iller-chris-valasek-hack-car-2013-7>and
control it's every function, from breaks to speed to air conditioning.
****

And it’s *any *car that has an Electronic Control Unit (an ECU, fancy for
internal computer), which is *every *car since sometime in the mid-90s.****

Mechanics — like cardiologists — typically use a connection from the ECU to
diagnose problems with the car.****

Turns out, that physical connection can also be used to control the car.****

(An earlier version of this story implied that the car could be remotely
controlled. That, so far, is not the case.)****

“Right now, there aren’t a lot of ways for hackers to remotely attack cars:
Bluetooth, wireless tire sensors, telematics units,” Miller told The New
York 
Times<http://bits.blogs.nytimes.com/2013/08/11/taking-over-cars-and-homes-remotely/>.
“But as cars get Internet connections, things will get easier for the
attacker.”****
The Weapons Hack****

Imagine nuclear weapons that didn't fire ... or that instead fired on
America's own cities?****

The Defense Science Board imagined just such an outcome, due in large part
to enemies hacking the military networks, or contractors installing
foreign-made circuit.****

>From the 
>report:<http://www.acq.osd.mil/dsb/reports/ResilientMilitarySystems.CyberThreat.pdf>
****

The benefits to an attacker using cyber exploits are* potentially
spectacular.* Should the United States find itself in a full-scale conflict
with a peer adversary, attacks would be expected to include denial of
service, data corruption, supply chain corruption, traitorous insiders,
kinetic and related non-kinetic attacks at all altitudes from underwater to
space. *U.S. guns, missiles, and bombs may not fire, or may be directed
against our own troops.*****

Nowadays all U.S. weaponry is on a network, and that network is like Swiss
cheese to new-age hackers (or so the DSB concluded).****

Their recommendation for America's nukes: invest in more off-the-grid
(under tons of water) nuclear subs, and, in the meantime, harden networks,
and make sure there aren't any foreign components in any of the circuitry
controlling nukes. ****
The Cryptopocalypse****

RSA <https://en.wikipedia.org/wiki/RSA_%28algorithm%29> and
Diffie-Hellman<https://en.wikipedia.org/wiki/Diffie-Hellman>are two
common encryption methods on the internet, and they make up the
vast majority of everyday encryption.****

Except there's one thing: hackers at Black Hat say there's a "small, but
definite chance" they'll be cracked within five years.****

The result of the crack would be “a total failure of trust on the
Internet,” Alex Stamos, chief technology officer of the online security
company Artemis <https://www.artemis.net/> told MIT Tech Review.****

>From MIT Tech Review:****

“The RSA protocol that is the foundation of security on the Internet is
likely to be broken in the very near future,” said Philippe Courtot, CEO of
security company Qualys <http://www.qualys.com/>, noting that while the
computer security industry was underpinned by just a handful of key
encryption schemes, “we are very slow at adapting them.”****

Another option, called elliptic curve
cryptography<https://en.wikipedia.org/wiki/Elliptic_curve_cryptography>or
ECC, is already in use in the Russian and American government.
****

Only problem, Russia holds the patents, and they're planning to share.****

“If the cryptopocalypse happens, those patents are not going to last,”
Stamos told MIT.****

Hopefully the damage isn't too much to overcome by then.****

** **


__._,_.___






__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to