The True Story: Two U.S. Nuclear Labs "Hacked"
December 8, 2007 5:49 PM
Two labs of America's top scientists have fallen for the oldest trick in the hackers' book
featured a blog yesterday on how the media frequently reports on so called "hacks" with little understanding of what happened, participating in a
irresponsible brand of journalism that borders on alarmism
. The problem is exacerbated in that people really do fall victim to Internet scams, even rather smart ones, which reporters dubiously dub "hacks."
One such report
that two nuclear labs had been "hacked." The true story is a bit more entertaining and the reveals that there is no threat to the country's nuclear safety. Real threats such as concerted "hacks"
conducted by the Chinese against the U.S. government
are certainly a concern, but the only thing dangerous about the compromise at these labs is the stupidity of a few scientists and workers at the plants.
The Oak Ridge National Laboratory (ORNL) in Tennessee and Los Alamos National Lab in New Mexico have made a habit of
collecting the social security numbers, names, and birth dates
of scientists who visit the plants. The information is put into a database, which reads like a who's who of America's top scientists.
Unfortunately, nobody thought such a practice might be a bit insecure. Starting October 29, workers at the labs began receiving phishing emails, which followed a traditional attack pattern of containing malicious Trojan-containing attachments.
There is no evidence that the attacks were specifically geared at the lab. If the attacks were just a general Internet attack, those responsible might have been excited at the big fish they caught. The two labs both have reported that the phishing emails gained access to their system, which indicates at least two employees -- one at each plant -- were foolish enough to click the attachment and commence the damage. The result was that the database with the scientists' information was compromised.
The phishers gained access to the records of all visitors at the plant between 1999 and 2004.
Don't blame the news networks solely for sensationalizing the attack and making it sound like a sophisticated assault. Leaders at the labs have gone on record trying to fudge the facts in statements, making the attacks sound more complex than they really are and icing over that the attacks only succeeded due to employee failures.
For example, ORNL director Thom Mason stated that the attacks were, "coordinated attempt to gain access to computer networks at numerous laboratories and other institutions across the country," and continued, "Because of the sensitive nature of this event, the laboratory will be unable for some period to discuss further details until we better understand the full nature of this attack."
Los Alamos has been more silent about what appears to prove the old adage that the greatest hole in security on the average computer network is the network's users.
In 2006 Los Alamos fell victim to social engineering and phishing when its emails were stolen and ended up on the USB stick of a drug dealer found in a police raid. The emails contained data of simulated nuclear weapons tests considered sensitive.
At the time executive director of the Project On Government Oversight (POGO), Danielle Brian blasted Los Alamos for their lax security stating, "This appears to be a new low, even drug dealers can get classified information out of Los Alamos."
Expect more pressure for ORNL and LANL as the smoke of sensationalism begins to blow away, revealing atrocious security due to user stupidity. Looks like some of America's top minds have just fallen for the one of the oldest tricks in the hackers' book.
"A politician stumbles over himself... Then they pick it out. They edit it. He runs the clip, and then he makes a funny face, and the whole audience has a Pavlovian response." -- Joe Scarborough on John Stewart over Jim Cramer
Hack The Planet
December 7, 2007, 1:52 PM
Unisys Blamed for China-Connected Homeland Security Hacks
September 26, 2007, 10:08 AM
Amazon Airborne Fulfillment Center – Your Merchandise Drop-Shipped from the Clouds
December 29, 2016, 5:00 AM
Amazon is experimenting with a new kind of grocery stores, Amazon Go
December 8, 2016, 5:00 AM
Google has developed Deep Learning Algorithm to detect Diabetic Eye Disease
December 4, 2016, 5:00 AM
Google plans ultra-fast wireless Internet for Research Triangle Park, N.C.
August 12, 2016, 6:30 AM
Twitter Senior VP: "Diversity is Important, But We Can’t Lower the Bar"
November 9, 2015, 9:59 AM
CNN Resorts to Internet Censorship to Promote Clinton Over Senator Sanders
October 15, 2015, 2:47 PM
Most Popular Articles
OPPO R9 – The Smartphone with Excellent Camera and Long Battery Life
January 12, 2017, 12:01 AM
Are you in the market for a private antenna?
January 11, 2017, 12:01 AM
Comparison: Xiaomi Mi Mix Vs. HTC U Ultra
January 14, 2017, 12:10 AM
Super Hi- Vision Will Amaze the World
January 16, 2017, 9:53 AM
Huawei P10 Smartphone – Coming this Spring
January 11, 2017, 12:01 AM
Latest Blog Posts
Jan 17, 2017, 12:16 AM
News of the Day
Jan 16, 2017, 12:10 PM
News and Technology Advancement
Jan 16, 2017, 7:58 AM
Jan 15, 2017, 12:32 AM
Here is Some News
Jan 14, 2017, 12:39 AM
News: Improved and New products
Jan 13, 2017, 12:01 AM
News around the world
Jan 12, 2017, 12:01 AM
Rumors and Announcements
Jan 11, 2017, 12:01 AM
This year CES and ridiculous gadgets
Jan 10, 2017, 12:01 AM
Nokia Android phone spurns the west.
Jan 9, 2017, 12:08 AM
New at CES 2017 - Changhong 8K Super Slim TV 65ZHQ3R
Jan 8, 2017, 1:07 AM
Debuted at CES 2017 - Vuzix Blade 3000 Smart Sunglasses
Jan 8, 2017, 12:39 AM
Some news of Day
Jan 7, 2017, 12:01 AM
News 2017 CES
Jan 6, 2017, 12:01 AM
Here is the Latest News in Tech
Jan 5, 2017, 1:47 AM
AI Beats World’s Best at Chinese board game “Go”
Jan 4, 2017, 11:21 AM
Las Vegas 2017 CES
Jan 3, 2017, 12:01 AM
News of Jan 2nd 2017
Jan 2, 2017, 4:40 AM
Wishing you all, the New Year brings the light of hope, joy, success, and Happy, Happy New Year.
Jan 1, 2017, 1:48 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information