Rendered at 11:26:22 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
CobaltFire 17 hours ago [-]
As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house:
Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly.
That said, the timing of the disclosure and the issue are rather concerning.
Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overseas locations where this would have ripple effects in the local economy. Guam specifically would cause catastrophic supply shortages, since DeCA probably supplies around 50% of the groceries on that island (that's a WAG based on my time there).
ericmay 16 hours ago [-]
Generally agree with your assessment, but in the case of Guam or other more remote installations if there were catastrophic issues we'd just airlift food in. Costly but certainly manageable.
Hawaii I'm not sure why that would be an issue unless the whole island was attacked or shut down. Even if the on-base shops were hacked you could just go shop at Wal-Mart or Costco or any number of other locations on the islands. If there was an extended issue then the commander could authorize meal stipends as they do for some units today and then you would just go buy food off-base. Ideal? No. Manageable? Very much.
nwatson 15 hours ago [-]
Did they airlift better supplies to a floating aircraft carrier somewhere in the northern Indian Ocean recently? No.
nwallin 13 hours ago [-]
Aircraft carriers are not particularly well suited to be supplied by cargo aircraft.
The largest cargo aircraft with the strengthened landing gear, arresting hook, and catapult attachment used to be the C-2 Greyhound. It had a range of approximately 1,500 miles with a 10,000 pound cargo. It was retired on July 28th, 2026. The C-2 has been replaced by the CMV-22B Osprey. It has a range of only 1,150 miles and a more limited cargo capacity of only 6,000 pounds. 6,000 pounds isn't nothing, but it's not a lot either.
There's not a lot of stuff within 1,150mi of the Arabian Sea. Your two options are one of the US bases in the southern Persian Gulf (Kuwait is too far) and Diego Garcia. Neither are ideal. In both cases you're doing a transfer out in the field.
On the other hand, the C-5 Galaxy can carry 120,000 pounds to a range of 4,800 miles. You can fill it with food in the continental US, fly to Hickam AFB in Hawaii, refuel, and fly the rest of the way to Guam. On the return leg, an unladen C-5 can fly directly to the 22nd Airlift Squadron's home base California without a layover.
The C-17B Globemaster is smaller than the C-5, although it's nearly as capable. With a 160,000 pound cargo, it has a range of 3,200 miles, (the C-17A has a shorter range) which is just short of the 3,800 miles to get from Hawaii to Guam. I don't know how much cargo it's capable of carrying 3,800 miles, but on the order of 100,000 pounds is a reasonable guess. It is also capable of an empty flight back to the US without a layover.
Mostly tensioned cables carrying hoses (liquids especially fuel being the highest volume / limiting factor), some palletized transfer over cables, and some helicopter lift (because the flight pads/decks are already sitting next to each other while everyone is waiting for fuel to finish).
RobotToaster 3 hours ago [-]
> It was retired on July 28th, 2026.
Why does it seem like the US always retires useful hardware and replaces it with less useful hardware?
The complete lack of frigates in the US navy is another example of this.
juvoly 3 hours ago [-]
Minesweepers?
tgsovlerkhgsel 10 hours ago [-]
The Osprey is air refuelable though, isn't it? Each flight is roughly one pound per person on board.
It's also roughly 2800 nautical miles from Kuwait to Diego Garcia, so regardless of where the carrier group is, it should be at most a ~6 day round trip at 20 knots for a supply ship from the closest of the two.
That assumes there is no way to airdrop watertight pallets of food (e.g. steel drums loaded with cans and MREs) into the water, then retrieve it with RHIBs or helicopters.
mlyle 5 hours ago [-]
Trying to do 4 Osprey flights per day, with refueling, for spartan resupply... is going to be tough. Sure, it's not impossible...
In such a situation I expect you'd have a lot of other stuff competing with food for that lift, too, like spare parts.
CobaltFire 13 hours ago [-]
Not really relevant but a fun anecdote:
I can't speak to how much cargo was on board, but I did a Hawai'i to Guam leg on a C-17B that was carrying palletized cargo.
One of my better Space-A experiences. Crew was great, flight was smooth. I preferred it over the KC-135 leg, despite the more spartan conditions. The aircrew let us toss out sleeping bags and packs in the aisles between cargo and get some sleep.
skhr0680 9 hours ago [-]
I thought it was well-known that unmodified C-130s (Look ma, no hook!) can land and take off from US-sized carriers successfully. Ergo, in a pinch, everyone will be getting their chicken nuggets and canned corn.
mlyle 5 hours ago [-]
When we had crews that had trained for it and recent operational experience with the capability, it was deemed not worth it.
Trying to stand it up in an emergency now is asking for trouble.
You'd have to be in a really dire situation to risk the carrier and aircraft this way.
psunavy03 5 hours ago [-]
No, in a pinch, you're just beclowning yourself with your utter ignorance of carrier air operations.
They're not striking the entire air wing below just so one C-130 can land and take off, and that's assuming a stunt pulled by one elite test pilot was replicable by a bog-standard junior C-130 pilot.
nkrisc 14 hours ago [-]
Surely airlifting supplies to a carrier in a war zone is not totally comparable to airlifting supplies to a base in a US territory?
ceejayoz 14 hours ago [-]
There was supposed to be a base there.
The Fifth Fleet base in Bahrain got flattened.
wongarsu 13 hours ago [-]
That explains why resupply doesn't work as well as in peace time
But at the same time, it's not like that came out of nowhere. If you attack a country, that country shooting back at any military installations in missile range has to be one of the expected outcomes. Given the US had all the initiative in starting the conflict I would have hoped there was a logistics plan that involved not relying on those bases to continue to exist
solid_fuel 13 hours ago [-]
> Given the US had all the initiative in starting the conflict I would have hoped there was a logistics plan that involved not relying on those bases to continue to exist
Have you seen the people responsible for planning right now? They're more concerned with posting AI generated memes on twitter and scoring bigotry points than managing a foreign conflict.
mulmen 13 hours ago [-]
> Given the US had all the initiative in starting the conflict I would have hoped there was a logistics plan that involved not relying on those bases to continue to exist.
Anyone with the capability to plan for the Iran war never would have started it because the costs would have been obvious. In other words the only way to start a war with Iran is to have no plan for it.
Terr_ 12 hours ago [-]
> Anyone with the capability to plan for the Iran war never would have started it
Not only that, but it was already that way for ~40 years, where past presidencies all knew and documented why it was a stupid idea, didn't press the stupidity-button, and mostly worked towards better options.
Gollapalli 12 hours ago [-]
Idk, current president and general staff seemed to be very against it as well. Foreign influence and realized threats of assasination seem to be a factor.
ceejayoz 12 hours ago [-]
> current president and general staff seemed to be very against it as well
Gosh, if only they could've stopped it!
> Foreign influence and realized threats of assasination seem to be a factor.
The only head of state assassinated in this conflict was Iran's.
estearum 12 hours ago [-]
Mega copium.
All Trump needs is a little dangling of glory and publicity and he'd oink like a pig if he thought it'd earn it. Pathetic creature.
Netanyahu tried the same schtick he's done for 30 years of POTUS's, just now we have someone retarded enough to fall for it and a party that allowed him to be surrounded by sycophants.
You should just admit you voted for a retard and pay your penance to your countrymen and species.
vkou 9 hours ago [-]
> If you attack a country, that country shooting back at any military installations in missile range has to be one of the expected outcomes.
Americans make war on other people, other people don't make war on Americans. It's one of the reasons why they are so eager to do so. 'The other guys might hit back' doesn't even register in the cultural psyche.
LtWorf 6 hours ago [-]
They hit back on 9/11 and it caused a panic that is still ongoing.
lostlogin 5 hours ago [-]
I'm no shill for the US, but that's a hot take that's too simplistic by far.
Eg who armed the Mujahideen?
LtWorf 4 hours ago [-]
The USA, to fight the democratically elected government of afghanistan.
wbl 12 hours ago [-]
You'll notice that the aircraft carrier continues sortie generation. What's causing us to lose is failure to achieve victory due to the means employed not the enemy constraining our freedom of action through force. Not to say it's great: it sucks to be on the ship for this, but if Hezbollah murdered 3,000 Americans the shortage wouldn't make the news amid our invading Iran.
ceejayoz 12 hours ago [-]
> You'll notice that the aircraft carrier continues sortie generation.
No, it doesn't. It's now in Thailand for R&R, then back to base in the US, because of this issue.
> What's causing us to lose is failure to achieve victory due to the means employed…
Right. We're being too restrained. That's some Vietnam War era cope you're huffing.
wbl 10 hours ago [-]
In the Vietnam war the US didn't win because it couldn't, no matter how much force was employed. Here same thing: we can't depose the Iranian government without a land invasion (which is too costly) and nothing else keeps them from having control of the strait.
lazyasciiart 9 hours ago [-]
> In the Vietnam war the US didn't win because it couldn't, no matter how much force was employed. Here same thing
Yes, that is the point everyone has been trying to make.
sofixa 1 hours ago [-]
Exactly, which makes this a stupid war to start in the first place.
Also, to be clear, a land invasion isn't "too costly". It's suicidal because we're talking about a massive country that has been preparing for decades, has a terrain advantage and literally more than a million fanatics ready to die for the regime. You'd need millions of soldiers deployed, and are looking at some Operation Downfall level expected losses.
lostlogin 5 hours ago [-]
> What's causing us to lose is failure to achieve victory due to the means employed
We can all agree on your opening.
fn-mote 12 hours ago [-]
> if Hezbollah murdered 3,000 Americans the shortage wouldn't make the news
??
What does this even mean? It seems to come out of nowhere. Is it a reference to some event??
lazyasciiart 9 hours ago [-]
It's roughly how many Americans died in September 11.
8 hours ago [-]
lostlogin 5 hours ago [-]
> war zone
But the US won and have and have a peace agreement. Several times.
psunavy03 5 hours ago [-]
You're just revealing your ignorance of Navy supply chains with this comment, and I say that as a veteran who has no support for the ongoing shitshow, only sympathy for my former colleagues trapped underway.
ericmay 14 hours ago [-]
[flagged]
scheme271 16 hours ago [-]
More to the point for Guam and similar locations, canned and non-perishable food can are probably around and more can be airlifted in to get people through it. It was pretty much the standard back in the day.
avs733 14 hours ago [-]
The diet in Guam is already heavily dependent on shelf stable foods. I know this from personal experience but theres a surprising (to me) amount of research on it as well (c.v., https://www.guampedia.com/health-consequences-of-modern-diet...). However, it is worth noting that food on a military installation =/= food nearby, for many obvious and non obsvious reasons.
CobaltFire 14 hours ago [-]
I didn't mean to imply that this would hit Hawai'i as hard as Guam, just that it would be one of the more effective places to hit with a DeCA supply chain attack.
0xWTF 13 hours ago [-]
Guam freezers and chillers were offline several times the years when I was there. You just didn't get milk, butter, eggs, ice cream, meat, etc those weeks.
CobaltFire 11 hours ago [-]
Can't recall them going offline island wide when I was there (given there are two on not quite opposite sides of the island). I do recall one having downtime when the other was up and having to deal with that.
jamiek88 11 hours ago [-]
When were you there?
cyanydeez 15 hours ago [-]
With the current admin, assumptions about capabilities are just wrong.
One of the reasons for consitency above all else is to use the power of history.
Ahistorical is now the defacto standard. All asdumptions about America power are toilet paper.
jarym 2 hours ago [-]
No expert but mechanical parts all built to the same specification and used in more or less the same manner can fail around the same time.
We see that in commercial aviation a lot which is why when there’s so much as 2 instances of a similar failure within a short timespan investigators start looking more closely at maintenance and manufacturing.
aa-jv 18 minutes ago [-]
>Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly.
These two states are indistinguishable from each other. A good hack looks like a poorly configured maintenance update, and vice versa.
nottorp 2 hours ago [-]
Would a hostile state actor with access to basically a command and control network inside military bases ruin the food or stay quiet and try to use it to gain access to more interesting systems?
wjnc 3 hours ago [-]
This points to either an inside job (a US gov agency that feels it needs to create urgency) or Iran (that has an urgent need to do something), since no serious adversary would use this capability in the absence of a theater.
wood_spirit 3 hours ago [-]
Or criminals (perhaps ransom not paid etc) or Kiddies for the lolz or US teen lashing out or any of the gazillion nationalist-aligned hackers who don’t like USA.
But a misconfiguration is even more likely.
Can’t think _why_ freezers need to be web connected and remotely managed in the first place. What benefits does that bring the commissary in normal operation?
pests 2 hours ago [-]
To try to guess at a plausible answer, any monitoring / remote management stemmed from wanting to keep an eye on temps over time. Freezers can go out of temp for only so long before its all bad.
Tada. It saves someone from making the rounds with a clipboard and writing down temps every X hours.
I agree its unneeded, just I can see the thought process.
segmondy 11 hours ago [-]
I always wonder by folks with some "inside" knowledge like you will then come out to share more details. Why? I understand that there's no security through obscurity, but I don't think that the details to get your point across matters. Loose lips sink ships.
CobaltFire 10 hours ago [-]
Nothing I shared is, in any way, even close to something I am concerned with sharing.
This type of wargaming scenario is literally stuff they give to brand new kids out of high school to get them thinking. It's not anything close to "loose lips sink ships."
munificent 10 hours ago [-]
We are a very social species who likely evolved to feel good when we share juicy information.
addag 6 hours ago [-]
In any cases, it is a strong evidence that the freezer can be remotely controlled globally, and this is in itself a source of concerns (what other electrical equipment can be controlled remotely, especially on such critical features?)
small_scombrus 3 hours ago [-]
> it is a strong evidence that the freezer can be remotely controlled globally
As per the article that's literally a selling feature
xaxbxcxdxe 6 hours ago [-]
[dead]
metaphor 10 hours ago [-]
[dead]
aaron695 14 hours ago [-]
[dead]
TZubiri 16 hours ago [-]
>Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly.
Are these materially different? Assuming that there wasn't a literal command to turn off all freezers, from an organizational, non criminal perspective, to the organization the damage will be the same, the root cause will be a bug (whether exploited by chance or malice), and the fix will be the same(fixing the bug).
gavinsyancey 15 hours ago [-]
> Are these materially different?
A hack implies an adversary, and intentional targeting.
TZubiri 11 hours ago [-]
But is it materially different? Or is it a difference in quantitative increase of likelihood of the exploit?
The thesis "everything hackable" will be hacked, and with the advent of hacking LLMs, the boundary between criminal hacking and civil hacking is being blurred, it's no longer attributable to a criminal intent, hacking commands are just something that happens through no criminal intent.
Practically, the hackers, whether human or syntehtic, are a catalyst, they accelerate the rate at which a bug that causes damage will manifest, and perhaps the magnitude of the manifestation, but the essence of the negative manifestation of that bug is the same. Whether it was triggered by a solar ray flipbit or by a rogue LLM or by a russian hacker, the essence of the issue is the same.
namenotrequired 7 hours ago [-]
Yes? “one of us made a mistake” vs “someone is attacking us” is a difference that people care about.
croon 5 hours ago [-]
Not only care about; a mistake is unlikely to be repeated, a motivated attack is very likely to be attempted again.
lostlogin 5 hours ago [-]
> a mistake is unlikely to be repeated
If it was a mistake, it happened at many facilities. That seems like a repeated mistake to me.
peterabbitcook 23 hours ago [-]
A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising.
I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on the thing (user/pass eg admin/admin was their usual). Anecdote: I once spent hours reading the docs and clicking around trying to get it to accept an SSL certificate signed by a real CA and it wouldn’t go, but it accepted one I self-signed in openssl.
In all fairness, the people who are experts in the field of Siemens PLC programming are usually mechanical-ish engineers and security is not in their skill set or on their mind.
katzenversteher 22 hours ago [-]
Most factories I know do not allow their PLC be accessed from the internet. They are usually on a separate Network. However, the "engineering" station (the computer running e.g. TIA Portal) sometimes is.
The PLC engineers I had contact with usually had an electrical engineering background. That's why they like PLCs in the first place with the ladder logic programming languages, grafcet and if they feel fancy a bit of structured text (assembly like) or structured control language (pascal like). They indeed did not know much about software security but a great deal about machine safety.
A real security nightmare are older OPC servers (OPC-DA) which is super reliant on DCOM. OPC is quite important to connect the PLCs to SCADA systems or 3rd party devices.
lowbloodsugar 16 hours ago [-]
>They are usually on a separate Network.
Then someone plugs in a cable because boss wants something "over there" and there's already a network that runs "over there". Or optimizes to a smart switch with vlans, and then someone else optimizes to a single vlan. It's not hard to not give a shit, or not understand, network security.
lenerdenator 16 hours ago [-]
That someone can be brought into an office and shown a small diagram of the approved network topology. Then they can be shown a small diagram of the current network topology. Next, they can be asked if they're the same. If they're not, they can finally be asked if they're aware that deviating from the approved network topology without consulting infosec is grounds for termination of their employment.
edoceo 15 hours ago [-]
Bunch of assumptions about operational excellence in there. Doesn't match my experience but, it does match my desire.
crote 14 hours ago [-]
You're assuming that it'll be noticed at all, and that the person noticing cares enough about it to make a big deal out of it - likely involving several layers of management.
In reality it'll likely first be noticed ten years down the line, by someone who lets out a big sigh, mutters something about "incompetent dipshits not updating documentation", and moves on with their day.
lenerdenator 8 hours ago [-]
I'm not assuming anything.
I'm saying that's what you do in order to solve the issue. You have to actually try, and you have to do actual engineering.
If the local planning commission submits a call for proposals for a bridge to cross a 400 foot chasm over sharp rocks, and they insist that it absolutely, positively must be made out of popsicle sticks, local civil engineering firms aren't going to take up the project, because that's insane.
Why do we give the management of these places a pass for PLC and SCADA systems that could give massive problems - up to and including the loss of human life - if they're hacked?
lowbloodsugar 11 hours ago [-]
We're talking about the military. Many years ago I heard a presentation by an IT guy in the marines. He stated that senior officers would regularly give him instructions that would violate some policy or other - such as giving their secure laptop direct access to the internet so they could check their personal email - as an order. That is, they could not refuse. I hope things have changed, but this fellow was dead serious at the time.
fireflash38 10 hours ago [-]
Report that shit to your security officer
sidewndr46 23 hours ago [-]
Isn't this the industry expectation in that kind of equipment? If it was signed by a real CA the cert. could expire and render the equipment unable to communicate.
peterabbitcook 21 hours ago [-]
That’s a tough question. If your PLC is on an airgapped LAN, admin/admin is not great security hygiene but you’ve reduced most of the risk by airgapping.
On my project the service I wrote was doing bidirectional communication with the PLC over OPCUA. The server running this pod was connected to the internet, so it was critical to have proper TLS for the OPCUA client/server. Rotating LetsEncrypt certs on the system every 45 days is a lot of toil, but using a self-signed cert that expires in 2040 from some dev laptop doesn’t pass muster in most organizations either.
That’s just the OPCUA path.. In these projects You also typically see WinCC HMIs that can talk to the PLC from anywhere on the network without TLS. And also SIMATIC Web Server pages - minimally secured by default, and the amount of info you can grok about the system in Chrome Dev Tools is troubling.
gopher_space 16 hours ago [-]
> admin/admin is not great security hygiene but you’ve reduced most of the risk by airgapping.
admin/admin is on a post-it stuck to the monitor because everyone we hire is perfectly capable of rooting a machine they have physical access to.
crote 14 hours ago [-]
[dead]
detourdog 13 hours ago [-]
Just my opinion but I believe a self-signed is more secure than Let’s encrypt. When a self-signed cert changes and no one in the org knows why that is alarming. Getting certificate error messages every month and half every numbs the org to the alarm.
sidewndr46 17 hours ago [-]
I'm not sure if you're speaking from personal experience, but most I've interacted with don't have to worry about the self-signed vs. LetsEncrypt debate. They just don't do it. Also there would be no way to do LetsEncrypt as the system is air gapped.
bragr 14 hours ago [-]
You can do DNS challenges for air gapped networks as long as the TXT records resolve publicly.
sidewndr46 14 hours ago [-]
So then you have a signed CSR right? How would you get the certificate onto the box?
dylan604 17 hours ago [-]
> Rotating LetsEncrypt certs on the system every 45 days is a lot of toil
What is unique about your system using LetsEncrypt that you can't automate certbot to handle this task as it was designed and intended to be done?
gmueckl 14 hours ago [-]
On an airgapped system that is is turned on once and needs to keep running for many, many years? Industrial equipment is a world of its own and internet best practices just don't transfer directly.
Some PLCs run extremely expensive machines. Some machines can't afford to have their control systems stutter or fail because that can lead to physical damage and production outages of enormous proportions. A PLC that stops communicating because a certificate just expired is absolutely not acceptable in some plants.
tgsovlerkhgsel 10 hours ago [-]
Running certbot on your web server is easy.
Running certbot on a random PLC isn't happening.
tgsovlerkhgsel 10 hours ago [-]
My guess would be something like the CA using some feature that was newer than what the equipment would support (e.g. ECC signatures but the equipment only supporting RSA), not an intentional "no real CAs" decision.
stephbook 22 hours ago [-]
also you can't pin the user/pw to the machine with a note, because someone might need remote access. better stick with admin/admin
jordanb 22 hours ago [-]
My mind was blown when I realized that the way tftp works is that as the machine is booting it asks the network if anyone has some software for it to run.
Joker_vD 17 hours ago [-]
Well, what else can it do, really? It has to boot with pretty much zero knowledge about the external world (maybe except asking the user for the current date and time). Sure, you can hardcode an outdated list of CAs (it's always outdated because the system can be booted 10/20/100 years after it was made) in but that just opens you to unexpected obsolescence, and you usually can't put too much stuff in the bootloader anyway.
Not really dissimilar from the human upbringing: leave a baby with "bad" guardians, and it will grow up corrupted. That's a feature, not a bug: if you knew what behaviour exactly you wanted (other than "whatever Simon says"), you would just bake it in in the first place, right?
Dylan16807 3 hours ago [-]
If we pretend we're revising TFTP boot in 1995, let's have it get up to 20 boot options from the server and their md5 hashes, and if it's not set to auto it waits for the user to pick one. It then verifies the hash as it downloads. Also it uses TCP for the download.
Joker_vD 27 minutes ago [-]
Nah, you won't sell the cow like that. You need to add more reliance on the public CA infrastructure and third-party code signing. Also, "ask user"? Ask the TPM instead — I mean, why would the computer's owner trust the computer's user, right?
17 hours ago [-]
lenerdenator 16 hours ago [-]
> In all fairness, the people who are experts in the field of Siemens PLC programming are usually mechanical-ish engineers and security is not in their skill set or on their mind.
Stuxnet was over a decade ago.
There should be a simple rule that everyone with the ability to understand things like PLCs should be able to grasp: your equipment does not touch the internet or external storage, period.
Those who can't grasp this concept should be shown the door with a recommendation that they find a less mentally-taxing line of work.
crote 14 hours ago [-]
The Stuxnet PLCs weren't touching either, though.
The worm was designed to jump across network air gaps via USB flash drives, and spread across isolated networks to other hosts. Finally, it targeted what was likely going to be a service technician laptop, which had to connect to the PLC via a data cable to update and adjust its configuration.
An attack like this can only be avoided if you never transfer any data from the outside to the inside. But that means you won't ever be able to install any form of software update or upload new config files without manually typing them in - or even reinstall the OS on any machine...
Prickle 10 hours ago [-]
Oh I wish that was possible.
Fact is if the customer wants to put their worksite management on AWS, you inevitably expose the OPC server and/or PLC to a Intranet. This is then inevitably connected to the internet in some way. The customer may or may not put barriers between them, but that's not up to us to decide.
This becomes especially a problem if they have multiple sites across a country or countries.
We have a customer that runs a factory on god forsaken WIFI, then dares to complain about a bad connection to said equipment. Thankfully, they have their own internal IT department.
bugbull 22 hours ago [-]
[dead]
0xWTF 12 hours ago [-]
This is eerily suggestive of a vulnerability Hank Paulson hinted at in his 2014 book "Dealing with China"
"Every nonelectric cooler comes with 25 years of free real-time monitoring. On a visit to the company in the spring of 2012, I watched as technicians in Broad Air’s space-age control room checked on the performance of its units in locations as diverse as the Adolfo Suárez Madrid–Barajas Airport in Spain; Qualcomm headquarters in San Diego, California; and Fort Stewart, the U.S. Army base in Georgia [emphasis added].
"Zhang says that 80 percent of his clients are repeaters. “If you bring long-term benefits for your clients, they will choose you.”"
Terr_ 10 hours ago [-]
America's tech-sector has a similar problem, which--until recently--was tempered by the idea that it was a dependable and predictable ally to most of its customers.
Not just in the sense of secretive kill-switches, but "US government commands you to turn over this encryption key and you're not allowed to say you did so" stuff.
vkou 9 hours ago [-]
> "US government commands you to turn over this encryption key and you're not allowed to say you did so"
That barely even registers given the scale of more modern escalations against its 'allies'. Escalations like "US government threatens that you aren't a real country and that you can't defend yourself from it."
codingdave 23 hours ago [-]
The author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems?
Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.
gwbas1c 22 hours ago [-]
They are charging down that path because vulnerabilities that effect the refrigerators were disclosed the same day as 14 refrigerators failed in an absurd way. They all turned on the defrost cycle and heated the food.
The problem is the author should have put a few concise bullet points at the top. (14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.)
I really recommend skimming the article to the end.
(Unfortunately, the article really is so verbose it's a borderline rant.)
wavemode 4 hours ago [-]
At the same time, I think some people in this comment section are underestimating the likelihood that this was a hack, because they're overestimating how sophisticated such a hack would have to be.
In my mind, if this was a hack, it was probably not a Stuxnet virus or something. These are smart fridges we're talking about - someone probably just logged into them using leaked credentials or a Web app vuln, and turned them off.
odyssey7 23 hours ago [-]
Obvious sabotage would be addressed promptly. Subtle sabotage could persist as a minor torment indefinitely.
pizzaiolo 23 hours ago [-]
Stuxnet was a good example of that.
19 hours ago [-]
ckdarby 23 hours ago [-]
The article has a post that says this happened across 14 bases at the same time.
ErroneousBosh 23 hours ago [-]
Then I would suspect that this is either down to the common control system, or there has been a batch failure of the controllers in the freezers that were presumably ordered and supplied at the same time.
I've seen batch failures in radio equipment where I could predict 100% accurately which devices would fail based on the range of serial numbers.
jvanderbot 23 hours ago [-]
So what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.
schiffern 23 hours ago [-]
OTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about.
Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late.
All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway.
Interesting times...
elictronic 15 hours ago [-]
The backbone of the US military is the logistics. It's why a US carrier being undersupplied was such a big deal. Making the US military look incompetent can very well be the goal.
Considering Iran is looking for any possible avenue to make the US look bad especially directly before an election with a president who cheerleads the military strongly while not actually putting the time or thought into what makes it strong.
This would be worth far more than the vulnerability itself to Iran right now. No real injuries causing escalation. Making a more capability adversary look foolish.
conorcleary 20 hours ago [-]
Not just that, the position to stick a thermometer into the food before serving was axed as DEI, and the position to clean the food prep surface areas of the kitchen is too beneath the warrior ethos. Buying above single ply is too expense and it's too heavy, so have fun with the ED (dual meaning).
madaxe_again 22 hours ago [-]
And how many shipboard stores have been affected? Hardly something they’re going to talk about, and a far stronger candidate for attack. This could be spillover.
jvanderbot 19 hours ago [-]
Oh that's interesting. what if the issues w/ toilet spillover were hacks? Hilarious.
larrysalibra 23 hours ago [-]
> I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.
according to the article, the denominator is ~235.
jvanderbot 21 hours ago [-]
If we limit ourselves to these, then that's a 0.5% known failure rate.
senordevnyc 19 hours ago [-]
6%
jvanderbot 16 hours ago [-]
Owning my failure and moving on.
More coffee next time.
alephnerd 23 hours ago [-]
There are a couple hundred US armed forces bases each with commissaries that would be managed by DeCA.
An attack like the author hypothesized would require a LOTL modus operandi, and doing so on 14 locations wouldn't justify completely blowing up an entire LOTL operation, because it exposes indicators, registers, and tradecraft that is then shared amongst all security vendors.
The way it's framed is clickbait at its worst with the added issue of limited security experience, but the same can be said of HN in general.
tgsovlerkhgsel 10 hours ago [-]
Or someone somehow got into one web interface (e.g. by popping a random workstation used to monitor all these sites) and clicked buttons.
Zigurd 14 hours ago [-]
First let's acknowledge that this could very easily be a misconfiguration issue.
But, I'd be a lot more inclined to that idea if it wasn't for how they failed: they started a defrost cycle that turned the freezers into heaters, spoiling the food quicker. And the failure happened overnight, delaying discovery of the problem.
It could be just a compounding of bad luck. But an attacker with access to the specs for the freezers might be aware of how long they would stay cold after being simply shut off.
edelbitter 11 hours ago [-]
I was thinking timezone update - because of course an internet-connected freezer needs updated zone info so one can configure defrost schedules without the benefit of UTC.
PeterStuer 4 hours ago [-]
Central unanswered question in the article on wich all the speculation rests: "If this were a cyberattack, why mess with freezers?"
And yes, remember you can explain everyting by adding enough dimensions to a game of chess. But in reality? Seems the upside is near zero while the dowside is sacrifising your access.
2 hours ago [-]
selfhoster1312 3 hours ago [-]
If we're actually talking about a hack, there's no particular reason to believe it was done by an APT who would like to retain access.
Maybe a kid just wanted to do it for fun? Maybe a smaller hacking group who would just like to make a statement against fascist/imperialist USA is happy to just cost them a few million dollars with a few network packets?
mark-r 11 hours ago [-]
Maybe the whole point of this was not to ruin some food, but to prove infiltration of a DoD network in a way that would leak broadly because it's not classified?
thomasjudge 12 hours ago [-]
I think it is worth mentioning that at least a couple of these bases are pretty critical from a natsec standpoint. Fort Huachuca is a big IT and secure communications installation (United States Army Network Enterprise Technology Command, the United States Army Intelligence Center, Intelligence and Electronic Warfare Directorate); F.E. Warren AFB is one of the three AFBs that operate the strategic nuclear ICBM fleet. Not saying that any classified systems were potentially hacked/at risk in this situation
ungreased0675 6 hours ago [-]
The timing of the event at 2AM suggests something nefarious rather than an accident. That’s when it would be least likely to be noticed, but the temperatures would be high long enough to spoil all the food.
avs733 5 hours ago [-]
That’s also when (poor) logic would dictate you should push a software update.
meliz242 15 hours ago [-]
Howdy y’all, author here. Just discovered this thread after wondering why Hacker News was a linked views source to my silly little freezergate braindump.
Wanted to offer a few clarifications:
I’m not a cybersecurity expert; I’m an investigator (in a totally different field), and this was essentially me following a weird thought to see where it went. My background is in natsec so that’s where my mind goes. There have since been at least dozens of additional freezer outages reported in a similar pattern, but I'm refraining from calling/tracking down every individual weirdness based on a Facebook comment at this point since there are much larger outlets with journalists more proficient than I covering this by now. Another interesting thing - There are numerous freezers and fridges within base stores, not under the control of DeCA/DoD, and none of those appear to be impacted.
I completely agree that a bad update/configuration or other shared technical failure may be the much more boring answer. The interesting part to me is that potentially hundreds of varying systems can converge upstream into common monitoring/control infrastructure. Anyone on this forum probably understands that, however IoT was something that was a relatively new concept when I was in school, and my degrees were somewhat relevant. The average person is blissfully unaware how expansive (and how much work behind safeguarding) the IoT is.
Also, since it came up: Yup. Human written. I’m pretty firmly anti-AI as a writer and also just, like, societally. I'll be sure to add some sort of footnote detailing my ai usage at the bottom of future public facing work, because I too detest reading (or questioning if what I'm reading is) slop. Minimal LLM used for understanding technical concepts and what the fuck fridge norms are…The weird formatting, excessive bolding, neurotic parentheticals, and rant energy are, unfortunately, totally my own. Sorry guys.
This was my first ever public post and intended audience was ~ 10 friends forced to read my diatribe, not thousands of strangers very validly raising questions I am not smart enough to answer myself. Appreciate the discussion and will be further educating myself on some of the points a few of you have brought up.
jesse_dot_id 5 hours ago [-]
Impressive article. I read most of it without skimming and that is high praise from this AuDHD nerd.
It's definitely suspicious. My money is on inside job — perhaps someone not fond of the current administration's handling of things. In my experience, these types of vulnerabilities are well-known and kept in the back pocket of engineers that have a lot of experience maintaining the equipment. Everywhere I've worked has been deeply vulnerable in some way, all of the engineers knew it, and often joked about it or were counting the days to getting pwned because companies never like to spend money to address the issue. I'm sure the military is no different. Probably worse.
jcurbo 15 hours ago [-]
Hi, I'm the poster. Sorry for the unexpected attention! I saw this on Bluesky and thought it was interesting enough to share here. If anything the style of your writing makes it stand out in a good way, we shouldn't always have polished/corporate-speak posts here.
meliz242 14 hours ago [-]
No apologies please, I'm flattered! I figured I should put the substack I made months ago to use and start putting some of my thoughts to paper (/keyboard) when it comes to my hyperfixation-of-the-week, instead of continuing to subject my friends to these rants. It's been an interesting few days.
simonw 12 hours ago [-]
I thought this was excellent. It pulled together a whole bunch of interesting evidence, was very careful not to make claims that weren't supported by that evidence, and every time I had a question it answered my question in the next paragraph. Hope you publish more!
tgsovlerkhgsel 10 hours ago [-]
Even if it isn't an attack, you demonstrated how it could be one. The vulnerability is likely there and worth mitigating. Excellent investigation and write-up!
bjackman 14 hours ago [-]
I came to these comments coz I was curious about the AI usage here, and FWIW I also thought it smelled AI written, but I didn't think it was slop. (IMO not all AI output is slop and not all slop comes from AI).
My main question was "did Claude do the investigation by itself or just write up the article from someone's notes?"
Also though, I'm quite willing to believe this is human written and the human just happens to have a Claudey style. The actual prose isn't that Claudey it's just the structure of how it presents ideas. But, Claude had to get that structure from somewhere. It's not that surprising to see people with that style of communication.
meliz242 14 hours ago [-]
Nope, I'm one of those lucky folks who was privileged enough to be accused of writing in a weird and probably too mature for my high school English paper-way before the advent of gpt, lol. I've had to all but remove the em-dash from my vernacular, thanks to the ~ plague of inauthenticity ~ as I call it.
I did all the digging, researching, writing, etc myself. The reason the screenshots are from mobile is because I wrote a lot of it literally in my notes app, on my phone before I started putting together more dots. I eventually asked gpt if I was correct in my understanding about refrigeration controllers doing XYZ and if it was plausible for them to be hacked in this way, when looking for some docs I asked if it would be standard to have XYZ part of a contract public and XYZ private, and other singular questions like that. I also use a browser extension for spellcheck that (I think) uses AI to suggest phrasing improvements, which I used pretty nominally.
Is there any type of sidebar/footnote that you, as a reader, would like to see to denote AI usage during the writing and/or research process? Would you expect none? I don't plan to do many investigations such as this (literally started because I was personally impacted) but I do have a few potential article seeds about defense procurement tech I've asked a few definition/research questions to AI about and would like to make sure I'm keeping tabs on it since this is something I want to be perhaps hyper aware of moving forward. Keeping in mind this is my personal substack and I would like to maintain integrity, but also, not doing really any groundbreaking work here. Intended to be an outlet for my thoughts, not news.
bjackman 10 hours ago [-]
> Is there any type of sidebar/footnote that you, as a reader, would like to see to denote AI usage during the writing and/or research process?
It's not something I expect, but I definitely don't see an issue with people putting a couple of sentences in an "expand to see AI usage notes" tab at the top or bottom of the page.
> Would you expect none?
As in, would I expect no AI usage? Coz no I absolutely expect people to use AI.
If you had got Claude to do this investigation for you then actually I think that would have been notable enough to include details of your AI workflow. But not because "it's cheating not to disclose it", rather because you'd probably have come up with quite a neat workflow that is interesting in its own right.
gwbas1c 22 hours ago [-]
To summarize for people who TLDR: 14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.
Regardless if this was a hack or a bug, the bigger lesson is that overcomplicated systems fail in catastrophic ways. Why do military commissaries need remote-controlled freezers? It seems like a very fragile, and needless, way to run a freezer.
---
But, there are some options that the author didn't consider:
1: This could be a quickly applied patch that failed.
2: This could be a "script kiddie" hack from someone who isn't a government actor.
I'm less onboard with a state actor. Generally, when a state actor has hacked something, they don't want the victim to know. In this case, if it was a state actor, I would anticipate that they would make a single freezer fail in a way that they could verify using something like a hacked video camera or otherwise by watching public social media feeds. IMO: A state actor would only "make sense" if they knew the hole was closing soon and they don't care if they're discovered, perhaps because their operation is winding down.
phil21 10 hours ago [-]
Could also just be a bunch of IoT devices running on synchronized time source that have what amounts to a defrost cronjob. And a latent bug that due to everything being synced and on the same schedule failed in the same manner (eg crashed the controller immediately after turning the heating element on and either didn’t boot back up or booted and some shitty programming forgot to check the heating element status). Saving state across boots or having a race condition of some sort like this gets my vote - since it’s a pretty common failure mode junior programmers are susceptible to.
I’ve seen similar too many times in my career - synchronized clocks are great until someone deploys a cronjob that fires at exactly the same time across the fleet and it breaks a certain OS or firmware revision. Which then exposes another bug that exists globally.
I definitely still subscribe to don’t attribute to malice what you can attribute to incompetence mindset.
Certainly all speculation though, real root cause will be interesting if it ever becomes public.
elictronic 14 hours ago [-]
Iran is actively looking for ways to attack back against the United States especially against military targets without actually escalating the situation.
I'm sure some script kiddie broke into a government network, hacked an industrial process, and forced a limited supply piece of equipment into a failure mode that takes some thought and is more unique as an attack vector. It's just like buying hacks for CS source right?
stackghost 17 hours ago [-]
>Generally, when a state actor has hacked something, they don't want the victim to know
Could be the Iranians, or someone aligned, conducting anti-morale operations. Could be the start of a series of small but annoying failures.
TeMPOraL 17 hours ago [-]
Or could be a rouge LLM in one of the big labs, that accidentally self-prompt-injected itself with the title of that vulnerability research paper.
stackghost 16 hours ago [-]
I suppose.
But if I was an Iranian operative with instructions to damage the morale of the American war machine, I'd absolutely do a series of things like this.
It doesn't really harm anyone, but enough similar events and the families of servicemembers start to feel unsafe, which is psychologically very different than the servicemembers themselves feeling unsafe.
It's probably more benign than that, most likely firmware or a central controller failure, but still
protocolture 5 hours ago [-]
Why would an LLM wear makeup?
quickthrowman 19 hours ago [-]
These aren’t your typical refrigerator or freezer, these facilities have walk-ins or purpose built cold storage with multiple evaporators and condensing units. A building automation system is pretty standard for most buildings above a certain size, and monitoring and controlling the refrigeration is usually a part of it.
Unfortunately, I would wager that all BAS software is full of flaws and holes, allowing access to it for the public internet seems like a bad idea. I need to be on my company VPN to access our locally hosted BAS front end (which I have authorized access for) which seems like the bare minimum security.
wormius 14 hours ago [-]
Probably not, but my closest bet would fall to Hanlon's razor:
I was curious if this was continued evidence of poor appropriations and upkeep or what... I do see "U.S. military commissary refrigeration maintenance, equipment replacement, and physical infrastructure are funded through the 5% commissary surcharge paid by customers at checkout rather than direct congressional appropriations."
So, perhaps the first place would be to follow the money - are these being repaired at the proper rate? Is this repair outsourced to third party vendors? (my guess). Is this gonna end up being the McDonald's Ice Cream machine all over again?
Really though, Hanlon's would be much easier to believe this is yet further ineptitude by those who run things (I am not going to claim malfeasance/malevolence, except a general sense of such across the board by this admin).
Since I'm not on the inside, anything I have to say would be speculative, just like the above, or the author themselves (I have no idea who it is, and perhaps they have a better beat on the ground with regards to this), but it just falls in line with "we're running out of missiles" and "sailors attempting to kill themselves".
We're so insistent on being #1, we can't admit we're in a society that is falling apart (and again, it may be the case that this IS a hack, but if I were to place my bets...)
Ineptitude, lowest cost players, etc "efficiency" indeed. You get what you pay for, and I guess 5% don't pay for a whole hell of a lot these days.
HardwareLust 17 hours ago [-]
My only question is, why would all refrigeration be under the remote control of DECA? That seems unnecessarily complicated.
Lt_Riza_Hawkeye 15 hours ago [-]
The article posits that they may just have centralized monitoring, not control. Since this didn't affect every location, I would assume it was a shared default password or something
deathanatos 7 hours ago [-]
> The article posits that they may just have centralized monitoring, not control.
… the article does posit this … nonsensically. TFA also establishes that "RMCS" stands for "Remote monitoring and control system". I would think the "and control" portion of the acronym would indicate that it is centralized monitoring … and control.
jpitz 16 hours ago [-]
This _IS_ the U.S. Government.
quickthrowman 16 hours ago [-]
Because they’re prefabbed walk-in coolers or freezers (at minimum, they could be purpose built cold storage warehouses) with multiple condensers, evaporators, pumps, temperature sensors, and humidity sensors. The refrigeration equipment needs some sort of control system and direct digital control is the usual way to do that these days.
This is food storage for a commissary, aka a store. They don’t use residential refrigerators.
fg137 15 hours ago [-]
Do regular grocery stores use a similar system? Or are locally controlled, simpler systems?
picofarad 7 hours ago [-]
I've noticed stores going to central coolant lines going to cold cases more and more lately. Its all still industrial control. Ideally.
addag 6 hours ago [-]
Until recently, I would have Occam's razor'd this and thought of a misconfiguration error from the military.
Now, considering how the OpenAI/HF hack emerged out of nowhere, it might be possible that groups of AI agents might have done this even without any close human supervision.
ggm 23 hours ago [-]
Single source systems provider and integrator and a doom date?
Could be a hack or a design flaw. I await the root cause analysis.
tyingq 23 hours ago [-]
This would be a bigger deal for the commissary locations outside the US, though I see none are on the list. Many of the very junior enlisted make very little money (~2400USD/month), and the low pricing at the commissary helps quite a lot. In the US, you would typically have some affordable off-base options. Overseas, it depends. Many of the locations are remote, or in places where the local groceries are significantly more expensive.
BobBagwill 23 hours ago [-]
I would suspect a firmware bug. Or a "Service Required" timer that was ignored.
jmuguy 22 hours ago [-]
Yeah I don't know why "hack" is more obvious than this. Central control pushes an update, it bugs out and cooks a dozen commissaries' frozen foods. Smart hack would be to do this randomly and fly under the radar.
elictronic 14 hours ago [-]
If you are a country currently in a weird war like situation looking for ways to make your opponent look foolish without escalating militarily, this seems like an amazing avenue.
I'm guessing Iran will claim it as an attack even if it doesn't end up being them in the end.
kotaKat 23 hours ago [-]
I'm in the firmware bug camp too. Over/under on "the remote management server went down and a bug on all the freezers decided to put them back into some form of local control where its first action was to do a defrost cycle then put it back into offline service"?
cduzz 22 hours ago [-]
Sure, that's possible?
It's also possible that, because the US is busy bombing Iran, Iran may be busy attacking the US infrastructure in any way possible? The US is also in a tepid war with russia, last I checked.
Some "cyber" crew getting a shell on an outsourced service provider and running a "defrost" command is also a totally explanation for this situation. It's also totally possible that some crew has mapped out a list of PLC entry points for various orgs and has them in a spreadsheet of "if we find a vulnerability, we should X this Y with this prestaged script that our intern / LMM cooked up last year to defrost these freezers"
reedf1 5 hours ago [-]
AI or not - can we agree to stop doing this now that AI has ruined it:
"But the thing I can’t get past is Fort Huachuca’s failure mode.
Not: the freezer compressor died.
Not: the power went out.
Not even: the refrigeration system stopped cooling.
Every freezer went into active defrost."
fg137 15 hours ago [-]
That's... a lot of words to say "freezers are down", with very little actual substance.
elictronic 14 hours ago [-]
Freezer's went into defrost melting all the frozen food and ice. If they just go down you have days to weeks to respond before everything unfreezes just based on the thermal mass and size of the freezer.
This is a much bigger deal than the freezer being down.
homeonthemtn 23 hours ago [-]
Very interesting article, very neurotically written. Definitely got grating by the end.
CarVac 23 hours ago [-]
The bold text use make me think it was largely LLM-written. Maybe even LLM-researched.
homeonthemtn 18 hours ago [-]
I was getting hints of that as well.
Hovertruck 16 hours ago [-]
Weirdly I felt like it got more LLM-y the further I got in. Then I hit the part with:
But the thing I can’t get past is Fort Huachuca’s failure mode.
Not: the freezer compressor died.
Not: the power went out.
Not even: the refrigeration system stopped cooling.
Every freezer went into active defrost.
mnicky 15 hours ago [-]
Well, definitely some LLM use :) At least in the second half... Confirmed with Pangram detector as well, which has pretty good precision.
meliz242 13 hours ago [-]
Hey, author here!
No LLM use while writing, except for my grammar/phrasing plugin which I think (?) uses AI. I detailed my explicit usage cases for gpt in an earlier comment above.
Is there anything you, as a skeptical reader, would like to disclaimed/posted/footnoted when it comes to disclosing gpt usage during research questions, etc?
Wasn’t planning to have to address this early on but I would love to moving forward, especially time listener, first time caller to the online writing publication world, especially in the era of rampant AI usage.
(Keeping in mind that this is my personal substack meant to be an anthology series of my thoughts and rabbit-holed interest write ups, not exactly intended for such wide scrutiny but, I guess, could be potentially disseminated widely in a rare instance such as this first post, lol)
waste_monk 6 hours ago [-]
>Confirmed with Pangram detector as well, which has pretty good precision.
Please don't say confirmed. AI detectors are not reliable in any way.
homeonthemtn 16 hours ago [-]
Yep! Same point for me too. Just a little too Claude-y
VCFundedGenYer 21 hours ago [-]
"To be very clear: I do not have evidence that the Defense Commissary Agency was hacked."
Should be much closer to the top of the article. Otherwise this is just weird and potentially dangerously wrong research.
senordevnyc 19 hours ago [-]
Can you spell out the danger this blog post represents?
snapcaster 16 hours ago [-]
what's with the pearl clutching?
0xbadcafebee 8 hours ago [-]
Never attribute to malice what can be explained by "military intelligence". If they're all controlled by remote monitoring from one location, then an engineer can run a loop to change a setting, and it can turn on the wrong setting.
There doesn't seem to be anything indicating an advanced attack. If you're a foreign adversary and you want to flex your muscles (in a way that would be a borderline act of war), you don't just flip one switch and giggle about spoiled food.
boesboes 23 hours ago [-]
Welcome to the internet of shitty unsupported and insecure crap!
Are we really this dumb as a society?
wlesieutre 23 hours ago [-]
As the saying goes, the S in IoT stands for security
Not exactly strong evidence presented here, but it wouldn't be a surprise either
m463 16 hours ago [-]
What's funny is that trump of all people is banning a lot of crap like this - internet connected chinese cars, internet connected solar panels, and other utility stuff.
But I fear the vested/wealthy interests involved in iot data mining, advertising, "relationship management" and plain "we own this"...
It (probably) prevents a comprehensive law supporting common sense.
DarmokTanagra 23 hours ago [-]
How many people do you know that have always on microphones in their home so that they buy things from amazon or google trivia answers?
voidUpdate 23 hours ago [-]
Yes
tialaramex 23 hours ago [-]
And at some point in hindsight it will be obvious what fractions of problems were
A. This technology is inherently crap, that's our fault
B. A bored teenager broke it. Bored teenagers are a thing, it literally doesn't matter which country they are in, stop building things bored teenagers will blow up, this is also inherently our fault
C. Foreign Adversaries
It suits both mass media audience figures and a narrative of wily enemies rather than incompetence to pin everything on C and it seems eminently possible that a country with as many enemies as the US would attract this sometimes, but the reality is that both A and B are much more likely despite being embarrassing.
nom 23 hours ago [-]
it's not AI generated so it must be true
b112 3 hours ago [-]
This is the dumbest thing I've ever heard of. The only reason I can conceive to really need network connectivity is to monitor temp, and there's zero reason to have that hooked into power, on/off, whatever.
Having remote on/off capability, or even the ability to set temperatures for freezers remotely is just so insanely idiotic, I don't get it. Why even have the path? If the temp is wrong, go investigate.
This is such a colossal non-problem. The risk is now, at the start of a war action base supplies could be made unusable.
One of the big current risk scenarios is, all smart cars, all meat packing plants, all industrial capacity, all phones, all internet, all interrupted at precisely the same time. A multi-pronged hack, right at the start of the war.
Imagine all electric cars bursting it flames in garages as they charge overnight. Conjoined with all cell phones, network connectivity, and landlines going out. And 911 call centres.
So now you have a fire raging, the fire department doesn't even know, and if it wanted to respond? There's 4 fires on every suburban block.
Within a few hours, a large portion of the populous now has no housing.
That's just from two simple hacks, communication and electric cars.
The society of always-on-connected is just dumb, stupid, insane, and has threat-results worse than some nuclear exchange scenarios.
And there will never, ever, ever be secure software. Ever. Never going to happen, ever. No rust, no this or that, no AI help, will ever, ever, ever secure software. Ever.
And how do I know this?
Because 50 years later, I've seen software just as buggy, insecure, as it always has. Anyone thinking "oh, we can just do this thing! And then software will be safe" is a loon, it'll never ever happen.
And that means?
Nothing important should ever be network connected, ever.
So why would any yahoo think remote control capacity on a freezer is sane?
the_real_cher 22 hours ago [-]
Would be hilarious if this was a runaway AI that someone was using to control their own IoT fridge.
> "I'm sorry I'm familiar with that function. Let me research enabling defrost for you."
TeMPOraL 17 hours ago [-]
The vulnerability research paper article mentions has a title that I could imagine an LLM take as an instruction - or a challenge.
fzeroracer 23 hours ago [-]
There's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers.
We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people who were in charge of operational control for stuff like freezers across military bases.
voidUpdate 23 hours ago [-]
I would agree, but the freezers going into high heat defrost mode seems like an intentional action from someone, whether that be incompetence or malice on the side of DeCA, or malice from a third party. If they got rid of the people commanding the freezers what to do, I feel like they'd just stay on whatever mode they were already on, rather than suddenly command all the freezers to defrost
ssl-3 16 hours ago [-]
Defrosting is very often automatic. That can involve mechanical timers, or software timers, or logic/code of any complexity. All of these things can be badly-implemented and/or become broken or stuck.
Maybe the mode they got stuck on was defrost.
if n>100 then defrost until y=3
If n is found to be greater than 100 and y subsequently never comes 'round to be 3, then defrost starts and runs forever.
kjs3 23 hours ago [-]
To be fair, if you want to mess with your adversaries troop morale, screwing up dinner is pretty effective.
astura 23 hours ago [-]
These are commissary fridges, not galley fridges.
schiffern 22 hours ago [-]
Still troops, still dinner?
ssl-3 16 hours ago [-]
Often more like a tax-free cost-plus-5% grocery store that sells some of everything (including cat food), but yeah: Still troops, and some of that stuff might become dinner.
schiffern 16 hours ago [-]
Fair points.
"some of that stuff might become dinner" is splitting hairs, I feel.
Why? Because disruptions along the supply line are disruptions along the supply line. If a deep Russian ammo depot had a sudden smoking accident, you would (rightly) think it absurd for a Russian mil-blogger to quip that "technically we didn't lose ammo, the fuses are put in right before firing, we lost stuff that might become ammo." Seems less convincing now, right?
Maybe tonight's meal isn't disrupted, but the weekly meal planning is certainly disrupted. I hate to say it, but if the intent was an opportunistic hit to troop morale before a CVE got burned anyway, I'd say mission accomplished. :(
If this does turn out to be an attack, it's from decades of higher-ups ignoring cybersecurity coming home to roost.
Jtsummers 14 hours ago [-]
> Maybe tonight's meal isn't disrupted, but the weekly meal planning is certainly disrupted.
This appears to be happening stateside, and most, if not all, of the listed bases have nearby grocery stores (I'm saying most based on the ones I recognize and know where they are, I didn't look up the rest). This is an annoyance, not a massive disruption.
Honestly, it probably creates more disruption for the retirees in the areas around the bases than it does the local active duty members.
ssl-3 14 hours ago [-]
I'm not splitting hairs. I'm just tryin' to talk about the commissary's role. :)
I agree that it is an important role that would be worthy of disruption for a motivated attacker.
But also: These things aren't usually at the center of vast food deserts. There's typically other ways to find some grub, like the Wal-Mart right over there.
kjs3 14 hours ago [-]
Sorry, forgot '/its-a-joke-not-a-legal-filing'.
Kichererbsen 23 hours ago [-]
General Stupidity should probably be demoted for this.
avs733 4 hours ago [-]
A quick check says this contract has been in place since 2020.
The internet security practices I experienced when working with the DOD in a prior life were…interesting?
Outside of the classified realm, there seemed to be little to no on the ground understanding of the Internet. Many things where internet connected that shouldn’t be or weren’t that should. I was involved in one contract where we had to demonstrate the ability to remotely access and control a system (to satisfy the system’s owner) as well as demonstrate that the system could not be remotely accessed via the internet (to satisfy the base IT folks). The solution was a hotspot kept in a lock box…that I doubt was ever locked after we left because it was constantly attached to our internal monitoring network despite our pleas.
odyssey7 23 hours ago [-]
This is exactly the sort of thing that a saboteur would want its targets to think.
“If sovereign and subject are in accord, put division between them.” —Sun Tzu, The Art of War
fzeroracer 23 hours ago [-]
That's the exact sort of thing the military would want us to think, because 'we were hacked by another nation' sounds a lot better than 'we fired the people responsible for food logistics'. You're not going to be able to divine the real reason this way.
odyssey7 23 hours ago [-]
There would be far better excuses here than saying “we’re incompetent.”
566788899999 23 hours ago [-]
[dead]
1284725 23 hours ago [-]
Gilfoyle was here. Everything that has been mocked in the Silicon Valley Show has either already happened or will happen.
AppAttestationz 23 hours ago [-]
I'm waiting for the OpenAI report that their agents defrosted everything.
ForHackernews 18 hours ago [-]
Oops, you're absolutely right to call me out for that. Starting the defrost cycle without emptying the freezer first COULD lead to spoilage. The load-bearing temperature is 0 degrees Celsius — above that point, and frozen food starts to go bad.
stephbook 22 hours ago [-]
It'll take them two weeks and then they'll find the systems were hacked half a year ago and they had industrial robots write messages on a literal chalkboard in order to share progress.
Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly.
That said, the timing of the disclosure and the issue are rather concerning.
Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overseas locations where this would have ripple effects in the local economy. Guam specifically would cause catastrophic supply shortages, since DeCA probably supplies around 50% of the groceries on that island (that's a WAG based on my time there).
Hawaii I'm not sure why that would be an issue unless the whole island was attacked or shut down. Even if the on-base shops were hacked you could just go shop at Wal-Mart or Costco or any number of other locations on the islands. If there was an extended issue then the commander could authorize meal stipends as they do for some units today and then you would just go buy food off-base. Ideal? No. Manageable? Very much.
The largest cargo aircraft with the strengthened landing gear, arresting hook, and catapult attachment used to be the C-2 Greyhound. It had a range of approximately 1,500 miles with a 10,000 pound cargo. It was retired on July 28th, 2026. The C-2 has been replaced by the CMV-22B Osprey. It has a range of only 1,150 miles and a more limited cargo capacity of only 6,000 pounds. 6,000 pounds isn't nothing, but it's not a lot either.
There's not a lot of stuff within 1,150mi of the Arabian Sea. Your two options are one of the US bases in the southern Persian Gulf (Kuwait is too far) and Diego Garcia. Neither are ideal. In both cases you're doing a transfer out in the field.
On the other hand, the C-5 Galaxy can carry 120,000 pounds to a range of 4,800 miles. You can fill it with food in the continental US, fly to Hickam AFB in Hawaii, refuel, and fly the rest of the way to Guam. On the return leg, an unladen C-5 can fly directly to the 22nd Airlift Squadron's home base California without a layover.
The C-17B Globemaster is smaller than the C-5, although it's nearly as capable. With a 160,000 pound cargo, it has a range of 3,200 miles, (the C-17A has a shorter range) which is just short of the 3,800 miles to get from Hawaii to Guam. I don't know how much cargo it's capable of carrying 3,800 miles, but on the order of 100,000 pounds is a reasonable guess. It is also capable of an empty flight back to the US without a layover.
It's been the basis for at-sea supply of long-endurance ships since ~1910 when refueling oil became a key blue sea naval requirement.
Modern example: https://m.youtube.com/shorts/kzncvGBj-88
Mostly tensioned cables carrying hoses (liquids especially fuel being the highest volume / limiting factor), some palletized transfer over cables, and some helicopter lift (because the flight pads/decks are already sitting next to each other while everyone is waiting for fuel to finish).
Why does it seem like the US always retires useful hardware and replaces it with less useful hardware?
The complete lack of frigates in the US navy is another example of this.
It's also roughly 2800 nautical miles from Kuwait to Diego Garcia, so regardless of where the carrier group is, it should be at most a ~6 day round trip at 20 knots for a supply ship from the closest of the two.
That assumes there is no way to airdrop watertight pallets of food (e.g. steel drums loaded with cans and MREs) into the water, then retrieve it with RHIBs or helicopters.
In such a situation I expect you'd have a lot of other stuff competing with food for that lift, too, like spare parts.
I can't speak to how much cargo was on board, but I did a Hawai'i to Guam leg on a C-17B that was carrying palletized cargo.
One of my better Space-A experiences. Crew was great, flight was smooth. I preferred it over the KC-135 leg, despite the more spartan conditions. The aircrew let us toss out sleeping bags and packs in the aisles between cargo and get some sleep.
Trying to stand it up in an emergency now is asking for trouble.
You'd have to be in a really dire situation to risk the carrier and aircraft this way.
They're not striking the entire air wing below just so one C-130 can land and take off, and that's assuming a stunt pulled by one elite test pilot was replicable by a bog-standard junior C-130 pilot.
The Fifth Fleet base in Bahrain got flattened.
But at the same time, it's not like that came out of nowhere. If you attack a country, that country shooting back at any military installations in missile range has to be one of the expected outcomes. Given the US had all the initiative in starting the conflict I would have hoped there was a logistics plan that involved not relying on those bases to continue to exist
Have you seen the people responsible for planning right now? They're more concerned with posting AI generated memes on twitter and scoring bigotry points than managing a foreign conflict.
Anyone with the capability to plan for the Iran war never would have started it because the costs would have been obvious. In other words the only way to start a war with Iran is to have no plan for it.
Not only that, but it was already that way for ~40 years, where past presidencies all knew and documented why it was a stupid idea, didn't press the stupidity-button, and mostly worked towards better options.
Gosh, if only they could've stopped it!
> Foreign influence and realized threats of assasination seem to be a factor.
The only head of state assassinated in this conflict was Iran's.
All Trump needs is a little dangling of glory and publicity and he'd oink like a pig if he thought it'd earn it. Pathetic creature.
Netanyahu tried the same schtick he's done for 30 years of POTUS's, just now we have someone retarded enough to fall for it and a party that allowed him to be surrounded by sycophants.
You should just admit you voted for a retard and pay your penance to your countrymen and species.
Americans make war on other people, other people don't make war on Americans. It's one of the reasons why they are so eager to do so. 'The other guys might hit back' doesn't even register in the cultural psyche.
Eg who armed the Mujahideen?
No, it doesn't. It's now in Thailand for R&R, then back to base in the US, because of this issue.
https://apnews.com/article/thailand-singapore-us-aircraft-ca...
> What's causing us to lose is failure to achieve victory due to the means employed…
Right. We're being too restrained. That's some Vietnam War era cope you're huffing.
Yes, that is the point everyone has been trying to make.
Also, to be clear, a land invasion isn't "too costly". It's suicidal because we're talking about a massive country that has been preparing for decades, has a terrain advantage and literally more than a million fanatics ready to die for the regime. You'd need millions of soldiers deployed, and are looking at some Operation Downfall level expected losses.
We can all agree on your opening.
??
What does this even mean? It seems to come out of nowhere. Is it a reference to some event??
But the US won and have and have a peace agreement. Several times.
One of the reasons for consitency above all else is to use the power of history.
Ahistorical is now the defacto standard. All asdumptions about America power are toilet paper.
We see that in commercial aviation a lot which is why when there’s so much as 2 instances of a similar failure within a short timespan investigators start looking more closely at maintenance and manufacturing.
These two states are indistinguishable from each other. A good hack looks like a poorly configured maintenance update, and vice versa.
But a misconfiguration is even more likely.
Can’t think _why_ freezers need to be web connected and remotely managed in the first place. What benefits does that bring the commissary in normal operation?
Tada. It saves someone from making the rounds with a clipboard and writing down temps every X hours.
I agree its unneeded, just I can see the thought process.
This type of wargaming scenario is literally stuff they give to brand new kids out of high school to get them thinking. It's not anything close to "loose lips sink ships."
As per the article that's literally a selling feature
Are these materially different? Assuming that there wasn't a literal command to turn off all freezers, from an organizational, non criminal perspective, to the organization the damage will be the same, the root cause will be a bug (whether exploited by chance or malice), and the fix will be the same(fixing the bug).
A hack implies an adversary, and intentional targeting.
The thesis "everything hackable" will be hacked, and with the advent of hacking LLMs, the boundary between criminal hacking and civil hacking is being blurred, it's no longer attributable to a criminal intent, hacking commands are just something that happens through no criminal intent.
Practically, the hackers, whether human or syntehtic, are a catalyst, they accelerate the rate at which a bug that causes damage will manifest, and perhaps the magnitude of the manifestation, but the essence of the negative manifestation of that bug is the same. Whether it was triggered by a solar ray flipbit or by a rogue LLM or by a russian hacker, the essence of the issue is the same.
If it was a mistake, it happened at many facilities. That seems like a repeated mistake to me.
I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on the thing (user/pass eg admin/admin was their usual). Anecdote: I once spent hours reading the docs and clicking around trying to get it to accept an SSL certificate signed by a real CA and it wouldn’t go, but it accepted one I self-signed in openssl.
In all fairness, the people who are experts in the field of Siemens PLC programming are usually mechanical-ish engineers and security is not in their skill set or on their mind.
The PLC engineers I had contact with usually had an electrical engineering background. That's why they like PLCs in the first place with the ladder logic programming languages, grafcet and if they feel fancy a bit of structured text (assembly like) or structured control language (pascal like). They indeed did not know much about software security but a great deal about machine safety.
A real security nightmare are older OPC servers (OPC-DA) which is super reliant on DCOM. OPC is quite important to connect the PLCs to SCADA systems or 3rd party devices.
Then someone plugs in a cable because boss wants something "over there" and there's already a network that runs "over there". Or optimizes to a smart switch with vlans, and then someone else optimizes to a single vlan. It's not hard to not give a shit, or not understand, network security.
In reality it'll likely first be noticed ten years down the line, by someone who lets out a big sigh, mutters something about "incompetent dipshits not updating documentation", and moves on with their day.
I'm saying that's what you do in order to solve the issue. You have to actually try, and you have to do actual engineering.
If the local planning commission submits a call for proposals for a bridge to cross a 400 foot chasm over sharp rocks, and they insist that it absolutely, positively must be made out of popsicle sticks, local civil engineering firms aren't going to take up the project, because that's insane.
Why do we give the management of these places a pass for PLC and SCADA systems that could give massive problems - up to and including the loss of human life - if they're hacked?
On my project the service I wrote was doing bidirectional communication with the PLC over OPCUA. The server running this pod was connected to the internet, so it was critical to have proper TLS for the OPCUA client/server. Rotating LetsEncrypt certs on the system every 45 days is a lot of toil, but using a self-signed cert that expires in 2040 from some dev laptop doesn’t pass muster in most organizations either.
That’s just the OPCUA path.. In these projects You also typically see WinCC HMIs that can talk to the PLC from anywhere on the network without TLS. And also SIMATIC Web Server pages - minimally secured by default, and the amount of info you can grok about the system in Chrome Dev Tools is troubling.
admin/admin is on a post-it stuck to the monitor because everyone we hire is perfectly capable of rooting a machine they have physical access to.
What is unique about your system using LetsEncrypt that you can't automate certbot to handle this task as it was designed and intended to be done?
Some PLCs run extremely expensive machines. Some machines can't afford to have their control systems stutter or fail because that can lead to physical damage and production outages of enormous proportions. A PLC that stops communicating because a certificate just expired is absolutely not acceptable in some plants.
Running certbot on a random PLC isn't happening.
Not really dissimilar from the human upbringing: leave a baby with "bad" guardians, and it will grow up corrupted. That's a feature, not a bug: if you knew what behaviour exactly you wanted (other than "whatever Simon says"), you would just bake it in in the first place, right?
Stuxnet was over a decade ago.
There should be a simple rule that everyone with the ability to understand things like PLCs should be able to grasp: your equipment does not touch the internet or external storage, period.
Those who can't grasp this concept should be shown the door with a recommendation that they find a less mentally-taxing line of work.
The worm was designed to jump across network air gaps via USB flash drives, and spread across isolated networks to other hosts. Finally, it targeted what was likely going to be a service technician laptop, which had to connect to the PLC via a data cable to update and adjust its configuration.
An attack like this can only be avoided if you never transfer any data from the outside to the inside. But that means you won't ever be able to install any form of software update or upload new config files without manually typing them in - or even reinstall the OS on any machine...
Fact is if the customer wants to put their worksite management on AWS, you inevitably expose the OPC server and/or PLC to a Intranet. This is then inevitably connected to the internet in some way. The customer may or may not put barriers between them, but that's not up to us to decide.
This becomes especially a problem if they have multiple sites across a country or countries.
We have a customer that runs a factory on god forsaken WIFI, then dares to complain about a bad connection to said equipment. Thankfully, they have their own internal IT department.
"Every nonelectric cooler comes with 25 years of free real-time monitoring. On a visit to the company in the spring of 2012, I watched as technicians in Broad Air’s space-age control room checked on the performance of its units in locations as diverse as the Adolfo Suárez Madrid–Barajas Airport in Spain; Qualcomm headquarters in San Diego, California; and Fort Stewart, the U.S. Army base in Georgia [emphasis added].
"Zhang says that 80 percent of his clients are repeaters. “If you bring long-term benefits for your clients, they will choose you.”"
Not just in the sense of secretive kill-switches, but "US government commands you to turn over this encryption key and you're not allowed to say you did so" stuff.
That barely even registers given the scale of more modern escalations against its 'allies'. Escalations like "US government threatens that you aren't a real country and that you can't defend yourself from it."
Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.
The problem is the author should have put a few concise bullet points at the top. (14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.)
I really recommend skimming the article to the end.
(Unfortunately, the article really is so verbose it's a borderline rant.)
In my mind, if this was a hack, it was probably not a Stuxnet virus or something. These are smart fridges we're talking about - someone probably just logged into them using leaked credentials or a Web app vuln, and turned them off.
I've seen batch failures in radio equipment where I could predict 100% accurately which devices would fail based on the range of serial numbers.
Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late.
All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway.
Interesting times...
Considering Iran is looking for any possible avenue to make the US look bad especially directly before an election with a president who cheerleads the military strongly while not actually putting the time or thought into what makes it strong.
This would be worth far more than the vulnerability itself to Iran right now. No real injuries causing escalation. Making a more capability adversary look foolish.
according to the article, the denominator is ~235.
An attack like the author hypothesized would require a LOTL modus operandi, and doing so on 14 locations wouldn't justify completely blowing up an entire LOTL operation, because it exposes indicators, registers, and tradecraft that is then shared amongst all security vendors.
The way it's framed is clickbait at its worst with the added issue of limited security experience, but the same can be said of HN in general.
But, I'd be a lot more inclined to that idea if it wasn't for how they failed: they started a defrost cycle that turned the freezers into heaters, spoiling the food quicker. And the failure happened overnight, delaying discovery of the problem.
It could be just a compounding of bad luck. But an attacker with access to the specs for the freezers might be aware of how long they would stay cold after being simply shut off.
And yes, remember you can explain everyting by adding enough dimensions to a game of chess. But in reality? Seems the upside is near zero while the dowside is sacrifising your access.
Maybe a kid just wanted to do it for fun? Maybe a smaller hacking group who would just like to make a statement against fascist/imperialist USA is happy to just cost them a few million dollars with a few network packets?
Wanted to offer a few clarifications:
I’m not a cybersecurity expert; I’m an investigator (in a totally different field), and this was essentially me following a weird thought to see where it went. My background is in natsec so that’s where my mind goes. There have since been at least dozens of additional freezer outages reported in a similar pattern, but I'm refraining from calling/tracking down every individual weirdness based on a Facebook comment at this point since there are much larger outlets with journalists more proficient than I covering this by now. Another interesting thing - There are numerous freezers and fridges within base stores, not under the control of DeCA/DoD, and none of those appear to be impacted.
I completely agree that a bad update/configuration or other shared technical failure may be the much more boring answer. The interesting part to me is that potentially hundreds of varying systems can converge upstream into common monitoring/control infrastructure. Anyone on this forum probably understands that, however IoT was something that was a relatively new concept when I was in school, and my degrees were somewhat relevant. The average person is blissfully unaware how expansive (and how much work behind safeguarding) the IoT is.
Also, since it came up: Yup. Human written. I’m pretty firmly anti-AI as a writer and also just, like, societally. I'll be sure to add some sort of footnote detailing my ai usage at the bottom of future public facing work, because I too detest reading (or questioning if what I'm reading is) slop. Minimal LLM used for understanding technical concepts and what the fuck fridge norms are…The weird formatting, excessive bolding, neurotic parentheticals, and rant energy are, unfortunately, totally my own. Sorry guys.
This was my first ever public post and intended audience was ~ 10 friends forced to read my diatribe, not thousands of strangers very validly raising questions I am not smart enough to answer myself. Appreciate the discussion and will be further educating myself on some of the points a few of you have brought up.
It's definitely suspicious. My money is on inside job — perhaps someone not fond of the current administration's handling of things. In my experience, these types of vulnerabilities are well-known and kept in the back pocket of engineers that have a lot of experience maintaining the equipment. Everywhere I've worked has been deeply vulnerable in some way, all of the engineers knew it, and often joked about it or were counting the days to getting pwned because companies never like to spend money to address the issue. I'm sure the military is no different. Probably worse.
My main question was "did Claude do the investigation by itself or just write up the article from someone's notes?"
Also though, I'm quite willing to believe this is human written and the human just happens to have a Claudey style. The actual prose isn't that Claudey it's just the structure of how it presents ideas. But, Claude had to get that structure from somewhere. It's not that surprising to see people with that style of communication.
I did all the digging, researching, writing, etc myself. The reason the screenshots are from mobile is because I wrote a lot of it literally in my notes app, on my phone before I started putting together more dots. I eventually asked gpt if I was correct in my understanding about refrigeration controllers doing XYZ and if it was plausible for them to be hacked in this way, when looking for some docs I asked if it would be standard to have XYZ part of a contract public and XYZ private, and other singular questions like that. I also use a browser extension for spellcheck that (I think) uses AI to suggest phrasing improvements, which I used pretty nominally.
Is there any type of sidebar/footnote that you, as a reader, would like to see to denote AI usage during the writing and/or research process? Would you expect none? I don't plan to do many investigations such as this (literally started because I was personally impacted) but I do have a few potential article seeds about defense procurement tech I've asked a few definition/research questions to AI about and would like to make sure I'm keeping tabs on it since this is something I want to be perhaps hyper aware of moving forward. Keeping in mind this is my personal substack and I would like to maintain integrity, but also, not doing really any groundbreaking work here. Intended to be an outlet for my thoughts, not news.
It's not something I expect, but I definitely don't see an issue with people putting a couple of sentences in an "expand to see AI usage notes" tab at the top or bottom of the page.
> Would you expect none?
As in, would I expect no AI usage? Coz no I absolutely expect people to use AI.
If you had got Claude to do this investigation for you then actually I think that would have been notable enough to include details of your AI workflow. But not because "it's cheating not to disclose it", rather because you'd probably have come up with quite a neat workflow that is interesting in its own right.
Regardless if this was a hack or a bug, the bigger lesson is that overcomplicated systems fail in catastrophic ways. Why do military commissaries need remote-controlled freezers? It seems like a very fragile, and needless, way to run a freezer.
---
But, there are some options that the author didn't consider:
1: This could be a quickly applied patch that failed.
2: This could be a "script kiddie" hack from someone who isn't a government actor.
I'm less onboard with a state actor. Generally, when a state actor has hacked something, they don't want the victim to know. In this case, if it was a state actor, I would anticipate that they would make a single freezer fail in a way that they could verify using something like a hacked video camera or otherwise by watching public social media feeds. IMO: A state actor would only "make sense" if they knew the hole was closing soon and they don't care if they're discovered, perhaps because their operation is winding down.
I’ve seen similar too many times in my career - synchronized clocks are great until someone deploys a cronjob that fires at exactly the same time across the fleet and it breaks a certain OS or firmware revision. Which then exposes another bug that exists globally.
I definitely still subscribe to don’t attribute to malice what you can attribute to incompetence mindset.
Certainly all speculation though, real root cause will be interesting if it ever becomes public.
I'm sure some script kiddie broke into a government network, hacked an industrial process, and forced a limited supply piece of equipment into a failure mode that takes some thought and is more unique as an attack vector. It's just like buying hacks for CS source right?
Could be the Iranians, or someone aligned, conducting anti-morale operations. Could be the start of a series of small but annoying failures.
But if I was an Iranian operative with instructions to damage the morale of the American war machine, I'd absolutely do a series of things like this.
It doesn't really harm anyone, but enough similar events and the families of servicemembers start to feel unsafe, which is psychologically very different than the servicemembers themselves feeling unsafe.
It's probably more benign than that, most likely firmware or a central controller failure, but still
Unfortunately, I would wager that all BAS software is full of flaws and holes, allowing access to it for the public internet seems like a bad idea. I need to be on my company VPN to access our locally hosted BAS front end (which I have authorized access for) which seems like the bare minimum security.
I was curious if this was continued evidence of poor appropriations and upkeep or what... I do see "U.S. military commissary refrigeration maintenance, equipment replacement, and physical infrastructure are funded through the 5% commissary surcharge paid by customers at checkout rather than direct congressional appropriations."
So, perhaps the first place would be to follow the money - are these being repaired at the proper rate? Is this repair outsourced to third party vendors? (my guess). Is this gonna end up being the McDonald's Ice Cream machine all over again?
Really though, Hanlon's would be much easier to believe this is yet further ineptitude by those who run things (I am not going to claim malfeasance/malevolence, except a general sense of such across the board by this admin).
Since I'm not on the inside, anything I have to say would be speculative, just like the above, or the author themselves (I have no idea who it is, and perhaps they have a better beat on the ground with regards to this), but it just falls in line with "we're running out of missiles" and "sailors attempting to kill themselves".
We're so insistent on being #1, we can't admit we're in a society that is falling apart (and again, it may be the case that this IS a hack, but if I were to place my bets...)
Ineptitude, lowest cost players, etc "efficiency" indeed. You get what you pay for, and I guess 5% don't pay for a whole hell of a lot these days.
… the article does posit this … nonsensically. TFA also establishes that "RMCS" stands for "Remote monitoring and control system". I would think the "and control" portion of the acronym would indicate that it is centralized monitoring … and control.
This is food storage for a commissary, aka a store. They don’t use residential refrigerators.
Now, considering how the OpenAI/HF hack emerged out of nowhere, it might be possible that groups of AI agents might have done this even without any close human supervision.
Could be a hack or a design flaw. I await the root cause analysis.
I'm guessing Iran will claim it as an attack even if it doesn't end up being them in the end.
It's also possible that, because the US is busy bombing Iran, Iran may be busy attacking the US infrastructure in any way possible? The US is also in a tepid war with russia, last I checked.
Some "cyber" crew getting a shell on an outsourced service provider and running a "defrost" command is also a totally explanation for this situation. It's also totally possible that some crew has mapped out a list of PLC entry points for various orgs and has them in a spreadsheet of "if we find a vulnerability, we should X this Y with this prestaged script that our intern / LMM cooked up last year to defrost these freezers"
"But the thing I can’t get past is Fort Huachuca’s failure mode.
Not: the freezer compressor died.
Not: the power went out.
Not even: the refrigeration system stopped cooling.
Every freezer went into active defrost."
This is a much bigger deal than the freezer being down.
No LLM use while writing, except for my grammar/phrasing plugin which I think (?) uses AI. I detailed my explicit usage cases for gpt in an earlier comment above.
Is there anything you, as a skeptical reader, would like to disclaimed/posted/footnoted when it comes to disclosing gpt usage during research questions, etc?
Wasn’t planning to have to address this early on but I would love to moving forward, especially time listener, first time caller to the online writing publication world, especially in the era of rampant AI usage.
(Keeping in mind that this is my personal substack meant to be an anthology series of my thoughts and rabbit-holed interest write ups, not exactly intended for such wide scrutiny but, I guess, could be potentially disseminated widely in a rare instance such as this first post, lol)
Please don't say confirmed. AI detectors are not reliable in any way.
Should be much closer to the top of the article. Otherwise this is just weird and potentially dangerously wrong research.
There doesn't seem to be anything indicating an advanced attack. If you're a foreign adversary and you want to flex your muscles (in a way that would be a borderline act of war), you don't just flip one switch and giggle about spoiled food.
Not exactly strong evidence presented here, but it wouldn't be a surprise either
But I fear the vested/wealthy interests involved in iot data mining, advertising, "relationship management" and plain "we own this"...
It (probably) prevents a comprehensive law supporting common sense.
A. This technology is inherently crap, that's our fault
B. A bored teenager broke it. Bored teenagers are a thing, it literally doesn't matter which country they are in, stop building things bored teenagers will blow up, this is also inherently our fault
C. Foreign Adversaries
It suits both mass media audience figures and a narrative of wily enemies rather than incompetence to pin everything on C and it seems eminently possible that a country with as many enemies as the US would attract this sometimes, but the reality is that both A and B are much more likely despite being embarrassing.
Having remote on/off capability, or even the ability to set temperatures for freezers remotely is just so insanely idiotic, I don't get it. Why even have the path? If the temp is wrong, go investigate.
This is such a colossal non-problem. The risk is now, at the start of a war action base supplies could be made unusable.
One of the big current risk scenarios is, all smart cars, all meat packing plants, all industrial capacity, all phones, all internet, all interrupted at precisely the same time. A multi-pronged hack, right at the start of the war.
Imagine all electric cars bursting it flames in garages as they charge overnight. Conjoined with all cell phones, network connectivity, and landlines going out. And 911 call centres.
So now you have a fire raging, the fire department doesn't even know, and if it wanted to respond? There's 4 fires on every suburban block.
Within a few hours, a large portion of the populous now has no housing.
That's just from two simple hacks, communication and electric cars.
The society of always-on-connected is just dumb, stupid, insane, and has threat-results worse than some nuclear exchange scenarios.
And there will never, ever, ever be secure software. Ever. Never going to happen, ever. No rust, no this or that, no AI help, will ever, ever, ever secure software. Ever.
And how do I know this?
Because 50 years later, I've seen software just as buggy, insecure, as it always has. Anyone thinking "oh, we can just do this thing! And then software will be safe" is a loon, it'll never ever happen.
And that means?
Nothing important should ever be network connected, ever.
So why would any yahoo think remote control capacity on a freezer is sane?
> "I'm sorry I'm familiar with that function. Let me research enabling defrost for you."
We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people who were in charge of operational control for stuff like freezers across military bases.
Maybe the mode they got stuck on was defrost.
If n is found to be greater than 100 and y subsequently never comes 'round to be 3, then defrost starts and runs forever."some of that stuff might become dinner" is splitting hairs, I feel.
Why? Because disruptions along the supply line are disruptions along the supply line. If a deep Russian ammo depot had a sudden smoking accident, you would (rightly) think it absurd for a Russian mil-blogger to quip that "technically we didn't lose ammo, the fuses are put in right before firing, we lost stuff that might become ammo." Seems less convincing now, right?
Maybe tonight's meal isn't disrupted, but the weekly meal planning is certainly disrupted. I hate to say it, but if the intent was an opportunistic hit to troop morale before a CVE got burned anyway, I'd say mission accomplished. :(
If this does turn out to be an attack, it's from decades of higher-ups ignoring cybersecurity coming home to roost.
This appears to be happening stateside, and most, if not all, of the listed bases have nearby grocery stores (I'm saying most based on the ones I recognize and know where they are, I didn't look up the rest). This is an annoyance, not a massive disruption.
Honestly, it probably creates more disruption for the retirees in the areas around the bases than it does the local active duty members.
I agree that it is an important role that would be worthy of disruption for a motivated attacker.
But also: These things aren't usually at the center of vast food deserts. There's typically other ways to find some grub, like the Wal-Mart right over there.
The internet security practices I experienced when working with the DOD in a prior life were…interesting?
Outside of the classified realm, there seemed to be little to no on the ground understanding of the Internet. Many things where internet connected that shouldn’t be or weren’t that should. I was involved in one contract where we had to demonstrate the ability to remotely access and control a system (to satisfy the system’s owner) as well as demonstrate that the system could not be remotely accessed via the internet (to satisfy the base IT folks). The solution was a hotspot kept in a lock box…that I doubt was ever locked after we left because it was constantly attached to our internal monitoring network despite our pleas.
“If sovereign and subject are in accord, put division between them.” —Sun Tzu, The Art of War