security

Fatal security flaw discovered in software that controls U.S. power plants

Wednesday, August 29, 2012 by: J. D. Heyes

Tags: Security, Software, Power

Pin It
(NaturalNews) A cyber-security specialist has discovered a flaw in the software that allows hackers to spy on and attack the communication of critical infrastructure operators of power plants, water systems, dams and more, and gain access to the credentials of computer systems which control those critical systems - claims the U.S. government is investigating.

Justin W. Clarke, an expert in securing industrial control systems, said a conference in Los Angeles earlier this month that he had discovered a way to spy on traffic moving into and out of networking equipment manufactured by RuggedCom, a division of Siemens.

Officials with the Department of Homeland Security said in an alert the agency released after it had learned of the potential security issue asked RuggedCom to confirm the gap Clark, 30, a security expert who has worked in the electric utility field for some time, had identified, then provide steps to mitigate the impact.

The firm, a Canadian subsidiary of Siemens which sells networking gear for use in harsh environments like areas with extreme weather, said it was looking into Clarke's allegations but did not elaborate, Reuters reported.

Clarke said his discovery is disturbing to the extent that hackers who are able to spy on communications of infrastructure operators could then also gain credentials allowing access to computer systems that control power and water plants, as well as electric grids and other critical infrastructure.

"If you can get to the inside, there is almost no authentication, there are almost no checks and balances to stop you," Clarke told Reuters.

Flaw in the system of software

Clarke, a high school grad who did not attend college, has now found two bugs in products manufactured by RuggedCom that are widely utilized by power companies which rely on its gear to support communications with remote power stations, said the Tribune.

Earlier this year, RuggedCom released an update to its Rugged Operating System software following a discovery by Clarke that it had a previously uncovered "back door" account that could provide hackers a way in to access the equipment with a password that was easily obtained.

"The Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team, which is known as ICS-CERT, said in its advisory on Tuesday that government analysts were working with RuggedCom and Clarke to figure out how to best mitigate any risks from the newly identified vulnerability," Reuters reported.

Clarke says the problem won't be easily fixed because all of the firm's Rugged Operating System software uses a single software "key" to decode traffic that's encrypted as it traverses networks. He added that he believes it's possible to extract that "key" from any piece of the software.

'It's a big deal'

Clarke told Reuters he bought RuggedCom's products through eBay. Afterward, he conducted the hacking research in his spare time with equipment he had spread out on a bed in his downtown San Francisco apartment.

Earlier this year, he was hired by Cylance, a firm specializing in the security of such vital infrastructure that was founded by former chief technology officer of Intel's McAfee security division, Stuart McClure.

Other cyber-security experts could use Clarke's discovery to wreak havoc on communications networks as part of a wider attack.

"It's a big deal," said Marcus Carey, a researcher with Rapid7, a Boston-based security firm. Carey worked previously to help defend military networks as a member of the U.S. Navy Cryptologic Security Group.

"Since communications between these devices is critical," he said, "you can totally incapacitate an organization that requires the network."

Uptick in cyber-attacks aimed at U.S. infrastructure

There have so far been no publicly reported cases of cyber-attacks that caused damage to critical U.S. infrastructure, but military and government officials, as well as some lawmakers, have expressed concerns about such attacks in recent months.

And in July, The New York Times reported that there has been a dramatic rise in cyber-attacks targeting U.S. infrastructure.

Gen. Keith B. Alexander, who heads the National Security Agency and also the newly created United States Cyber Command, said there has been a 17-fold increase in attacks by criminal enterprises, hackers and foreign nations.

Sources:

http://www.homelandsecuritynewswire.com

http://www.chicagotribune.com

http://www.nytimes.com

Get breaking news alerts on GMOs, fluoride, superfoods, natural cures and more...
Join over four million monthly readers. Email privacy 100% protected. Unsubscribe at any time.

Articles Related to This Article:

Air traveler choked to death in police custody at Phoenix airport after being handcuffed, detained

TSA is not tracking security breach patterns, new report reveals

TSA now needs false flag security incident to convince Americans to accept obscene pat-downs

Pharmaceuticals are more dangerous to your health than terrorists' exploding underwear (satire)

Never going back: Air travel changed for worse, forever after 9/11

Airport security is a joke; backpacks carried right in with zero scrutiny

Related video from NaturalNews.TV


Your NaturalNews.TV video could be here.
Upload your own videos at NaturalNews.TV (FREE)

Have comments on this article? Post them here:

 people have commented on this article.

Related Articles:

Air traveler choked to death in police custody at Phoenix airport after being handcuffed, detained

TSA is not tracking security breach patterns, new report reveals

TSA now needs false flag security incident to convince Americans to accept obscene pat-downs

Pharmaceuticals are more dangerous to your health than terrorists' exploding underwear (satire)

Never going back: Air travel changed for worse, forever after 9/11

Airport security is a joke; backpacks carried right in with zero scrutiny

Take Action: Support NaturalNews.com

Email this article to a friend

Permalink to this article:

Reprinting this article: Non-commercial use OK, cite NaturalNews.com with clickable link.

Embed article link: (copy HTML code below):
Most Popular
Today | Week | Month | Year

See all Top Headlines...




GET YOUR FREE GIFT + SHOW DETAILS.


Now Available from NaturalNews.TV

Also on NaturalNews:

Health Ranger Videos
Activist music
CounterThink Cartoons
Food documentaries
FREE Special Reports
Podcasts
Colloidal Silver
Advertise with NaturalNews...

Support NaturalNews Sponsors:
Advertise with NaturalNews...

Most Popular Stories

U.S. dairy industry petitions FDA to approve aspartame as hidden, unlabeled additive in milk, yogurt, eggnog and cream
EXPOSED: Angelina Jolie part of a clever corporate scheme to protect billions in BRCA gene patents, influence Supreme Court decision (opinion)
Prominent rifle manufacturer killed in mysterious car crash days after posting psych drug link to school shooters
How Angelina Jolie was duped by cancer doctors into self mutilation for breast cancer she never had
Angelina Jolie inspires women to maim themselves by celebrating medically perverted double mastectomies
Facebook bans Gandhi quote as part of revisionist history purge
BREAKING: European Commission to criminalize nearly all seeds and plants not registered with government
Obama betrays America yet again by signing the 'Monsanto Protection Act' into law
Photos: Private military operatives hired to 'work' the Boston marathon with black backpacks, radiation detectors, tactical gear
Boston marathon bombing happened on same day as 'controlled explosion' drill by Boston bomb squad
Dr. Oz viciously attacks organic foods and farmers markets, pushes feedlot beef, urges clueless consumers to eat more pesticides and GMO (opinion)
USDA caves to food industry pressures, approves three new toxic meat preservatives

25 Amazing Facts About Food

This FREE downloadable report unveils a collection of astonishing and little-known facts about the food we eat very day. Click here to read it now...

 

Resveratrol and its Effects on Human Health and Longevity - Myth or Miracle.

Unlock the secrets of cellular health with the "miracle" nutrient Resveratrol Click here to read it now...

 

Nutrition Can Save America

FREE online report shows how we can save America through a nutrition health care revolution. "Eating healthy is patriotic!" Click here to read it now...

The Healing Power of Sunlight and Vitamin D

In this exclusive interview, Dr. Michael Holick reveals fascinating facts on how vitamin D is created and used in the human body to ward off chronic diseases like cancer, osteoporosis, mental disorders and more. Click here to read it now...

Vaccines: Get the Full Story

The International Medical Council on Vaccination has released, exclusively through NaturalNews.com, a groundbreaking document containing the signatures of physicians, brain surgeons and professors, all of which have signed on to a document stating that vaccines pose a significant risk of harm to the health of children. Click here to read it now...

Health Ranger Storable Organics

GMO-free, chemical-free foods and superfoods for long-term storage and preparedness. See selection at www.StorableOrganics.com



Recommended Resources On:

Natural News trends
Health Ranger news
Natural News GMOs
Mike Adams tracker
Natural News photos
Natural News Global
Natural News in focus
Natural News connect
Natural News shocking stories
Natural News radar
GMOs
Quackwatch
Vaccines
Health freedom
Dr. Paul Offit

This site is part of the Natural News Network © 2013 All Rights Reserved. Privacy | Terms All content posted on this site is commentary or opinion and is protected under Free Speech. Truth Publishing International, LTD. is not responsible for content written by contributing authors. The information on this site is provided for educational and entertainment purposes only. It is not intended as a substitute for professional advice of any kind. Truth Publishing assumes no responsibility for the use or misuse of this material. Your use of this website indicates your agreement to these terms and those published here. All trademarks, registered trademarks and servicemarks mentioned on this site are the property of their respective owners.