Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What I heard about the Stuxnet attack was different from what you are saying:

The enrichment facility had an air-gapped network, and just like our air-gapped networks, they had security requirements that mandated continuous anti-virus definition updates. The AV updates were brought in on a USB thumb drive that had been infected, because it WASN'T air-gapped when the updates were loaded. Obviously their AV tools didn't detect Stuxnet, because it was a state-sponsored, targeted attack, and not in the AV definition database.

So they were a victim of their own security policies, which were very effectively exploited.



Do you have any sources that the infected USB contained AV updates?

I can't find any sources saying that..


This was years ago by word of mouth within channels. AFAIK it wasn't classified, but maybe the guy who told me goofed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: