Remix.run Logo
codingdave 2 days ago

The author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems?

Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.

gwbas1c 2 days ago | parent | next [-]

They are charging down that path because vulnerabilities that effect the refrigerators were disclosed the same day as 14 refrigerators failed in an absurd way. They all turned on the defrost cycle and heated the food.

The problem is the author should have put a few concise bullet points at the top. (14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.)

I really recommend skimming the article to the end.

(Unfortunately, the article really is so verbose it's a borderline rant.)

odyssey7 2 days ago | parent | prev | next [-]

Obvious sabotage would be addressed promptly. Subtle sabotage could persist as a minor torment indefinitely.

pizzaiolo 2 days ago | parent [-]

Stuxnet was a good example of that.

a day ago | parent [-]
[deleted]
wavemode 19 hours ago | parent | prev | next [-]

At the same time, I think some people in this comment section are underestimating the likelihood that this was a hack, because they're overestimating how sophisticated such a hack would have to be.

In my mind, if this was a hack, it was probably not a Stuxnet virus or something. These are smart fridges we're talking about - someone probably just logged into them using leaked credentials or a Web app vuln, and turned them off.

ckdarby 2 days ago | parent | prev [-]

The article has a post that says this happened across 14 bases at the same time.

jvanderbot 2 days ago | parent | next [-]

So what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.

schiffern 2 days ago | parent | next [-]

OTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about.

Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late.

All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway.

Interesting times...

elictronic a day ago | parent | next [-]

The backbone of the US military is the logistics. It's why a US carrier being undersupplied was such a big deal. Making the US military look incompetent can very well be the goal.

Considering Iran is looking for any possible avenue to make the US look bad especially directly before an election with a president who cheerleads the military strongly while not actually putting the time or thought into what makes it strong.

This would be worth far more than the vulnerability itself to Iran right now. No real injuries causing escalation. Making a more capability adversary look foolish.

conorcleary a day ago | parent | prev | next [-]

Not just that, the position to stick a thermometer into the food before serving was axed as DEI, and the position to clean the food prep surface areas of the kitchen is too beneath the warrior ethos. Buying above single ply is too expense and it's too heavy, so have fun with the ED (dual meaning).

madaxe_again 2 days ago | parent | prev [-]

And how many shipboard stores have been affected? Hardly something they’re going to talk about, and a far stronger candidate for attack. This could be spillover.

jvanderbot a day ago | parent [-]

Oh that's interesting. what if the issues w/ toilet spillover were hacks? Hilarious.

larrysalibra 2 days ago | parent | prev [-]

> I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.

according to the article, the denominator is ~235.

jvanderbot a day ago | parent [-]

If we limit ourselves to these, then that's a 0.5% known failure rate.

senordevnyc a day ago | parent [-]

6%

jvanderbot a day ago | parent [-]

Owning my failure and moving on. More coffee next time.

ErroneousBosh 2 days ago | parent | prev | next [-]

Then I would suspect that this is either down to the common control system, or there has been a batch failure of the controllers in the freezers that were presumably ordered and supplied at the same time.

I've seen batch failures in radio equipment where I could predict 100% accurately which devices would fail based on the range of serial numbers.

alephnerd 2 days ago | parent | prev [-]

There are a couple hundred US armed forces bases each with commissaries that would be managed by DeCA.

An attack like the author hypothesized would require a LOTL modus operandi, and doing so on 14 locations wouldn't justify completely blowing up an entire LOTL operation, because it exposes indicators, registers, and tradecraft that is then shared amongst all security vendors.

The way it's framed is clickbait at its worst with the added issue of limited security experience, but the same can be said of HN in general.

tgsovlerkhgsel a day ago | parent [-]

Or someone somehow got into one web interface (e.g. by popping a random workstation used to monitor all these sites) and clicked buttons.