# Cyber War

**URL:** <https://boards.straightdope.com/t/cyber-war/478180>\
**Category:** Great Debates\
**Created:** [December 21, 2008, 12:08pm UTC](https://boards.straightdope.com/t/cyber-war/478180 "2008-12-21T12:08:47Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![chowder](https://avatars.discourse-cdn.com/v4/letter/c/977dab/32.png) [@chowder](https://boards.straightdope.com/u/chowder)\
**Post date:** [December 21, 2008, 12:08pm UTC](https://boards.straightdope.com/t/cyber-war/478180/1 "2008-12-21T12:08:47Z")

</div>

I’ve just finished reading _The Edge of Madness_ by Michael Dobbs.

Chinese hardliners attempt to take over the world by hacking into the government computers of Britain, The USA and Russia and also of several other smaller countries.

They hack into the the puters that control the Thames flood barrier, the one that stores all records of citizens personal health details and also private info on Top Secret Govt. puters.

It’s quite a good read and I just wonder is it possible for another country or indeed even an individual to do this, causing havoc wherever they/he chose to hack into

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [December 21, 2008, 4:00pm UTC](https://boards.straightdope.com/t/cyber-war/478180/2 "2008-12-21T16:00:24Z")

</div>

You can be sure that cyber-war is something for which nations are already preparing, both on the offensive and defensive aspects. This will be an essential part of the wars of the future.

Of course servers owned by government agencies would be most desirable targets but also those of common corporations. Suppose massive attempts are detected to interfere with US servers. What do you do? Cut of all internet communications with the rest of the world? That would be disastrous.

In my view this also points out the reality that the world is becoming a smaller place and a different place. In a few generations war will not be one group of people here fighting a group of people over there. Our enemies will be among us and we will not be fighting for geographical territory but to model the society we want.

---

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [December 21, 2008, 6:29pm UTC](https://boards.straightdope.com/t/cyber-war/478180/3 "2008-12-21T18:29:47Z")

</div>

Let me just note that a lot of that sort of stuff isn’t even connected to the outside world. If you could get on the premises of the Thames flood barrier, you might be able to link in and take over, but if you’re already there you might as well just leave a bomb and split. It will probably take less time than it would to surgically link in and brute force the password of one of the administrators. A bomb would also be more costly in both time and money to fix.

---

<div class="post-metadata">

**Author:** ![Racer1](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Racer1](https://boards.straightdope.com/u/Racer1)\
**Post date:** [December 21, 2008, 6:30pm UTC](https://boards.straightdope.com/t/cyber-war/478180/4 "2008-12-21T18:30:02Z")

</div>

This will definitely be more of an issue in future, as **Sailor** says. Certainly, it already exists on a smaller scale with the purpose of stealing information.

Currently, though, different systems are still quite separate and you’d have to hack into each one, usually using very different methods, to take any meaningful control. It’s not like you can hack into the magic Britain computer and type “exit missiles then open Tower Bridge (return)”

I could be wrong here, but I’m not sure the Thames barrier control systems would have any connection to the outside world, anyway. I’d imagine there is someone always there (or on call) to oversee things rather than people working remotely. That would mean you’d need to sneak someone in physically.

---

<div class="post-metadata">

**Author:** ![chowder](https://avatars.discourse-cdn.com/v4/letter/c/977dab/32.png) [@chowder](https://boards.straightdope.com/u/chowder)\
**Post date:** [December 21, 2008, 7:18pm UTC](https://boards.straightdope.com/t/cyber-war/478180/5 "2008-12-21T19:18:55Z")

</div>

I don’t think I explained fully, so here goes.

In the book, whenever a system is hacked into, like the Thames Barrier, what happens is that the barriers do not rise as they should at high tides/bores.

They stay down and the system is so hacked to not show that, they show as if the barriers have in fact been raised.

The same happens when other systems are hacked, things go wrong but as far as the system is concerned all is OK

---

<div class="post-metadata">

**Author:** ![Xan](https://avatars.discourse-cdn.com/v4/letter/x/ac8455/32.png) [@Xan](https://boards.straightdope.com/u/Xan)\
**Post date:** [December 21, 2008, 7:30pm UTC](https://boards.straightdope.com/t/cyber-war/478180/6 "2008-12-21T19:30:55Z")

</div>

> [@chowder](#):
>
> I don’t think I explained fully, so here goes.
> 
> In the book, whenever a system is hacked into, like the Thames Barrier, what happens is that the barriers do not rise as they should at high tides/bores.
> 
> They stay down and the system is so hacked to not show that, they show as if the barriers have in fact been raised.
> 
> The same happens when other systems are hacked, things go wrong but as far as the system is concerned all is OK

Yes but what everyone is saying is that those systems wouldn’t be connected to the internet. You’d have to have someone physically there to do it.

---

<div class="post-metadata">

**Author:** ![Racer1](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Racer1](https://boards.straightdope.com/u/Racer1)\
**Post date:** [December 21, 2008, 7:35pm UTC](https://boards.straightdope.com/t/cyber-war/478180/7 "2008-12-21T19:35:25Z")

</div>

> [@chowder](#):
>
> I don’t think I explained fully, so here goes.
> 
> In the book, whenever a system is hacked into, like the Thames Barrier, what happens is that the barriers do not rise as they should at high tides/bores.
> 
> They stay down and the system is so hacked to not show that, they show as if the barriers have in fact been raised.
> 
> The same happens when other systems are hacked, things go wrong but as far as the system is concerned all is OK

Yeah, but the principal is still the same. Hacking is just gaining access to the system. Once inside you could steal information, run a program or “virus” that acts as you describe above, or fool the system into reporting whatever you like. Doesn’t matter what you do when you have control.

The point is that hacking into multiple systems to do these things on a mass-level is not easy as they mainly sit on different types of system, which are not vulnerable to the same hacking techniques. Once you’re into the Greater Manchester Police payroll system, you’re only into the Greater Manchester Police payroll system. If you want to hack into the criminal records system, that is separate, and almost certainly running on a completely different type of system. Then the fire brigage is a different system again, probably not vulnerable in the same ways. I’m simplifying hugely there, but you get what I mean.

Also, most sensitive systems will not even have access to the outside world to provide a path in. Why would you need Internet or remote access to/from the Thames barrier systems? Easiest way to protect it from remote attacks is not not connect it to the outside world.

---

<div class="post-metadata">

**Author:** ![Projammer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/projammer/32/559_2.png) [@Projammer](https://boards.straightdope.com/u/Projammer)\
**Post date:** [December 21, 2008, 9:03pm UTC](https://boards.straightdope.com/t/cyber-war/478180/8 "2008-12-21T21:03:00Z")

</div>

It’s been going on far longer than the internet.

[1982 explosion attributed to CIA trojan software](http://www.wired.com/culture/lifestyle/news/2004/03/62806?currentPage=all)

---

<div class="post-metadata">

**Author:** ![Kobal2](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kobal2/32/20_2.png) [@Kobal2](https://boards.straightdope.com/u/Kobal2)\
**Post date:** [December 21, 2008, 9:46pm UTC](https://boards.straightdope.com/t/cyber-war/478180/9 "2008-12-21T21:46:38Z")

</div>

I’m with \*\*SageRat \*\*here : “Hollywood style” sensational hacks are not happening. Not today, not tomorrow, not ever, because the systems that control our essentials (power stations, traffic lights, missile command, bank transactions etc…) are not linked to the outside world. They’re not hooked to telephone lines. Sometimes, they’re not hooked to anything at all, save for the machinery they control.

(which is why [this](http://xkcd.com/463/) is very insightful and funny)

The only way one could hack into them would be to either physically access the machines themselves, or to somehow patch into the connecting cables (and I don’t know how anyone could do that without instantly being spotted by the network admin, assuming he’s not asleep at the wheel).  
Of course, if you can access the machines physically, a tall guy with a gun to the admin’s head will get things done way faster than Kevin Mitnick…whose exploits have been greatly exaggerated anyway.

Hacking stories, ironically enough, are the exclusive domain of non-computer savvy people.

@\*\*Projammer \*\*: even should the story be true (which I doubt), it has nothing to do with hacking in the popular meaning of the word, which is the acception the OP is using. Nobody gained illegal entry into any network - it’s just spy games and providing the enemy poisoned, sabotagey gifts. Had the microchips in the story been, I dunno, dummy war maps or bogus engineering plans, would anyone have called the CIA spooks “[hackers](http://catb.org/jargon/html/H/hacker.html)” ?

---

<div class="post-metadata">

**Author:** ![treis](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@treis](https://boards.straightdope.com/u/treis)\
**Post date:** [December 21, 2008, 9:55pm UTC](https://boards.straightdope.com/t/cyber-war/478180/10 "2008-12-21T21:55:21Z")

</div>

> [@Xan](#):
>
> Yes but what everyone is saying is that those systems wouldn’t be connected to the internet. You’d have to have someone physically there to do it.

This isn’t necessarily true. I don’t know if, for example, the Thames barrier systems are hooked up to the internet but other semi critical systems are. Oil Refinery control rooms are, for one example, and I’m sure other similar facilities are as well.

---

<div class="post-metadata">

**Author:** ![chowder](https://avatars.discourse-cdn.com/v4/letter/c/977dab/32.png) [@chowder](https://boards.straightdope.com/u/chowder)\
**Post date:** [December 21, 2008, 10:18pm UTC](https://boards.straightdope.com/t/cyber-war/478180/11 "2008-12-21T22:18:30Z")

</div>

Also:

The vast majority of the systems hacked into by the Chinese had chips which had been made by them and which held some kind of “thingy” that could be activated from afar thus causing havoc

---

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [December 21, 2008, 10:24pm UTC](https://boards.straightdope.com/t/cyber-war/478180/12 "2008-12-21T22:24:01Z")

</div>

> [@treis](#):
>
> This isn’t necessarily true. I don’t know if, for example, the Thames barrier systems are hooked up to the internet but other semi critical systems are. Oil Refinery control rooms are, for one example, and I’m sure other similar facilities are as well.

Indeed. (Note that I said “a lot of” in my post, not “all.”)

But even though something might be going over the internet, it will likely be using proprietary software on top of TCP/IP. Getting access to it will still entail a very long process of reverse engineering how the whole thing works, which you have to do without being discovered.

Hacking, in real life, will just as likely involve some amount of social engineering.

The process of hacking/cracking isn’t in finding the mathematical secret that allows you to work back from an encrypted packet to its key, it’s in determining the weakest link in the chain and attacking that point. If the technological security in place is well made, it’s often cheaper and faster to knock a guy out and steal his pass card.

---

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [December 21, 2008, 10:25pm UTC](https://boards.straightdope.com/t/cyber-war/478180/13 "2008-12-21T22:25:54Z")

</div>

> [@chowder](#):
>
> Also:
> 
> The vast majority of the systems hacked into by the Chinese had chips which had been made by them and which held some kind of “thingy” that could be activated from afar thus causing havoc

:dubious: Cite?

ETA: Or oh, you’re talking about your book, not some conspiracy theory.

---

<div class="post-metadata">

**Author:** ![Indistinguishable](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@Indistinguishable](https://boards.straightdope.com/u/Indistinguishable)\
**Post date:** [December 21, 2008, 10:26pm UTC](https://boards.straightdope.com/t/cyber-war/478180/14 "2008-12-21T22:26:20Z")

</div>

He’s talking about the novel he read, not making an assertion about actual history.

---

<div class="post-metadata">

**Author:** ![Racer1](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Racer1](https://boards.straightdope.com/u/Racer1)\
**Post date:** [December 21, 2008, 10:46pm UTC](https://boards.straightdope.com/t/cyber-war/478180/15 "2008-12-21T22:46:08Z")

</div>

> [@Sage\_Rat](#):
>
> _snip_ The process of hacking/cracking isn’t in finding the mathematical secret that allows you to work back from an encrypted packet to its key, it’s in determining the weakest link in the chain and attacking that point. If the technological security in place is well made, it’s often cheaper and faster to knock a guy out and steal his pass card.

Yep, or just call the guy up claiming to be tech support and ask for his password. I’ve seen this done on a pen-test.

Of course, you’d hope people in sensitive facilities would take security more seriously, but if we are dealing with Doctor Who style thingys, all bets are off!!

---

<div class="post-metadata">

**Author:** ![clayton\_e](https://avatars.discourse-cdn.com/v4/letter/c/c57346/32.png) [@clayton\_e](https://boards.straightdope.com/u/clayton_e)\
**Post date:** [December 23, 2008, 9:04am UTC](https://boards.straightdope.com/t/cyber-war/478180/16 "2008-12-23T09:04:47Z")

</div>

> [@Sage\_Rat](#):
>
> :dubious: Cite?

I’m gonna have to second that… According to Wikipedia Mr. Dobbs was a Speechwriter, a “Deputy Advertising Chairman”, and a columnist. He also wrote several _fiction_…

Wait.. I was going to write several _fiction_ books as well as the books you’re reading.. Until I looked up that book and realized _ **its a book of fiction itself.** _

I had a few other points I was going to make about his lack of scientific background.. but doesn’t look like I have to.

Christ.. I thought you were reading something like commentary or technical analysis.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [December 23, 2008, 9:47am UTC](https://boards.straightdope.com/t/cyber-war/478180/17 "2008-12-23T09:47:14Z")

</div>

Sadly, the Chinese really are trying to hack into British systems, and have been for years. They were the number 1 electronic threat during my time at BAE.

---

<div class="post-metadata">

**Author:** ![clayton\_e](https://avatars.discourse-cdn.com/v4/letter/c/c57346/32.png) [@clayton\_e](https://boards.straightdope.com/u/clayton_e)\
**Post date:** [December 23, 2008, 10:40am UTC](https://boards.straightdope.com/t/cyber-war/478180/18 "2008-12-23T10:40:46Z")

</div>

I was specifically looking for a cite that says “Here’s that phone home chip! You know, the one where it sleeps until china lowjacks it and steals all your porn!” with it all pulled apart and unarmed.

I have no doubt that China is a threat in the potential cyberwar, I just thought this phone home chip was for real (cited by the author of the opening post of this Great Debate thread meant, I assumed, we were talking about debating the potential hazards of a non-fictional cyberweapon).

---

<div class="post-metadata">

**Author:** ![groo](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@groo](https://boards.straightdope.com/u/groo)\
**Post date:** [December 25, 2008, 8:20am UTC](https://boards.straightdope.com/t/cyber-war/478180/19 "2008-12-25T08:20:56Z")

</div>

Not sure how much press this got (because my life was a whirlwind of activity at the time), but during the week before Thanksgiving this year, every IT person who worked with computers that handled classified data had to work 'round-the-clock to verify that the systems were “safe.”

[Link](http://www.usnews.com/articles/news/iraq/2008/11/28/computer-virus-hits-us-military-base-in-afghanistan.html)

There was some unsafe computing going on regarding thumb drives that arrived fresh from the manufacturer complete with viruses (or perhaps only one virus).

(A separate issue) I haven’t seen explicit mention of routers with backdoors in their firmware, but there were a bunch of [counterfeit routers](http://it.slashdot.org/article.pl?sid=08/05/09/164201) discovered in areas where classified information was processed. It scared people (a lot), because there were no procedures in place to verify firmware of “new” hardware.

The terrifying thing that I think is much more plausible: my 401K is going to have to provide me with about 2/3 of my retirement income, and it’s accessible to anyone on the internet who can log on with my username and password. I must rely on the safe computing habits of one financial services company, and this year, I (and the rest of the world) learned that people of character and intelligence are not in positions of power in many of these companies. As usual, we’re only as safe as the weakest link.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [December 25, 2008, 11:13am UTC](https://boards.straightdope.com/t/cyber-war/478180/20 "2008-12-25T11:13:03Z")

</div>

> [@groo](#):
>
> There was some unsafe computing going on regarding thumb drives that arrived fresh from the manufacturer complete with viruses (or perhaps only one virus).

That’s not what the article says. It would be trivial to clean the pendrives before first use. What it says is

> [@](#):
>
> the portable drives can inadvertently spread viruses through separate computer networks in the field. Late last week, Pentagon officials also banned the use of thumb drives because of concerns that they were spreading a virus through the Department of Defense computer networks.

[Next page](https://boards.straightdope.com/t/cyber-war/478180.md?page=2)
