Need help?
<- Back

Comments (68)

  • CobaltFire
    As someone who spent over 20 years active duty, and spent a ton of my career in the IT, security, etc. side of the house:Unlikely to be a hack, more likely to be a misconfiguration or update sent incorrectly.That said, the timing of the disclosure and the issue are rather concerning.Regarding the highest value targets to hit with an attack like this, you would want to target Guam, Hawai'i, and other isolated overseas locations where this would have ripple effects in the local economy. Guam specifically would cause catastrophic supply shortages, since DeCA probably supplies around 50% of the groceries on that island (that's a WAG based on my time there).
  • peterabbitcook
    A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising.I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on the thing (user/pass eg admin/admin was their usual). Anecdote: I once spent hours reading the docs and clicking around trying to get it to accept an SSL certificate signed by a real CA and it wouldn’t go, but it accepted one I self-signed in openssl.In all fairness, the people who are experts in the field of Siemens PLC programming are usually mechanical-ish engineers and security is not in their skill set or on their mind.
  • codingdave
    The author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems?Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.
  • HardwareLust
    My only question is, why would all refrigeration be under the remote control of DECA? That seems unnecessarily complicated.
  • ggm
    Single source systems provider and integrator and a doom date?Could be a hack or a design flaw. I await the root cause analysis.
  • BobBagwill
    I would suspect a firmware bug. Or a "Service Required" timer that was ignored.
  • tyingq
    This would be a bigger deal for the commissary locations outside the US, though I see none are on the list. Many of the very junior enlisted make very little money (~2400USD/month), and the low pricing at the commissary helps quite a lot. In the US, you would typically have some affordable off-base options. Overseas, it depends. Many of the locations are remote, or in places where the local groceries are significantly more expensive.
  • gwbas1c
    To summarize for people who TLDR: 14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.Regardless if this was a hack or a bug, the bigger lesson is that overcomplicated systems fail in catastrophic ways. Why do military commissaries need remote-controlled freezers? It seems like a very fragile, and needless, way to run a freezer.---But, there are some options that the author didn't consider:1: This could be a quickly applied patch that failed.2: This could be a "script kiddie" hack from someone who isn't a government actor.I'm less onboard with a state actor. Generally, when a state actor has hacked something, they don't want the victim to know. In this case, if it was a state actor, I would anticipate that they would make a single freezer fail in a way that they could verify using something like a hacked video camera or otherwise by watching public social media feeds. IMO: A state actor would only "make sense" if they knew the hole was closing soon and they don't care if they're discovered, perhaps because their operation is winding down.
  • homeonthemtn
    Very interesting article, very neurotically written. Definitely got grating by the end.
  • VCFundedGenYer
    "To be very clear: I do not have evidence that the Defense Commissary Agency was hacked."Should be much closer to the top of the article. Otherwise this is just weird and potentially dangerously wrong research.
  • the_real_cher
    Would be hilarious if this was a runaway AI that someone was using to control their own IoT fridge.> "I'm sorry I'm familiar with that function. Let me research enabling defrost for you."
  • boesboes
    Welcome to the internet of shitty unsupported and insecure crap! Are we really this dumb as a society?
  • 1284725
    Gilfoyle was here. Everything that has been mocked in the Silicon Valley Show has either already happened or will happen.
  • fzeroracer
    There's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers.We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people who were in charge of operational control for stuff like freezers across military bases.
  • AppAttestationz
    I'm waiting for the OpenAI report that their agents defrosted everything.