upvote
They are charging down that path because vulnerabilities that effect the refrigerators were disclosed the same day as 14 refrigerators failed in an absurd way. They all turned on the defrost cycle and heated the food.

The problem is the author should have put a few concise bullet points at the top. (14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.)

I really recommend skimming the article to the end.

(Unfortunately, the article really is so verbose it's a borderline rant.)

reply
Obvious sabotage would be addressed promptly. Subtle sabotage could persist as a minor torment indefinitely.
reply
Stuxnet was a good example of that.
reply
deleted
reply
The article has a post that says this happened across 14 bases at the same time.
reply
Then I would suspect that this is either down to the common control system, or there has been a batch failure of the controllers in the freezers that were presumably ordered and supplied at the same time.

I've seen batch failures in radio equipment where I could predict 100% accurately which devices would fail based on the range of serial numbers.

reply
There are a couple hundred US armed forces bases each with commissaries that would be managed by DeCA.

An attack like the author hypothesized would require a LOTL modus operandi, and doing so on 14 locations wouldn't justify completely blowing up an entire LOTL operation, because it exposes indicators, registers, and tradecraft that is then shared amongst all security vendors.

The way it's framed is clickbait at its worst with the added issue of limited security experience, but the same can be said of HN in general.

reply
Or someone somehow got into one web interface (e.g. by popping a random workstation used to monitor all these sites) and clicked buttons.
reply
So what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.
reply
OTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about.

Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late.

All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway.

Interesting times...

reply
The backbone of the US military is the logistics. It's why a US carrier being undersupplied was such a big deal. Making the US military look incompetent can very well be the goal.

Considering Iran is looking for any possible avenue to make the US look bad especially directly before an election with a president who cheerleads the military strongly while not actually putting the time or thought into what makes it strong.

This would be worth far more than the vulnerability itself to Iran right now. No real injuries causing escalation. Making a more capability adversary look foolish.

reply
Not just that, the position to stick a thermometer into the food before serving was axed as DEI, and the position to clean the food prep surface areas of the kitchen is too beneath the warrior ethos. Buying above single ply is too expense and it's too heavy, so have fun with the ED (dual meaning).
reply
And how many shipboard stores have been affected? Hardly something they’re going to talk about, and a far stronger candidate for attack. This could be spillover.
reply
Oh that's interesting. what if the issues w/ toilet spillover were hacks? Hilarious.
reply
> I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.

according to the article, the denominator is ~235.

reply
If we limit ourselves to these, then that's a 0.5% known failure rate.
reply
6%
reply
Owning my failure and moving on. More coffee next time.
reply