This doesn't seem terribly surprising to me. There are still companies that use them, so if you need to spy on one, a device like this would be useful.
The weirdest part is that the CIA uses agile-type user stories when developing its spy gear.
In fact, this is an excellent requirements document. Clear user stories with prioritization and notes. I also appreciate the Questions section at the bottom.
Good requirements documents are a rare find in my experience.
Indeed, as a UX designer I would have loved having these types of requirements when starting a project. Especially with the "Must Have"/"Nice to Have" distinction which isn't always made clear when people are asking for an endless list of features.
It is also amazing that they were using RPI and Gumstix. Looks like rapid prototyping instead of custom miniature solutions, but if it works, why not...
CIA is doing their job spying on tech that they care about, news at 11!
SCADA systems are often very old and sit unconnected to the internet for decades at a time. There are likely hundreds of nuclear reactors around the world running this old, unpatched, and very vulnerable software. They'll likely not patch it until they refurbish the entire system.
On the face this seems ridiculous. It's a big stretch, but we do know that some US adversaries use portable media (usually thumb drives) to currior data. Maybe they had a target that was using floppies? Maybe Iran's centrifuges or N. Korea still uses really old tech?
Ancient technology is pervasive in established industries. Development and deployment costs (due to risk) are huge in this world. They don't have the staff to fix a glitch due to a docker migration or whatever, and frankly wouldn't see much benefit anyway. So they continue to use what works as long as they can. And if they have to pay $10 each for obsolete media and scrounge part bins for FDD replacements, so be it.
And the CIA's job is as much to spy on this world of established industrial capability as it is to hunt down laser-toting agents in the urban jungle of Beijing.
Doesn't sound too far fetched to me, I'm actually using floppies at work to move data from old equipment (mainly old oscilloscopes and other measurement systems). If it ain't broke...
...and if you're not careful when ordering Siemens Simatic software, the accompanying licence file arrives on a yellow 3,5" floppy.
Don't ask me how I know. It took AGES to purge our ERP system of any reference to the Siemens item# which resulted in a floppy showing up.
On the other hand, it resulted in some business for both DHL and whoever still manufactures floppy drives nowadays - service engineers opening a package somewhere in the world, finding what kids today would assume was a 3d-printed 'save' icon - and order a drive, double haste...
Sadly they replaced that with a wireless system in most trains a few years ago. But you find a lot of old tech in the train system. Some traffic control was built 50+ years ago with even older technology.
It could be organizations in the US itself. I remember somewhere that the military was still requriing 3.5 floppies at least within the last 5 years. (no, I'm not talking about the nuke software that uses the bigger floppies)
Makes perfect sense to me. Why upgrade some critical piece of infrastructure if upgrading can only hurt you, but can never help you ? Assuming they didn't have ongoing problems such as bit-rot with floppies, why upgrade to USB ? There have been at least a few major attacks using either auto-run , auto-mount, or even infections in USB firmware over the years.
If you dont need the extra capacity or speed that USB or optical offers you, don't upgrade. I mean this specifically for infrastructure-size projects where the "thing" / entity that is controlled costs multiple orders of magnitude more than the computer system controlling it. Say I have a hydro-electric dam, or any kind of power plant (not just nuke), or train switch controller, submarine, aircraft carrier, etc. Stuff that can't break. Its just cheaper and safer to keep using the same tech, keep replacing known-working parts, than it is to risk updating the system to "stay current", and risk a costly outage (or some kind of catastrophe, even if theres only a 10^-7 chance of it happening). I dont blame them one bit.
You assume too much. Bit rot was the driver towards anything-not-floppy, if I recall the 90s correctly. "Can't break" and "floppies" is an oxymoron - oh God, now I have that horrible sound of a floppy read error (yes, you could actually hear most types of read errors) stuck in my head. (Perhaps the 8-inch floppies are still in use as their lower density gives higher resilience?)
What I meant was if you expect them to die, and discard them on some regimented schedule instead of expecting them to last forever. Flash-based USB storage (and even platter-based HDDs ) suffer degradation and/or bitrot, just at different rates/probabilities. Even optical media only has a few years of expected lifetime.
Of course there's bit rot everywhere, just that floppies were notoriously unreliable because of it.
OTOH, the only way to actually preserve data is to keep rolling them forward to new physical media as the old ones die off (this is of course abstracted away in cloud solutions).
Any university has dozens of labs with 386s, or similar vintage, because the software they need to operate incredibly expensive equipment is abandonware.
In fact an IT guy I knew kept the best surviving examples of vintage computers in his closet for parts or to transfer data with.
To me an interesting piece is the systemd / Linux references. The protocol to talk to floppy drives is not all that complex. If battery life is a concern, dedicated embedded code (not using Linux) seems likes a better option and not all that much more difficult to implement.
Then again, I suppose embedded Linux keeps getting lighter / better.
That requirement strikes me as classic non-/semi-technical product owner trying to suggest to the engineers how to do their job.
As for people using floppy disks in 2013... actually not surprised at all. They have a little bit of security through obscurity now and they can be easily cleared with a magnet and some scissors or open flame. And as another poster pointed out, it might be for legacy systems like industrial control.
Can't understand why they even considered using compression at all. A simple mini sd card can easily have room for 128 GB while a typical 3.5" floppy is 1.44MB. There's gonna be quite a lot of floppies to copy before that is filled.
I don't understand why crypto doesn't help avoid detection?
Imagine I have a usb thumb drive with gigabytes of mp3s on it, and I devise a way to embed and extract a floppy image into the mp3s (i.e. steganography), or perhaps family pictures. unless the images are viewed before and after, it can be difficult to determine what was stored or even if anything was stored.
Of course, not impossible as their attacks that can be done on this, but I'd argue that if one is already suspected of using steganography and they have access to the device you are storing the data on, you are most likely screwed anyways, even if they can't prove it.
The described use scenario is for smuggling the specified device in a secured environment where no electronic devices or storage devices are allowed, and passing through a physical search by masquerading the device as something innocuous i.e. "initial plan for concealment host is as a day planner". There's no intent to use steganography, random data (e.g. gigabytes of mp3 of family photos) should never be exiting the secure area in a legal manner, not even after a review; even if accidentally gets brought in, it's not getting out.
Bringing an USB thumb drive to such a place by itself would a serious incident, but might be treated (after a review) as a benign accident, but having a concealed device that can read floppies is another manner, it's obviously not a coincidence. Discovering that you ("the asset") have such a concealed device is by itself clearly sufficient for failing the mission and getting detained. It doesn't matter if it's "difficult to determine what was stored or even if anything was stored" - possession of the device and attempt to smuggle it to the secure area would be sufficient.
If you get caught with a hidden floppy drive near a place that uses floppy disks for any interesting purposes, it is pretty clear what you were up to. Being able to conceal whether you already copied anything and if, what exactly, wouldn't probably make a big difference. You are almost certainly in some serious trouble at that point.
I worked for a vendor that made networking hardware. On the system there was some flash storage. We sold to the TLAs. When we got kit in for a demo it came back out minus the flash. USB drives and the like are never allowed in a secure area. Best case you get fired, worse case you end up in prison for 100 years. In the case of what they are asking for here, it is likely "hey we have spy in one of the secure areas and we want to copy the data from the floppy on the system (still in use as others have pointed out)." If you got caught with the device you would get shot and it would not matter if they could read what was on the device. Crypto would just slow down what is a time sensitive operation.
Are there any devices (on the public market) that allow for high-density whole-disk imaging/scanning with one rotation of the floppy? Feels like it could be useful for bringing "dead" floppies back to life for e.g. retro computing enthusiasts.
Scan it once at insanely high resolution and later analyze the data...
There are hardware tools like http://www.kryoflux.com/ which might be of interest, I've never used them, so can't comment on how well they'd work afraid.
That sounds like it'd require a custom read head. Normally, a floppy read head is comparatively small, and has to be moved across the disk's radius with a stepper motor. To read it in one pass would require a head that can read all the tracks at once, so this would be something specially-fabricated, which doesn't sound cheap at all. I'm sure it could be done (esp. considering how old floppy tech is), but I don't think it's something you're going to just fabricate in a small lab with spare parts, it'd need something custom manufactured.
A 3.5" floppy copier concealed as a "day planner" and using systemd? Such spycraft in 2013 is hilarious to think about.
Especially thinking about some random corporate/government worker who got recruited as a source by the CIA and has 'unsupervised' access to some floppies.
I'm sure there's plenty of mostly non-networked industrial facilities in the "3rd world" that use 3.5 for enough of their equipment that it's the most convenient form of storage at the facility level.
I imagine this is to target old manufacturing or scada equipment. If you want to sabotage an industrial target then you're going to be seeing a lot of legacy equipment. /r/sysadmin posts from manufacturing and industrial sysadmins are fascinating as they are scary.
Also it may reveal that the target is using old methods for security purposes. Imagine an office where no one has any sort of user accessible networking (ethernet would be just for updates, security, auditing, etc), just a 1980s style set of workstations each accessing things from the floppy drive. If you want to see a file on a certain topic then you'd walk up the librarian who would check your ID and give you the disk. If you wanted to sneak that data out, then you'd have to physically copy the disk or steal it. The latter being much more risky as the librarian knows you had it last. Perhaps there's enough empty space in the floppy case to put in some kind of tracker as well.
You also don't need to worry about USB vulnerabilities with USB sticks nor the worry that someone will show up with the right cable, mount the USB drive to their phone, and copy the data. Nor the write limits and versioning exploits on writable CD media. You could also set off a EM burst that'll wipe a room full of floppies in a millisecond if need be.
If you deal with text data files then the 3.5" space limitation is not an issue, what's the average word file size? 80k? Imagine an intelligence service that keeps its state secrets like this. You'd be hard pressed to hack them. This isn't a hypothetical as we have data that suggests some intelligence services have moved to typewriters to avoid hacking[1]. Seems to me, I'd much rather just use 3.5" disks on a linux box with no networking attached to a printer than a typewriter. Even spies can't live without WYSIWG editors. Perhaps the great typewriter experiment has failed and sneakernet is a better compromise between security and convenience.
edit (as it wont let me reply) in regards to exploits here:
Your attack surface has now changed from "Anastasia in accounting clicking on resume.js" to now dragging TEMPEST equipment into the basement of the Lubyanka building undetected.
Or a mole now trying to sneak in a bulky 3.5" copy device instead of right-click > encrypt > email.
And I also think that it is pretty hard to make these 1980's workstations secure -- that old DOS software was full of vulnerabilities, and it has no modern protections at all (usernames, kernel mode). I remember back at high school we had "1980s style set of workstations each accessing things from the floppy drive." and they were full of viruses. And once you have your code on target computers, you can exfiltrate data pretty easily (emit right patterns with pc speaker, memory access, display, etc..)
You could definitely put an RF tag on a floppy and then have detectors at all exits like a retail store does with merchandise. Hell, you could use a "mantrap" like banks do so that you automatically catch the person on their way out.
There is more latitude available than you think. Intelligence Community members weren't required to cancel their NYT and WashPo subscriptions just because classified info was published verbatim during the Snowden leaks.
However, browsing wikileaks from a government-owned computer is sure to get you in trouble. Or, most likely, be blocked by whatever nanny proxy is in place.
I would never have expected someone in the defense/IC community to be whining about people posting on a privately owned website. When I was in the military I believed in personal responsibility.
Expecting people to write up a summary of documents before posting to HN is absurd. Attaching insults to the main audience of HN is not going to win you over any friends.
Question -- would that security clearance allow you to read that third party writeup? I would think it would prohibit all contact, both direct and multiple-times-removed indirect contact with the data.
It does. Just because the info is now in the public domain doesn't change it's classification level. Bizarre, I know. But it's because the classifying authority is the one responsible for changing it, and until they do it's still at the original level and all the classification and need-to-know rules still apply.
If you signed an NDA that criminalizes reading public data (that is still classified) on the open web, perhaps it's not the fault of websites posting links to that data when you click on it.
Seriously, your clearance comes with tradeoffs. Some of us aligned against government secrecy and flunkies who sympathize with the surveillance state want the list of potential downsides for that career choice to be as long as possible.
If your shitty job will put you in jail for reading headline news, maybe you should reconsider your job.
You have another option: Boot Tails. Use Tor. Read away. Don't get caught. Don't let the thought police use the threat of jail to extinguish your intellectual curiosity.
If merely hosting a headline & link like this is problematic, you must also have an issue walking by news stands, visiting bookstores, or watching CNN. It sounds exhausting.
It looks like a 3rd party observation and not a personal statement.
I.e government surveillance professionals and people with old-school conservative personalities: "I know this is hard for some of you in your SoCal startup VC money burning bubbles" are not welcome to a party hosted by SoCal startup VC money burning bubblers, free-neters, no-surveilancers, opensourcers, and progressive types.
So, 3.5" floppies are probably used in much more modern weapon designs. Perhaps orbital lasers or something. /s