US military’s use of Microsoft Windows lets hacker run wild

“To hear the US government tell it, Gary McKinnon is a dangerous man, and should be extradited back to America to stand trial in a Virginia courtroom,” Clark Boyd reports for BBC News. “One US prosecutor has accused him of committing ‘the biggest military computer hack of all time.’ If extradited, Mr McKinnon could face decades in US jail, and fines of close to $2m.”

“The US government alleges that between February 2001 and March 2002, the 40-year-old computer enthusiast from North London hacked into dozens of US Army, Navy, Air Force, and Department of Defense computers, as well as 16 Nasa computers,” Boyd reports. “It says his hacking caused some $700,000 dollars worth of damage to government systems. What’s more, they allege that Mr McKinnon altered and deleted files at a US Naval Air Station not long after the terrorist attacks on September 11, 2001 and that the attack rendered critical systems inoperable. The US government also says Mr McKinnon once took down an entire network of 2,000 US Army computers. His goal, they claim, was to access classified information.”

McKinnon admits “that he hacked into dozens of US government computer systems. In fact, he calmly detailed just how easy it was to access extremely sensitive information in those systems. ‘I found out that the US military use Windows,’ said Mr McKinnon in that BBC interview. ‘And having realised this, I assumed it would probably be an easy hack if they hadn’t secured it properly.’ Using commercially available software, Mr McKinnon probed dozens of US military and government networks. He found many machines without adequate password or firewall protection. So, he simply hacked into them,” Boyd reports.

Full article here.

MacDailyNews Take: That the US military would use insecure Microsoft Windows operating systems for any computer containing sensitive information is beyond belief.

Advertisements:
• MacBook Pro. The first Mac notebook built upon Intel Core Duo with iLife ’06, Front Row and built-in iSight. Starting at $1999. Free shipping.
• iMac. Twice as amazing — Intel Core Duo, iLife ’06, Front Row media experience, Apple Remote, built-in iSight. Starting at $1299. Free shipping.
• iMac and MacBook Pro owners: Apple USB Modem. Easily connect to the Internet using dial-up service. Only $49.
• iPod Radio Remote. Listen to FM radio on your iPod and control everything with a convenient wired remote. Just $49.
• iPod. 15,000 songs. 25,000 photos. 150 hours of video. The new iPod. 30GB and 60GB models start at just $299. Free shipping.
• Connect iPod to your television set with the iPod AV Cable. Just $19.

Related MacDailyNews articles:
Cybersecurity advisor Clarke questions why anybody would buy from Microsoft – February 18, 2005
U.S. Army’s 1,566 64-bit Apple Xserve G5 supercluster can exceed 25 teraflops – September 15, 2004
UK Royal Navy will run nuclear bomb-carrying warships on Windows 2000 – September 07, 2004
US Army to Bill Gates: cut out the freebies immediately – March 11, 2004
CCIA wants U.S. Dept. of Homeland Security to reconsider buying ‘insecure Microsoft software’ – August 29, 2003
U.S. Department of Homeland Security says Windows vulnerable to attack – August 01, 2003
Department of Homeland Security chose Microsoft due to time and money limitations – July 21, 2003
U.S. Department of Homeland Security awards enterprise agreement to Microsoft – July 15, 2003

59 Comments

  1. bat hasnt he done them a favour, better someone just showing them how unsecure they are than a terrorist actually hacking in and using the information, the govenment should be thanking him and locking the armies IT department in prison for neglegence really

  2. Oh, so the system’s were only inoperable because they were hacked were they?

    Yeah, I believe that.

    Mind you, how stupid is this Gary fellow?

    “I’ll go do some hacking. Who can I hack? I know, the most powerful military force on the planet! That’s a great idea, and guaranteed not to have any comeback.”

  3. I agree with MDN on this one. This is simply unbelievable that our government still no idea what real Computer Security is. I’m not blaming them for using Windows, this is, of course, what happens when you deal with lowest bid contracting afterall. (How low can you go, other than to Windows?) But to set them up without proper firewall and security measures, it’s simply inexcusable.

  4. This guy deserves a medal, not a jail cell. I don’t condone any damage, deletions or network disruptions he has created, but there are obviously many in key military and government positions that need a wake-up call.


  5. ‘I found out that the US military use Windows,’ said Mr McKinnon in that BBC interview.

    If you don’t take care of your feet, you get foot rot.

    If you don’t keep your weapon clean, it could jam when you need it the most.

    If you don’t post sentries around your perimeter, you’re likely to be infiltrated.

    If you don’t reconnoiter the terrain in advance, you’re likely to be ambushed.

    What you don’t need to do is worry about your Windows computer because Microsoft is the biggest software company on the planet. Just bend over, put your legs between your knees, and kiss your sorry ass because we’re all doomed.

  6. MDN nailed it.

    But you must understand that Microsoft FUD-casters relentlessly work the government agencies to inflict Windows on all government operations. They identify all those who have the power to make or prevent purchasing decisions and they manipulate them into favoring Windows and banning all alternatives.

    I just hope we all come to the point where choosing Windows in government or industry is declared prima facia evidence of incompetence and/or corruption.

  7. I am a network designer/engineer in the Marines and I will say that Windows is the only thing we use. During one exercise last year, we got hit so hard with a virus that it crippled the entire operation for a few hours. Windows is used for all networks, from non-secure to top-secret.

    I personally carry a Powerbook G4 everywhere I go but am phohibited from using it on the network because of fears of unsecurity (go figure). The US Military is 95% Windows and I have seen countless down time because of that. This story come as no surprise.

  8. It may prohibit it, but that isn’t a legal prohibition meaning that the end user isn’t *allowed* or *able* to use it in secure environments; it just indemnifies the evil Redmond Empire from legal responsibility when the planes start falling from the sky if he does.

  9. Trust me, the military is not that dumb to use a common operating system for sensitive data.

    They do have Windows PC’s around to give that impression, to catch hackers and spy’s and such.

    They also have Windows PC’s around to create the image that they are a all Windows opertation to mask their use of a really secure, unreleased operating system.

    This is why the US Governement props up Microsoft so much to keep it dominant. If everyone else is using a insecure operating system and that’s basically the only thing the rest of the world can get, that gives the military a great tatical advantage.

    Of course they can’t let on that they are using anything else or else all these other countries would want it too.

    Only recently has these other countries realized they need to develop their own OS in order to kee their data secure.

  10. The letter I just sent to my two Senators and Congressmen…

    I am totally dumbfounded to have read an article on the BBC’s website (http://news.bbc.co.uk/2/hi/technology/4715612.stm) profiling a gentleman named Gary McKinnon, who has been charged with hacking into dozens of U.S. Military computer systems from a foreign nation. He was able to successfully do his hacking because our military runs the Windows operating system and not a secure, Unix-based operating system such as Linux, Mac OS X, BSD, or Solaris. I dread to think what could have happened if he were in the employ of an enemy of our nation.

    Why is our military, where security is of the highest priority, using Windows? Why are my tax dollars being wasted on a computer OS with enough holes in it for an army of suicide bombers to walk through? Why is the military not standardized on secure a Unix variant?

  11. “He found many machines without adequate password or firewall protection.”

    Guess that kind of says it all. Its easy to break into a house when all the doors and windows are wide open.

    If you are going to run a network, regardless of OS, you should take the time to secure it properly. On my Linux box, if I don’t rename the root account something else and I make its password ‘123’, I’m gonna expect to be hacked into pretty easily.

  12. I read this after viewing with considerable disbelief a new Windows (at least here) sick making advert on TV spouting on about Microsofts belief in security. protecting their customers and their continuing ‘efforts’ to improve it even more in the future. I really don’t know whether to laugh or cry at the shear audacity of this FUD.

    I do urge anyone to complain about the untruths and misleading comments inherent in any such Microsoft advert to the relavent advertising authorities.

  13. I wrote this to my two Senators and Reepresentative (thanks for the quote TommyMC):

    I recently read a story on a blog about a gentleman named Gary McKinnon who had hacked into our military’s computer systems many times from overseas. When asked why, he stated “it’s because they run Windows”.

    I asked my neighbor Tommy, who works in IT for the Marine Corps, and he said: “Windows is the only thing we use. During one exercise last year, we got hit so hard with a virus that it crippled the entire operation for a few hours. Windows is used for all networks, from non-secure to top-secret. I personally carry a Mac Powerbook everywhere I go but am prohibited from using it on the network because of fears of insecurity (go figure). The US Military is 95% Windows and I have seen countless down time because of that. This story come as no surprise.”

    Why are we compromising our national security by running Windows? Due to their secure nature the Unix operating systems have never suffered from viruses. Why aren’t our Armed Forces using Unix? Why is one of our soldiers who owns a secure Unix-based laptop told that he is prohibited from using it on his network because of fears of insecurity”? Who is the idiot in charge of IT for our Armed Forces who made that dumb decision? Does an attacker have to be from Al Quaeda before this issue gets attention? How many of our soldiers will need to be killed before common sense prevails?

  14. -just more killing the messenger- “why wont any friggin business sue MS for all the money lost by Windows being poor.
    Im sure that virus and malware and BSOD has caused more damages to the worlds businesses than the $700,000 this guy caused.
    stop jailing the people who do drugs, and go after the drug dealers.”

    This is so dead-on its not funny, or ironic, just true. And the comments by USTommyMC… Wow!

    How we got here hardly matters any more, but more – much more diversification of computing platforms needs to start happening – now.

    How America and Americans continue to tolerate the lack of basic consumer choice in the area of personal computing continues to mullify, stupify, and terrify me.

    We really really do not understand that we’ve thrown ALL of our eggs into one basket, something that was never possible (at this level) before the advent of personal computing. We must not realize what we’ve done, because I don’t believe we’d be doing it if we did.

  15. This is absolutely true!!! I was in the military for a very long time. I have two sons and a grandson serving now and we are amazed at the security holes that the military networks have. I, we, know these things first hand!

    It’s not only the military, but the entire government.

    The threats come from China, North Korea, Russia, various eastern european countries…and even some of our “allies” looking for military and government secrets as well as engaging in industrial espionage. These countries have skilled, persistent people working 24/7 to get into our networks and individual client machines.

    NASA’s networks are a big joke, have been forever.

    The really sad part is many government and industrial IT people know how unsecure Windows is, but have to go along to get along or delude themselves into think how great and secure Windows is. Many networks are poorly set up and maintained. And yet very little if anything is done about it.

    We as taxpayers should be concern and raise hell until something is done about it.

    Now there are some government agencies use Macs because they are so secure.

    If this guy was going to just to hack into these networks and so on to show how easy it is, he should have demonstrated this to the FBI or DHS, not just do this on his own.

    To redeem himself he should be made to work for the US government to help secure these networks. If there was a case for using Mac OS X, this is it.

    Flame me, cuss me, whatever…I know what I know.

  16. The UK military also relies on Windows. I was talking to the man in day-to-day charge of security who explained that things were ok, because no-one was allowed to connect a machine to the network unless it was approved for that network. He said it was a courtmarshall offense to attach a non approved machine. By non-approved he meant no laptop was allowed to leave the building and no-one could bring a machine in.

    He was satisfied that as soon as a non-authorised machine was attached to the network Microsoft Active Directory would announce the culprit and he could shut them down.

    He knew OSX was superior in security terms but was blissfully happy that his measures were more than enough. My protestations that his measures were insane as someone sooner or later would need their laptop for an external meeting, would log onto their home e-mail while they were out and then reconnect back at the office, fell on deaf ears.

    You’d think a techie at this level wouldn’t be so brainwashed by Windows.

  17. I’m from the UK and you can have this Gary idiot with the greatest of pleasure…lock him away, or whatever. Even if his hacking was not malicious, having someone that stupid walking the streets is a danger to all of us. Besides which he will by now have had a thousand requests for the information (for stacks of cash) from the mad-mullahs and other of Bin-Ladens madmen. In fact, publishing this forum is an extreme threat to the security of the west.

  18. The military uses computers running other operating systems but they are being phased out because of a dwindling supply of non-Microsoft-centric developers at the companies contracted to create/update the software those computers run. The same goes for the users. Most people have no clue how to manipulate any OS other than MS Windows so they complain when they have to work on the outdated and often times confusing software still running on those non-MS Windows computers. It’s like a negative feedback loop. The companies see the trend and continue dropping their non-MS Windows developers or force them to the dark side.
    A ray of light recently shown through the clouds, however, in that Mac OS X was certified secure and could thus be procured by the military and security establishments. I don’t know if/when we’ll start having large military purchases of Macs though.

  19. Macaday writes: “In fact, publishing this forum is an extreme threat to the security of the west.”

    Actually, it is Billy Boy and his dark disciples, who insist on using the Swiss Cheese of OS’s: Windoze, which is the extreme threat to the security of the west.

    If Gary could figure this out, then so can the “mad-mullahs and other of Bin-Ladens madmen.”

    Pretending a problem doesn’t exist won’t make it – nor the threat it represents – go away. The publicity about this is good in that the holes might actually get plugged.

  20. I work for NATO. Sensitive military systems rely on physical security measures, not operating system choice, for their security. If the US military had classified systems physically linked to the Internet then that is the crime, not their choice of OS or this hacker. This story is irrelevant.

  21. The people who allowed or apportioned the money to buy the MS Windows should be thrown in jail. Why should we allow this kind of terrorist to roam free and subvert our American Way of Life and Security!

    This should be just as important as Wiretapping U.S. Citizens, Hurricane Preparedness, Prescription Drug Plans and the Vice-Presidents right to bear arms and use them against his hunting buddies!

  22. So not only do these stupid Yanks invade countries they have no right to, they run their whole defense network on Windows!

    If ever there was a time for Bin Laden to attack the US, it is now. Not by bombing or blowing up planes, but logging into US Military mainframes and typing format c:

    Silly Yanks, don’t use Windows to protect your country.

  23. Nothing changes for the U.S. Army. A few years ago Texas-Instruments was found guilty of not going through redundancy testing on ALL critical chips used in American ICBM’s as is expected by their contract with the Airforce, are they out of business? Were there prison terms for the irresponsible? Was this story made openly public? no, no and again NO!!!
    Nothing changes for the U.S. Army

    Sly

  24. Testing again…

    Is it just me, or does this Gary McKinnon guy look STRIKINGLY similar to Richard Ramirez, the infamous L.A. Serial Killer AKA “Night Stalker”.

    Gary McKinnon:

    Richard Ramirez:

    If they break just c & P……Again, can someone tell me how to refernce a link to words in a post? Thanks.

  25. I’m persistant….

    Is it just me, or does this Gary McKinnon guy look STRIKINGLY similar to Richard Ramirez, the infamous L.A. Serial Killer – AKA “Night Stalker”.

    ” rel=”nofollow”>Gary McKinnon

    ” rel=”nofollow”>Richard Ramirez

  26. SORRY!

    THIS BETTER WORK:

    Is it just me, or does this Gary McKinnon guy look STRIKINGLY similar to Richard Ramirez, the infamous L.A. Serial Killer – AKA “Night Stalker”.

    ” rel=”nofollow”>Gary McKinnon

    ” rel=”nofollow”>Richard Ramirez

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.