From The Writer's Desk: Secret Electronic Wars?

Join Our Community of Science Lovers!

This article was published in Scientific American’s former blog network and reflects the views of the author, not necessarily those of Scientific American


In the series, "From The Writer's Desk," I'll describe what I do for a living as a writer and ideas I have for advancing my craft.

Today I have a story out on a secret war that might have taken place for years in the embedded computers found within the devices that make up the backbone of the infrastructures of our nations and corporations. And there's so much more to the story than might have comfortably fit into what ran, which I'll talk about here.

So as background, scientists at Columbia earlier showed they could fairly easily to hack into these embedded computers and use them as backdoors to infiltrate personal computers -- for instance, a printer could easily get compromised by an infected document file.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


The threat is potentially huge -- at least a fifth of all embedded computers accessible online still have their factory default passwords, meaning just about anyone can waltz in and compromise them. Now researchers at Columbia have developed software they call "symbiotes" that might be able to not only detect and prevent online attacks on embedded computers, but also help reveal how long they might have been going on under our noses. (You can read the online story here, and the print version here.)

So it's a pretty fun story. A little known threat, potentially very high stakes, a potential solution to the problem, and the hint of an unknown history. The thing about journalism -- or at least, in my mind, responsible journalism -- is that it's about what you can prove, not about all of what you might know or think you might know. As such, there are a lot of anecdotes and speculation connected with this research that I didn't think belonged in my story, but that I think it's all right to discuss and speculate about informally on my blog.

First off, there was a great anecdote about how the researcher Ang Cui met with a military base and told them about their online vulnerabilities. They checked about a month later, but the vulnerabilities were still there. When Ang asked them if they knew the vulnerabilities were still up, the officer he asked just raised an eyebrow.

So yes, the vulnerabilities were still there. They apparently served as what in hacker parlance is known as a honeypot — systems set up to record enemy attacks to learn more about intruder tactics.

Good luck trying to confirm the identity of the base or the fact that vulnerabilities were left out as bait for hackers. As such, an anecdote without confirmation is just hearsay, which is why I didn't put it into the story.

An intriguing, disturbing line of conjecture that came up when I was mulling this story over is why certain nations remain so vulnerable to this line of attack. For instance, South Korea, one of the most wired countries on the planet, hasn't patched many of these vulnerabilities yet. Given how they have a mortal enemy directly to their north, one would think they might put it on their to-do list, or how allies such as the United States might quietly tell them their fly was essentially open, especially given that an attack on South Korea might inadvertently or intentionally damage the United States as well.

What if certain vulnerabilities are intentionally being left open as giant honeypots? Defenders want to collect as much data on possible attacks as possible, so honeypots are useful for that purpose. Still, it seems like there'd be massive public outcry if so much infrastructure was intentionally left vulnerable just to collect intelligence, raising thoughts of popular ideas regarding the Coventry Blitz claiming that Churchill left Coventry burn during World War II to protect intelligence about the Enigma cypher machine.

I'm not really sure what's the worse possibility -- that countries are intentionally being left vulnerable to learn more about intruders, or that countries are unintentionally being left vulnerable out of sheer ignorance.

You can email me regarding From The Writer's Desk at toohardforscience@gmail.com.

Charles Q. Choi is a frequent contributor to Scientific American. His work has also appeared in The New York Times, Science, Nature, Wired, and LiveScience, among others. In his spare time, he has traveled to all seven continents.

More by Charles Q. Choi

Subscribe to Support Independent Journalism

Great science journalism requires human expertise, time, effort and creativity. And it costs money. That’s why I and the journalists here at Scientific American hope you’ll join our community.

When you subscribe, you are supporting staff and freelance journalists who are passionate about telling science stories that are true, important and compelling. Our editors and reporters are often experts in their fields, which means they understand the nuances of big discoveries and can untangle the breakthroughs from the hype. With a subscription, you are also supporting rigorous fact-checking to ensure the words we publish are precise and accurate. And you’re supporting original illustrations, graphics and photos that bring you closer to an advanced laboratory, an ice sheet in Antarctica or a space mission in orbit. You’re helping us craft other types of high-quality journalism as well: Our newsletters are carefully written, edited and curated by staffers you have or will come to know and love. Our Science Quickly podcast is based on original reporting, collaboration with editors and scientists and exacting production.

Subscriptions keep this engine running so we can continue to deliver thoughtful, rigorous and independent science journalism to you. In an era of viral misinformation, this work is crucial. If you value what we do, I hope you’ll consider joining us as a subscriber

Thank you,

Jeanna Bryner, Editor in Chief, Scientific American

Subscribe