Sunday, October 2, 2011

Bible Culture vs Modern Culture - Numbers

     There are many ways in which our culture is different from the culture of the Bible times. This can cause difficulty for us in understanding the Bible. In many cases, we know things that people in the Bible times did not know. In some cases, they knew things that we no longer know.
     One way in which our culture differs from the Bible is in a simple but important aspect of elementary math. In the Bible, they did not have a number zero. In fact, no one made wide use of the number zero until about the 12th century A.D. However, in today's world children are introduced to the number zero in first grade if not before, and we are so comfortable with zero that it is almost impossible for us to think of even simple arithmetic without it. It is also true that math with a zero is vastly superior to math without it, and so we have no motivation to try to think without it - our brain rebels at the attempt. But in Biblical times, there was no number zero.
     Many people are already familiar with one implication of the absence of a zero - the fact that there was no year zero, no 0 A.D. The year 1 A.D. immediately followed the year 1 B.C. This tends to make our math not work like we would think: we would assume that going from 5 B.C. to 5 A.D. can be calculated as 5 - (-5) = 10, but that is not right. The absence of the year zero means that there are nine years between 5 B.C. and 5 A.D., not ten.
     In Biblical Hebrew, a common way of saying "previously" is by saying "yesterday or three days ago" (Gen 31:2, Exod 5:8, etc.). But in this reckoning yesterday is two days ago, so the saying "yesterday or three days ago" can be rendered two or three days ago, with today being day one. You will never read yesterday or two days ago, because two days ago was yesterday. Just remember there was no zero, so they had to count that way. The same thing happens counting time forward. In Exodus 19:10-11, the LORD tells Moses to have the people consecrate themselves "today [day one] and tomorrow [day two]... and be ready on the third day."
     Probably something strange just happened in your mind. The counting backward case where yesterday was two days ago seems so strange that it hurts one's head. But the counting forward example, with tomorrow being the second day, was not strange; we might have even counted the days the same way. Why is that? The answer is that when we use cardinal numbers (three two one), we have a cardinal number zero. But when we use ordinal numbers (third, second, first) we do not have a zero (zeroith?) so suddenly we too do math without a zero, just like they did in Bible times.
     This explains why the Bible says that Jesus rose on the third day, even though He was in the tomb less than 48 hours. Crucifixion day - Friday - was day one, Saturday was day two, and Sunday was the day three. We are comfortable with this wording. The Bible uses the formulation that Jesus was or will be raised on the "third day" 13 times (Matt 16:21, 17:23, 20:19, 27:64, Mark 9:31, 10:34, Luke 9:22, 18:33, 24:7, 24:21, 24:46, Acts 10:40, 1 Cor 15:4). The Bible on eight occasions uses a formulation that counts three days to the resurrection, or says "after three days" (Matt 12:40, 26:61, 27:40, 27:63, Mark 8:31, 14:58, 15:29, John 2:19-20). The two different formulations are used in the same books and even in the mouths of the same people. We today might feel that "on the third day" and "after three days" do not mean the same thing, but this is because we have a cardinal number zero, but not an ordinal zero. In the Bible they do mean the same thing.

Sunday, September 25, 2011

About Those Mammoths

In this article we will address the riddle of the northern mammoths. How could those mammoths survive the cold dark Siberian north? Much of Siberia today is frozen seven months out of the year, and even when it thaws much of it is a bog not favorable for habitation by large animals. And mammoths are (were) very large animals. They eat (ate) a lot, too. In fact, their near relative, the African Bush Elephant, eats more than 500 pounds of green food each day. Elephants are not very efficient eaters - much of what they eat passes through without being digested, and the elephant sleeps only three hours a day, because it needs to devote most of its waking time to food. So how would mammoths get enough food to eat?
Perhaps before we get too far, we should discuss the evidence for mammoths living in the far north. Actually, let's start with just the topic of mammoths living, period. According to Wikipedia, mammoths lived from about 4.8 million years ago until about 4500 years ago, with a few surviving up to 1650 B.C. They were widely dispersed, living not only in the far north, but in locations as diverse as the channel islands of California and in the Mediterranean island of Sardinia. The first question might ought to be why they lived four million years and then died off only in the 0.1% of the time range that includes the present. In other words, how did they live through umpteen ice ages and then die only at the end of the most recent one? The dates alone ought to arouse suspicion from the inquisitive.
Next, we should wonder at the mammoths living in the far north. How far north? Mammoth remains have been found not only in Siberia, but on Wrangle Island, which is north of Siberia in the Arctic ocean - above 71 degrees north latitude - farther north than any portion of Alaska.

The Mammoth pictured above is named Lyuba. She is a young female found frozen in the Siberian permafrost, and estimated to be 40,000 years old. (Actually, she looks pretty good for a 40,000 year old.) So many mammoth tusks have been found in Siberia that it is certain that at one time there was a considerable population there.
So that's the story. Mammoths lived over a broadly dispersed portion of the earth, and especially in the far north. They became extinct by around 1650 B.C., and probably earlier in some places. Now it is easy enough to understand why they became extinct, at least in the far north. The climate in places like Siberia and Wrangel Island is totally incompatible with a large elephant-like creature that needs to eat hundreds of pounds of plant food each day. Of course they became extinct. The hard question isn't why they became extinct, it's how they ever lived there in the first place.

The Genesis Flood and the Climate After the Flood

I believe the answer to the question about the mammoths and the far north can be found in an understanding of the earth's climate in the initial aftermath of the Genesis flood. The first physical cause for the Genesis flood mentioned in the Bible is that "all the fountains of the great deep were broken up" (Genesis 7:11). Rain followed. The fountains of the great deep probably refers to water deep below the earth's surface. There is still today a great deal of water below the earth's surface, and the key point for this discussion is that it is very hot. If the Genesis flood released a substantial amount of this water into the ocean, the ocean water temperature would rise a great deal, and that rise would be worldwide and well mixed (both deep and shallow water would be warm). In fact, many Christian flood geologists who have modeled the flood have trouble with the flood water being too warm. In any case, the ocean water after the flood would be very warm, both shallow and deep, polar and equatorial. Such an ocean would be dramatically different from today's ocean. Because water holds heat so well, the ocean water temperature would take hundreds of years after the flood before it reached anything approaching its current state, where the average ocean water temperature worldwide is only 39 degrees fahrenheit.
How would the warm ocean affect the climate? It would be very different. Although direct sunlight does most of the heating of the atmosphere, the air over the water and near the coast would be abnormally warm all over the world, even in the far north. However, warm moist air in the far north moving inland would result in greatly increased cloud cover and precipitation inland, well away from the coast. In places like the north central U.S. and southern Canada, the increased cloud cover would make the climate much colder, especially in the summer, when the sun wouldn't warm it up as much as it does today. Thus - the ice age. And yet, along the coast of Siberia in close proximity to the warm Arctic Ocean (it is almost hard to write "warm Arctic Ocean"), the warm water would keep the climate temperate, even in the winter. Wrangel Island, north of Siberia, might be a nice place to live. Plant life could flourish, along with the mammoths. One can even imagine Siberian mammoth herds becoming conditioned to migrate north for the winter, since north would bring them closer to the warm ocean. Of course, if they did develop such an instinct it would only hasten their extinction as the climate changed to what it is today.

Thursday, September 15, 2011

Adventures with Carbon-14

Carbon-14 dating, also called radiocarbon dating, is commonly used to date objects containing carbon that are not considered extremely old. For example, the Shroud of Turin was dated to 1260-1390 A.D. using radiocarbon dating.

This is how Carbon-14 (C-14 for short) dating works. The normal atomic isotope of carbon is carbon-12 (C-12). However, nitrogen (nitrogen-15) in the atmosphere receives radiation from the sun, and this radiation causes a very small percentage of the nitrogen to lose a proton, forming C-14. The ratio of C-14 to C-12 is very small, about one to a trillion. Every living thing interacts with the atmosphere, so as long as an animal breathes or a plant lives, that animal or plant also has about one part per trillion of C-14 in every cell. C-14 is radioactive and decays exponentially with a half life of 5730 years. When an animal dies, it no longer breathes, and the C-14 in its body begins to decay. By measuring the ratio of C-14 to C-12, it is possible to determine how long ago the animal died. This process works for plants and animals, and can usually be used to also find the formation date of anything that contains carbon, such as petroleum, coal or diamonds.

Because the half-life is 5730 years, C-14 dating cannot be used to date things that are more than about 100,000 years old. The already tiny percentage of C-14 will have decayed to a percentage too small to be detected. Therefore, scientists will not usually try to date something like a dinosaur bone with C-14, since the conventional timeline has dinosaurs dying out 65 million years ago. The expectation is that if one dated a dinosaur's bone using C-14, no C-14 would be present and the age of the bone would be calculated to be infinite. Now here is where the fun begins. One of the nasty little secrets of C-14 dating is that whenever anything containing carbon is tested, C-14 is always found. When the sample is supposed to be extremely old, like a dinosaur bone, it will contain some C-14 and date to say, 50,000 years old. This produces one kind of problem for young earth creationists, who do not believe the earth is 50,000 old, meaning the date has to be off by a factor of 10 or so. It creates a more serious problem for evolutionists, who expect the dinosaur bone to be more than 65 million years old, meaning the date is off by a factor of more than 1000. What to do with this conundrum? Let's come back to it in a minute. Before we go further we need to discuss dating methods in general.

Dating Methods in General - An Example and Four Assumptions
All dating methods work in essentially the same way: they measure the rate a process operates, then calculate how long that process would take to arrive at the current state from some projected initial state. An example will help. Suppose we saw Chris peeling apples, and noticed that he took one minute to peel one apple. We then looked and saw a barrel of unpeeled apples on his left and a barrel of peeled apples on his right, with ten peeled apples in the right barrel. How long has the Chris been peeling apples? The answer is ten apples divided by one apple per minute, equalling ten minutes. So Chris has been peeling apples for ten minutes. Or has he? Perhaps he has improved his technique, having peeled the first few apples more slowly. Or perhaps he is tired and has slowed down, having peeled the first apples more quickly. We have been making an assumption, the first assumption in any dating method: (1) The rate of the process has remained constant. Here's another point - are we sure we counted the peeled apples correctly? If not, we will get the wrong answer. Therefore, the second assumption in any dating method is that (2) we have accurately measured the current state of the system. Also, what would have happened if just before we looked at Chris, Naomi's cheerleading squad arrived and they all ate some peeled apples? This illustrates the third assumption, (3) we are looking at a closed system, with no external contamination of inputs or outputs. Finally, are we sure that Chris peeled all ten apples? Perhaps Anne peeled eight apples before Chris sat down to peel his first one. This illustrates the fourth assumption: (4) We know what the initial state of the system is.

These four assumptions should be considered when we evaluate any dating method. (1) Has the rate of the process always remained constant? One might suppose with C-14 dating that it has, although we can't prove it beyond all doubt. It at least appears to be constant today even in varieties of temperatures, pressures, etc. However, there are dating methods where we are less confident about the rate. For example, one can calculate the age of the ocean by measuring the rate at which salt is swept into the ocean by erosion, but that rate probably has changed some as earth's climate and geography changed. (2) Have we accurately measured the current state of the system? Of all the assumptions, this is usually the most solid. Certainly with C-14 dating we can expect to get an accurate measurement, barring any incompetence in the labs. However, there are some dating methods where an accurate measurement of the current state of the system is questionable. For example, some models for estimating the age of the universe rely on estimates of the total mass of the universe. Whether we have accurate readings of universal mass is doubtful. (3) The assumption that we have a closed system is often dicey. In fact, when C-14 is present in samples thought to be too old, like a dinosaur bone, the evolutionary explanation will be that the sample has been contaminated, i.e., the system was not closed. (4) Do we know the initial state of the system? For young earth creationists, a 50,000 year old date for a dinosaur bone is still too old. The young earth explanation is that the initial state of the system is not what the C-14 labs believe; the atmosphere when the dinosaur died was not the same as it was today. Instead, there was less C-14 in the atmosphere, and anything that died at that time would date older than it really was.

Some C-14 Dating Results
C-14 dates seem to be pretty reliable going back to 1000 B.C. or so. C-14 accurately dated the Dead Sea Scrolls, scrolls which can be dated in several other ways. These scrolls were written at about the time of Christ. The Bible and Egyptian chronology agree on the date for an invasion of Judah by Pharaoh Shishak (Egyptian: Shoshenq) during the reign of Rehoboam around 925 B.C. C-14 dates at Tel Rehov (Rehov is mentioned in the Egyptian account) seem to match this date. However, moving back before 1000 B.C., problems emerge. Renown archeologist Katherine Kenyon verified that Jericho was destroyed and lay ruined for many years, as the Bible says. However, multiple C-14 tests put its destruction at about 1550 B.C, around 150 years before Joshua got there (my best estimate for the fall of Jericho using a Bible chronology would put it at 1406 B.C.). Similarly, Egyptologists were confident that the date of the eruption of the Thera volcano, the largest volcanic eruption in the Mediterranean in recorded history, was about 1500 B.C. However, C-14 dates pushed it back to a range between 1600-1627 B.C. Notice what has happened here: Recorded history for these two events, near in time to each other, give dates more recent than C-14 dates by 100-150 years. Something has begun to go wrong with the C-14 dates.

Moving back in time to events before this, but which a young earth creationist would place after the flood of Noah, the C-14 dates get older at an exponential rate. Many mammoth bones are frozen in the permafrost of Siberia and a few other locations in the far north. Permafrost must be post-flood. And these Mammoths often date around 12,000 years old or so, with dates ranging from around 40,000 B.C. to as recent as 1700 B.C. Now one wonders how mammoths, which need to ingest a massive amount of green food, can survive in Siberia, which is frozen for seven months a year. Of course they can't - they would go extinct. Yet somehow they once did, and during the ice age!? but that is a subject for another paper. For now let us just note that Mammoth dates and similar post-flood artifacts often date between 4000-40,000 years old.

Finally, what about samples which evolutionists would state are millions of years old, and which creationists would claim are pre-flood? As I mentioned before, it's a dirty little secret that all samples containing carbon also have some C-14, implying an age less than 100,000 years old. These samples have included dinosaur bones, diamonds, coal, and petroleum. At first glance, these samples seemed to measure with random very old but not infinite ages, ages that no one believes, so they have not until recently been analyzed systematically. Recently though, Rick Sanders wrote an article in the Creation Research Society Quarterly (Winter 2011 edition) that showed that the ages of these samples follow the lognormal model, with a mean age of 51,155 years and a standard deviation of 6997 years. The results are meaningful. They imply a "C-14 flood date" of 51,155 years before present.

So what does all this mean? I suggest that prior to the flood, the C-14 concentration in the atmosphere was only about one tenth of its present concentration. There can be several reasons why this may have been so - perhaps less radiation from the sun due to a slightly different atmosphere, more carbon in the biosphere, etc. This would calibrate the C-14 flood date from 51,155 years before present to a date about ten times more recent than that. After the flood, C-14 concentration in the atmosphere increased over a period of around a thousand years, reaching its modern equilibrium some time prior to 1000 B.C. I believe it was not quite at equilibrium at the time of the Thera eruption or the destruction of Jericho, explaining why those C-14 dates are a little too old. In between the flood and Jericho there were mammoths, whose bones have dates spanning the time period between the two.

I believe this is an area that would benefit from more study.

Sunday, August 28, 2011

Living Fossils?

What would the world think if we suddenly discovered a living dinosaur? I can imagine there would be shock, confusion, and then a negative reaction against the scientific establishment, which assured us that dinosaurs became extinct 65 million years ago. I doubt we will ever find a living dinosaur. However, we have discovered a number of species which were thought to have become extinct with or even before the time of dinosaurs. This ought to call into question not only the theory of evolution, but the supposed great ages for the earth itself.

Let us introduce a few of these animals. The most famous example is a fish called the coelacanth. It was presumed to have died off 65 million years ago with the dinosaurs, but was found in 1938 off the coast of South Africa. These fish live today along the shoreline of the Indian Ocean. It has an unusual two-lobed tail.

The discovery of a fish thought to be extinct for so long is more than just an "oops, my bad" moment for evolutionists. A fish reaches an age of reproductive maturity in less than two years. Therefore, the living coelacanth is, according to the evolutionary timeline, 30 million generations descended from the 65 million year old fossil coelacanth that evolutionists see in the fossil record. That means 30 million generations and it didn't evolve at all. The ancestors of humans, according to the evolutionary timeline, were an unrecognizable mammal 65 million years ago, and that was a lot less than 30 million generations. There is another problem for the evolutionists. There are many fossil coelacanths (search "fossil coelacanths" on google images to see a fair sample). Yet somehow, the story goes, we have recovered many fossil coelacanths of more than 65 million years in age, but no fossil coelacanths that are less than 65 million years old. This is so implausible that it should call into question the existence of the 65 million years.

If the coelacanth were the only example of this kind, that would be one thing, but there are more. Wikipedia lists under "Lazarus taxon" 12 different plants and animals known previously only from the fossil record, then discovered alive. A hat-shaped clam known as monoplacophora was originally thought to have gone extinct during the Devonian period (370 million years ago, by the conventional timeline) but discovered off Costa Rico in 1952. For evolutionists, this is even worse than the fish, because the years are greater, and the fossil record is full of clams.

Thursday, December 16, 2010

Stuxnet

Executive Summary:
1. Stuxnet is the most advanced instance of computer malware that is publicly known.
2. Stuxnet was designed to attack the Iranian nuclear program.
3. Stuxnet was developed by a nation state as opposed to an individual hacker, and the most likely nation state is Israel.
4. Stuxnet has likely had success in damaging the Iranian nuclear program, but the full extent of the damage is not yet known.

Introduction:
I have wanted to write about stuxnet for some time. It is hard to find any single article that fully describes the situation, since people who write on geopolitics usually are not experts on computer viruses, and experts on computer viruses are not usually experts on nuclear weapons programs. I am a computer professional conversant with geopolitics, but I don't know much about nuclear weapons programs. In this article, I will try to distinguish between what I know, what can be surmised, and what can only be guessed.

Timeline of Events:
1. On May 9, 1979, Habib Elghanian, a Jewish Iranian businessman, was executed by the new Islamic leadership in Iran for spying for Israel. The execution shocked the Iranian Jewish community and led to large scale Jewish emigration from Iran. The date may be significant, since stuxnet uses the code 19790509 on a Windows registry key to indicate its presence on a computer.
2. Stuxnet development probably began in 2007.
3. One instance of stuxnet executable code has a date of January 2009. Microsoft estimates that this may have been when it was first deployed, though other experts from Symantec estimate that the first deployment was in June 2009.
4. In May 2009, Iran has 4756 operating centrifuges enriching uranium at their Natanz nuclear facility. In August, the number of operating centrifuges drops to 4592, then drops further to 3936 in November. These drops take place despite Iran installing an increased number of centrifuges during this time period. Clearly, there was some systemic problem with the centrifuges.
5. In July 2009, wikileaks announces that there has been a serious nuclear incident at Natanz.
6. On June 16, 2010, stuxnet is detected by VirusBlokAda, a virus detection company. On the same day, two web sites in Malaysia and Denmark, www.mypremierfootball.com and www.todaysfutbol.com, shut down. The web sites were acting as mother ships to monitor the progress of stuxnet and to provide periodic updates to it.
7. On July 16 and July 22, 2010, Verisign Corporation revokes two public encryption keys that were stolen and used by stuxnet.
8. On August 22, 2010, well behind schedule, the Bushehr nuclear reactor is commissioned, though it does not go online.
9. On September 26, 2010, Iran's State News Agency announces that its Bushehr nuclear reactor had been infected by stuxnet, though they deny any damage was done. The Bushehr reactor is not yet online as of the date of this writing (December 20, 2010).
10. On November 16, 2010, Iran shut down all its centrifuges at the Natanz nuclear facility, according to the International Atomic Energy Agency. They were restarted several days later.
11. On November 30, 2010, Iranian President Mahmoud Ahmadenejad says that stuxnet had been detected and controlled in Iran.
12. On December 9, 2010, Eric Byres of Tofino Industrial Security says that his site is getting a tremendous number of inquiries from Iran, and indicates his belief that stuxnet is still not under control in Iran.
13. On December 14, 2010, Microsoft releases a fix for the last of the four zero-day security vulnerabilities exploited by stuxnet.
14. On June 24, 2012, stuxnet is designed to automatically shut itself down.

Part 1 - Overview of the Stuxnet Software:
A full understanding of the stuxnet software itself was not possible until November 2010, because stuxnet, as detected, consisted of a large (600 kb) portion of binary executable code. It is painstaking to reverse engineer executable code into source code - a process roughly akin to putting toothpaste back into a tube. For purposes of this discussion, I have chosen to distinguish between the carrier portion of stuxnet and the payload, or weapon, of stuxnet. Both are unprecedented in their scope and complexity.

The carrier portion of stuxnet exploits security vulnerabilities in the Microsoft Windows operating system to spread on Windows computers. In a typical scenario, stuxnet would reside on an infected USB device like a flash drive. When the flash drive is plugged into a computer with the Windows operating system, Stuxnet uses a previously unknown vulnerability to load itself onto the computer without the user's knowledge. It then uses two additional previously unknown vulnerabilities to give itself administrative privileges, allowing it to do anything on the computer that it wants. It installs a windows "rootkit" to hide itself from the user - if you looked for a stuxnet file you wouldn't see it. It then uses a fourth previously unknown vulnerability to copy itself to all other computers connected to the same network printer, if the computer is part of a network.

Before we go further, we should point out that the use of four previously unknown vulnerabilities is unprecedented. Unknown vulnerabilities, also called "zero day" vulnerabilities, are like nuggets of gold to a hacker, since each one can be used for a different virus. No previous computer virus uses four.

Back to stuxnet - if the computer is connected to the internet, stuxnet signals two mother ship web sites in Malaysia and Denmark and reports the computer name, the Windows version, the network group name (if the computer is part of a network), the IP addresses of all computers on the network, and whether industrial control systems software is installed or not. The mother ships can send updates to stuxnet, thereby allowing updated versions to replace older versions. Stuxnet also uses a peer to peer update capability. If two versions of stuxnet meet, they compare and copy such that the most recent version is stored in both places. Four different versions of stuxnet have been found.

Stuxnet also installs two drivers in the Windows operating system. One of the drivers masks the malware while the second drops encrypted blobs of code into memory. Because drivers can be dangerous, the Windows operating system requires that drivers be digitally signed with encryption keys that Windows can recognize. Stuxnet makes use of two stolen encryption keys to do this. One was stolen from JMicron and the other from RealTek, both of which are in the same office park in Taiwan. Encryption keys cannot be stolen by hacking; this requires the breaking and entering type of theft from a high security facility.

Notable is the fact that unlike almost all viruses, stuxnet was designed to carefully limit the way it is spread. Each flash drive has a counter such that it only allows three infections per stick. Stuxnet only attempts to spread across an internal network for 21 days, and most importantly, it does not spread itself across the internet at all. The result is that stuxnet spread outside its target environment very slowly, and was able to exist for more than a year without being detected. Stuxnet is designed to shut down on June 24, 2012. The authors apparently believed that by that date it would be detected and its target disinfected.

Stuxnet was designed to deploy its payload very precisely. If stuxnet did not find itself on a Windows computer connected to a Siemens S7-315-2DP or Siemens S7-417-2DP computer running industrial control software, stuxnet does nothing (except spread as described above). Therefore, almost everyone in the world infected by stuxnet never knew and never experienced any harm. Siemens is a major German engineering company that makes computers for, among other things, controlling industrial equipment. However, stuxnet further narrowed its target to Siemens computers that came from one of two vendors, a vendor in Vacon, Finland, or Fararo Paya, Iran. Finally, the Siemens computer must be running a frequency controller operating at a speed between 807-1210 Hz (something spinning at 60,000 revolutions per minute, which is unusually fast). Only if all of these conditions are met does stuxnet attack.

Stuxnet is the first known instance of computer malware to attack industrial control systems. Stuxnet subverts a software library allowing communication between a Windows PC and a Siemens computer connected to it. The stuxnet payload, or attack module, runs on the Siemens computer. It consists of 15,000 lines of code written in STL (Statement List) code, which is similar to an assembly programming language. The attack module has two "warheads", using two different logic paths, one designed to attack the S7-315 and the second to design the S7-417.

For the S7-315, the attack is done in the following manner. For a frequency controller operating between 807 and 1210 Hz, stuxnet counts events passively for a time period that is a minimum of 12 days. Then, in a process that takes between 15 and 50 minutes, it changes the speed to 1410 hz, then to 2 Hz, then to 1064 Hz, then repeats the process between 23 and 32 times (exact details vary depending on which vendor sold the S7-315). This could have the effect of damaging or destroying whatever equipment is rotating - though not right away. After the 15 minute takeover sequence, stuxnet goes back to a passive counting mode for at least 26 days. The built in delay could throw the troubleshooters of the system off track - hardware that fails after a long time would usually imply a subtle manufacturing defect.

The S7-417 attack takes about seven minutes. It changes the rotation frequency in a manner similar to the S7-315 attack, but it is more complex. The S7-417 attack code assumes that the frequency of rotation will be closely and constantly monitored by a human operator, so before beginning the attack it records data from the computer, then plays it back to the operator during the attack.

Stuxnet was also designed to hide itself on the Siemens computer, and if it is cleansed off the Windows computer, the Siemens computer can reinfect the Windows computer to which it is connected.

Symantec Corporation has monitored computers that try to connect to the stuxnet mother ship web sites, and at the time of this writing, about 100,000 internet-connected computers have been infected, 58% of them in Iran. Siemens reports that 14 factories unrelated to the Iranian nuclear program have been infected, though none have reported any damage. This would seem to indicate that the stuxnet authors were effective in minimizing any collateral damage from the attack. Note that the Iranian nuclear facilities are probably air-gapped, that is, not connected to the internet. Stuxnet would probably only reach those facilities via a USB drive.

For further information on the stuxnet software itself, I recommend reading the w32.stuxnet dossier written by the Symantec engineers who reverse engineered the software, or the blog by Cybersecurity expert Ralph Langner at www.langner.com.

Implications of the Stuxnet Software:
1. Stuxnet was designed to attack two high value industrial targets and to leave all other infected computers unharmed.
2. The stuxnet creators had detailed technical information on their target. For the Iranian nuclear weapons program, this would require spies or some sort of industrial espionage.
3. The stuxnet creators had the aid of agents who could commit brick and mortar type theft, to steal the two encryption keys.
4. The size of the stuxnet effort, 15,000 lines of code just for the payload, would require around 6-10 programmers working for at least a year. A support team of quality assurance, testing, management, etc. would also likely be required. I would estimate it took about 3 million dollars to develop stuxnet, not including the espionage aspects of the program. Microsoft estimated the task at 10,000 man-days, which is a bit higher. If the program was developed by the Israeli Army, as I will surmise later, it may have been less, as soldier salaries do not match those of software professionals. In any event, I believe everyone would agree with Ralph Langner that the total cost of the software did not exceed $10 million.
5. To assist in testing the software, a lab would need to be set up with Siemens and Windows computers and some kind of test hardware.
6. The creators of the program intended to closely monitor its spread, and to supply updates to the program as they saw fit.
7. The creators of the program knew stuxnet would eventually be detected, and took steps (instantly closing the mother ship web sites) to erase their trail.
8. The stuxnet creators had assistance from some party in deploying the virus initially in Iran. The reader can imagine multiple ways this could have been done using USB drives.

Part 2 - The Iranian Nuclear Program:
Stuxnet was apparently designed to target two aspects of the Iranian nuclear weapons program: (1) The uranium enrichment processing at the Natanz nuclear facility, and (2) The Bushehr nuclear power plant. The Natanz nuclear facility is a hardened underground site of 100,000 square meters. It contains multiple buildings and 9000 centrifuges, at last report. Much of the site is deep underground so as to make it difficult to attack by conventional methods. The Bushehr nuclear power plant can be used to produce electricity for the Iranian electrical grid. However, nuclear power plants also produce plutonium as a by-product, and plutonium can be used to make a nuclear weapon.

To describe the nature of the stuxnet attack, we first need to describe certain aspects of a nuclear weapons program.

Uranium ore when it is mined consists primarily of two isotopes, uranium-238 and uranium-235. The concentrations are very uneven, at 99% uranium-238 and 0.7% uranium-235. To be useful for producing electricity, uranium-235 must be 3-5% of the total. To make a weapon, the uranium-235 must make up 80% of the total. To reach these totals, the uranium must be enriched. This is one of the most difficult steps in a nuclear weapons program. A common means of enriching uranium and the means used by Iran is the centrifuge method.

In the centrifuge method, uranium is first dissolved in hydrofluoric acid to produce uranium hexafluoride gas. The gas is injected into a centrifuge that spins at extremely high rates. The slight difference in mass between the isotopes causes the heavier uranium 238 to tend to collect at the sides of the centrifuge and uranium 235 to collect in the middle. The gas in the center is extracted and will be slightly enriched, with an increased percentage of uranium-235. The process is repeated until the desired levels are reached, using a cascade set of connected centrifuges. The fully enriched gas will be added to calcium, which reacts with the fluoride to produce a salt and uranium back in mineral form. The reader may correctly perceive that this is a complex process. Gas diffuses, so if a centrifuge stops spinning, it will all quickly remix and become "unenriched." The process is painstakingly slow. 1500 centrifuges running for months can produce 20 kg of uranium-235, which is enough for one nuclear weapon. The centrifuges are about seven feet in height and a little over a foot in diameter. They must be light, strong and well-balanced, with high speed bearings, usually magnetic, to reduce friction. They must cycle at around 1000 hz, or 1000 times per second. Iran has reported creating initial batches of 20% uranium-235 with their centrifuges at Natanz.

Enter stuxnet. Stuxnet could have been designed to command the centrifuges to cycle at any speed whatsoever, say 100,000 Hz, which would have immediately broken the centrifuge, but instead the attack is more subtle. It increases the speed to 1410 Hz, above the rate at which the centrifuge was designed to operate, but not so fast as to immediately destroy it. I surmise that this might cause the centrifuge to fail more quickly than its expected design life. Stuxnet then slows the centrifuge to 2 hz, a snail's pace. The uranium hexafluoride gas, being a gas, would have little friction with the slow moving centrifuge and would quickly diffuse so that the uranium became unenriched - a month's worth of work on the centrifuge wasted. The end result at Natanz would be that the uranium enrichment process was not working and the centrifuges were breaking down. If I worked at the facility, I would have soon suspected sabotage, but I would have suspected first that someone was corrupting the centrifuge hardware. I don't know what the Iranians thought. The Iranians never did discover the problem - stuxnet, when it was detected, was detected by a computer virus detection company in Belarus.

The Bushehr nuclear power plant, like all power plants, uses a large turbine to generate electricity. The main turbine in the Bushehr plant is 150 feet in length. It is controlled by a Siemens S7-417-2DP controller (although this ought to be secret, it as has been verified by internet search of Russian Cyrillic documents). The turbine is a model K-1000-60/3000-3. Stuxnet will take over the turbine controller for 7 minutes. In order to fool the operators, before taking over, stuxnet records data from the controller and plays that data back to the user while the turbine is being manipulated. Noteworthy is that if stuxnet did attack Bushehr, by attacking the turbine, it attacked a part of the plant that is not intrinsically nuclear.

Part 3 - Identifying the Creator of Stuxnet
Stuxnet was too large, complex and costly a project for an individual hacker or even a small team of amateurs - stuxnet was the product of a nation-state entity that wished to disrupt the Iranian nuclear weapons program. But which nation?

There is no reason to overthink this. Israel is the only country that has ever acted forcefully to prevent nuclear proliferation, and they have done it twice. On June 7, 1981, the Israeli Air Force bombed the Iraqi nuclear reactor at Osirak. On September 6, 2007, The Israeli Air Force bombed a Syrian nuclear reactor. Israeli officials have repeatedly indicated that the prospect of Iran possessing nuclear weapons was unacceptable. However, a conventional attack against Iran's nuclear weapons would be much more dangerous and difficult to accomplish than the attacks on Iraq and Syria. It is most likely that Israel did choose to take action against Iran, just in a way that was not as dangerous and not likely to start a war. The stuxnet registry key code 19790509 certainly points to Israel. Although a different nation could have planted that code, it seems more likely that the Israelis chose to leave a very subtle calling card.

There are other nations that may have been motivated to stop Iran - the U.S., a number of Arab states, and perhaps a few European states. However, most Arab states would have had difficulty pulling it off. The U.S. could have done it, but an effort such as stuxnet would have required approval at the Presidential level, and the U.S. would be filled with reservations about such a hostile action.

Israel, on the other hand, would have no reservations. If they held a cabinet vote on this in Israel, the cabinet would have voted unanimously for massive sabotage of the Iranian nuclear program. Furthermore, if I am wrong and this was not an Israeli operation, I'm sure the Israeli government is now asking "Why didn't WE do this?"

Within the Israeli army there is a large unit of several thousand soldiers called the Signal Intelligence Corps, or Unit 8200. The identity of the Brigadier General in command is secret. Unit 8200 specializes in electronics, computers, and the like. There are unconfirmed reports that Unit 8200 deactivated the Syrian Air Defense radar during the 2007 Israeli attack on the Syrian nuclear facility. I suspect that this unit within the Israeli Army developed stuxnet. Unit 8200 may have been assisted by Mossad, the Israeli spy agency, to obtain design schematics from the Iranian nuclear program, and to plant the virus in Iran.

Part 4 - The Effects of Stuxnet
How successful was stuxnet in harming the Iranian nuclear program? The drop in the number of operational centrifuges at Natanz in 2009, the 2009 wikileaks report of a series nuclear incident there, and the complete shutdown of all centrifuges in November 2010 would seem to indicate that stuxnet hit that target. The Bushehr reactor remains off-line long after it was scheduled to be online. However, delays on major industrial projects are not unusual, and I can't venture an educated guess on what has happened to Bushehr.

In conclusion, stuxnet appears to be a first of its kind computer software weapon. It is possible that the damage done, particularly at Natanz, was more than could have been achieved with a typical bombs and missile attack. Ralph Langner, one of the cybersecurity experts who has reverse engineered the stuxnet code, believes stuxnet was "like the arrival of an F35 into a World War 1 battlefield", and may have set back the Iranian nuclear program by two years.

One more thing - the next version of Stuxnet is likely underway.

Saturday, October 9, 2010

The U.S. National Debt

It’s hard to think clearly about our government debt problem: the national debt, the annual budget deficit and future entitlement obligations. On the one hand, the debt problem is so unbelievably huge that we can’t even get our mind around a problem so big. On the other hand, it is not something that we “feel” in any sense in our day to day lives, so we don’t really have to think about it. This write-up is an attempt to reconcile those two different impulses.

First, to quantify it: At the time of this writing (10:00 p.m. on September 25, 2010) the national debt is $13.507 trillion dollars according to usdebtclock.org. If you are reading this note tomorrow it will be more. This number is increasing a little over $100 billion per month, which is about the run rate of the annual budget deficit of $1.360 trillion. This debt comes to $43,524 per citizen, so our family of four has a $174k share. This is a bit worse than it sounds, since many families of four could handle an additional $174k debt, but we have to remember that the analogy is imperfect, since this $174 k has to be paid out from our taxes, not from our salaries.

To put it a different way, the government’s annual revenue is $2.132 trillion, so the debt is six times revenue, and the deficit is 60% above revenue. The comparable analogy would be if a family with $100,000 annual income was spending $160,000 annually and was $600,000 in debt. But it’s here that analogies break down. Any family in a situation like that just described would be in great distress and probably bankrupt, but for the U.S. government, it’s not like that at all. Let’s presume that our debt-ridden family could continue to borrow at interest rates averaging around 2%, and had an unlimited line of credit to continue to borrow all it needed to fund its additional spending. Of course that could never happen for a normal family, but that is exactly the situation with the government.

This is the reason that we don’t “feel” the debt problem. It is not hurting us at all, since we can borrow all we need, and interest rates are so low that interest payments are not killing us. Interest payments are 15% of revenues, but no one is giving us any grief about borrowing all we need to cover those payments. Now I realize the debt is hurting us a little in indirect ways: sometimes a worthwhile program doesn’t get funded due to a surge in concern over the deficit, and economists are concerned that government borrowing has a certain crowding out affect that may restrict some private borrowing. However, for the most part, the economy continues just fine and we don’t really feel the debt.

The problem is that this process cannot continue indefinitely. It is a mathematical certainty. Eventually, we would soak up all the savings in the world and there would be nothing left to borrow. Or if interest rates increase, our interest payments will exceed our ability to borrow to cover them. Of course, it will never get quite that far. More likely is something akin to what happened to Greece this spring, when their interest rates rose to 20% suddenly, they had bills come due, and they couldn’t pay, so they got bailed out. We will not get bailed out because we are too big and no one can do it. Suddenly, we will have to live within our means, and when that happens, the pain will be almost unimaginable. All government programs would need to be cut about in half, including the entitlements like social security. It’s possible that this will occur along with inflation (though I don’t see inflation on the horizon yet), but the effect will be the same; inflation will just warp the way money gets distributed, with some people hurt more and others less.

Some folks have written that our debt situation is even worse, because they look at U.S. government commitments to make payments on programs in the future. For example, in 2030 Medicare will cost a bunch more money. I have chosen not to factor that into this analysis. If the government can’t pay somebody a promised benefit in 2030, it just won’t. They’ll change the law so that they don’t have to.

One final note – I believe the crunch will hit Japan before it hits the U.S. Their debt situation is worse than ours. They have been able to get away with it for a long time because they initially had a high national savings rate and they were able to export into a booming global economy. Neither of those factors is really in play any more, their debt is worse than ours, and their demographics are worse too. Japan will also be too big to bail out. There are other European nations that may be up to bat before Japan in the national debt baseball game, but I doubt the game will go on for too terribly much longer – it won’t be years and years.

The U.S. National Debt

It’s hard to think clearly about our government debt problem: the national debt, the annual budget deficit and future entitlement obligations. On the one hand, the debt problem is so unbelievably huge that we can’t even get our mind around a problem so big. On the other hand, it is not something that we “feel” in any sense in our day to day lives, so we don’t really have to think about it. This write-up is an attempt to reconcile those two different impulses.

First, to quantify it: At the time of this writing (10:00 p.m. on September 25, 2010) the national debt is $13.507 trillion dollars according to usdebtclock.org. If you are reading this note tomorrow it will be more. This number is increasing a little over $100 billion per month, which is about the run rate of the annual budget deficit of $1.360 trillion. This debt comes to $43,524 per citizen, so our family of four has a $174k share. This is a bit worse than it sounds, since many families of four could handle an additional $174k debt, but we have to remember that the analogy is imperfect, since this $174 k has to be paid out from our taxes, not from our salaries.

To put it a different way, the government’s annual revenue is $2.132 trillion, so the debt is six times revenue, and the deficit is 60% above revenue. The comparable analogy would be if a family with $100,000 annual income was spending $160,000 annually and was $600,000 in debt. But it’s here that analogies break down. Any family in a situation like that just described would be in great distress and probably bankrupt, but for the U.S. government, it’s not like that at all. Let’s presume that our debt-ridden family could continue to borrow at interest rates averaging around 2%, and had an unlimited line of credit to continue to borrow all it needed to fund its additional spending. Of course that could never happen for a normal family, but that is exactly the situation with the government.

This is the reason that we don’t “feel” the debt problem. It is not hurting us at all, since we can borrow all we need, and interest rates are so low that interest payments are not killing us. Interest payments are 15% of revenues, but no one is giving us any grief about borrowing all we need to cover those payments. Now I realize the debt is hurting us a little in indirect ways: sometimes a worthwhile program doesn’t get funded due to a surge in concern over the deficit, and economists are concerned that government borrowing has a certain crowding out affect that may restrict some private borrowing. However, for the most part, the economy continues just fine and we don’t really feel the debt.

The problem is that this process cannot continue indefinitely. It is a mathematical certainty. Eventually, we would soak up all the savings in the world and there would be nothing left to borrow. Or if interest rates increase, our interest payments will exceed our ability to borrow to cover them. Of course, it will never get quite that far. More likely is something akin to what happened to Greece this spring, when their interest rates rose to 20% suddenly, they had bills come due, and they couldn’t pay, so they got bailed out. We will not get bailed out because we are too big and no one can do it. Suddenly, we will have to live within our means, and when that happens, the pain will be almost unimaginable. All government programs would need to be cut about in half, including the entitlements like social security. It’s possible that this will occur along with inflation (though I don’t see inflation on the horizon yet), but the effect will be the same; inflation will just warp the way money gets distributed, with some people hurt more and others less.

Some folks have written that our debt situation is even worse, because they look at U.S. government commitments to make payments on programs in the future. For example, in 2030 Medicare will cost a bunch more money. I have chosen not to factor that into this analysis. If the government can’t pay somebody a promised benefit in 2030, it just won’t. They’ll change the law so that they don’t have to.

One final note – I believe the crunch will hit Japan before it hits the U.S. Their debt situation is worse than ours. They have been able to get away with it for a long time because they initially had a high national savings rate and they were able to export into a booming global economy. Neither of those factors is really in play any more, their debt is worse than ours, and their demographics are worse too. Japan will also be too big to bail out. There are other European nations that may be up to bat before Japan in the national debt baseball game, but I doubt the game will go on for too terribly much longer – it won’t be years and years.