7 Years Later, Emergency Alert Systems Still Unpatched, Vulnerable (securityledger.com) 24
chicksdaddy writes: The Security Ledger is reporting that more than 50 Emergency Alert System (EAS) devices made by Monroe Electronics (now Digital Alert Systems) are un-patched and accessible from the public Internet, seven years after security researchers alerted the public about security flaws in the devices. More than 50 EAS deployments across the United States still use a shared SSH key, a security vulnerability first discovered and reported by IOActive in 2013, according to a warning posted by the security researcher Shawn Merdinger on January 19, seven years after the initial vulnerability report was issued.
Security Ledger viewed the exposed web interfaces for Monroe/Digital Alerts Systems EAS hardware used by two FM broadcasters in Texas and an exposed EAS belonging to a broadband cable provider in North Carolina. Also publicly accessible: EAS systems for two stations (FM and AM) serving the Island of Hawaii. Residents there received a false EAS alert about an incoming ICBM in 2018. That incident was found to be the result of human error but prompted the FCC to issue new guidance about securing EAS systems. Digital Alert Systems said it is aware of the problem and is contacting the customers whose gear is exposed. However, a search using the Shodan search engine suggests that few have taken steps to remove their EAS systems from the public Internet in the past week. Security Ledger is withholding the names of the broadcasters whose EAS systems were exposed for security reasons. None of the stations contacted for the story was able to provide comment prior to publication.
Security Ledger viewed the exposed web interfaces for Monroe/Digital Alerts Systems EAS hardware used by two FM broadcasters in Texas and an exposed EAS belonging to a broadband cable provider in North Carolina. Also publicly accessible: EAS systems for two stations (FM and AM) serving the Island of Hawaii. Residents there received a false EAS alert about an incoming ICBM in 2018. That incident was found to be the result of human error but prompted the FCC to issue new guidance about securing EAS systems. Digital Alert Systems said it is aware of the problem and is contacting the customers whose gear is exposed. However, a search using the Shodan search engine suggests that few have taken steps to remove their EAS systems from the public Internet in the past week. Security Ledger is withholding the names of the broadcasters whose EAS systems were exposed for security reasons. None of the stations contacted for the story was able to provide comment prior to publication.
Danger to all viewers... (Score:3)
EAS is the interruption protocol that replaced EAS allowing takeover of an unmanned station (AM, FM or TV) by another in the event of an "emergency" situation. This is the series of modem tones you hear when they test it. The problem is there's not enough security or authentication to verify who's broadcasting, so nearly any program can be superimposed on any station with the takeover of just one. This should be unplugged.
Re:Danger to all viewers... (Score:4, Insightful)
Somehow, I feel like if somebody finds a way to send out zombie attack warnings on a daily basis for a week, the problem will take care of itself.
Re: (Score:2)
Indeed, they'd track the person down and arrest them in less time than that. "Problem solved."
No. Not that easy.
Re: (Score:2)
Only if that person is foolish enough to mess with the same station twice and doesn't use adequate layers of VPN to mask the source of the attack.
Re: (Score:2)
No. This would not just be the FBI investigating, they would have tips from the NSA, DIA, etc.
Re: Danger to all viewers... (Score:1)
Adequate layers of VPN? Tell me. How many layers in your opinion are adequate?
Re: (Score:2)
One. You only need a VPN that's been court tested to keep no logs.
Re: (Score:2)
Got a reference?
Re: (Score:2)
They all keep logs.
They have to - because you're only allowed a limited number of connections to their service. So they have to log your connection.
Now, they can destroy that log entry the moment you log out, so you should continuously be making and breaking the VPN connection. And you should also rotate which servers you use - choosing to use ones where there is at least another person on it at the same time which mixes your traffic in with
Re: (Score:2)
Re: (Score:2)
It is a good argument, but freaking people out when it misfires seems to be the only real-world use so far.
It was put in place to warn people in the event of a nuclear war, because the leaders are Deists and they want to have time to pray before we all die.
Re: (Score:2)
Yeah, good point. You really need a user-tunable setting, like in an IDS, where you can choose to filter out all the noise, so on a sliding scale of "One of the Kardashians just sneezed" through to "NUCLEAR WAR IS ACTUALLY STARTING RIGHT NOW, THAT STREAK IN THE SKY IS THE INCOMING WARHEAD" I'd set it more towards the latter than the former.
I live outside the US where luckily the govt. is a bit more sensible, so far I've only ever had one alert which was a tsunami warning, that's about the level of severi
Re: (Score:2)
That's exactly what I do when it goes off. I step outside and look at the sky to see if I'm about to die. So far, not. But I've never been happy to hear the damn thing.
Now, the one they broadcast on weather band radio, that one is really useful, I bring it with me when I visit the coast and if there is a high wind warning, it tells me. And if that big tsunami ever happens, the first alerts are going to be on the weather radio, not the other one.
Two different issues (Score:1)
It should not have been in the article.
The problem is not the alert system (Score:1)
This article is symptomatic of the state of affair in public debate.
The problem is that we have a lot of doomsday machines which can be triggered inadvertently or through actions of escalation where aggressive actors lose control of the situation.
The major culprit is the US who is constantly playing russian roulette while at the same time adding bullets to the revolver. Dan Ellsberg understands that and he understands the US is constantly playing russian roulette with the planet. I'd say more, if you hear s
And Trump Has is Confedderate Call-to-Arms Button (Score:2)