News: 1659722755

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Warning! Critical flaws found in US Emergency Alert System

(2022/08/05)


The US government is warning of critical vulnerabilities in its Emergency Alert System (EAS) systems that, if exploited, could enable intruders to send fake alerts out over television, radio, and cable networks.

The Department of Homeland Security (DHS) said in an [1]advisory it was recently informed about the flaws in EAS encoder and decoder devices, adding that they were successfully exploited by Ken Pyle, a security researcher at cybersecurity firm CYBIR. There is a sense of urgency to the advisory because the exploit "may" be presented, with proof of concept code, at the DEF CON conference in Las Vegas next week.

"In short, the vulnerability is public knowledge and will be demonstrated to a large audience in the coming weeks," the agency wrote in the advisory, which was issued this week by DHS' Federal Emergency Management Agency (FEMA).

[2]

The DHS is urging organizations that operate the [3]EAS to ensure that their devices and supporting systems are updated with the most recent software versions and security patches, are protected by a firewall, and are monitored, with audit logs being regularly reviewed to ensure there is no unauthorized access.

[4]

[5]

The exact nature of the security flaws was not disclosed by Homeland Security.

EAS has far-reaching capabilities nationally and locally, though it's probably best known for the irritating regular tests that loudly interrupt TV and radio broadcasts. The service on the federal level is run by FEMA and its partners, including the Federal Communications Commission (FCC) and National Oceanic and Atmospheric Administration.

[6]

The system is designed to ensure that the president can address US citizens within 10 minutes during a national emergency and requires that radio and TV broadcasters, cable TV, wireless cable systems, satellite, and wireline operators ensure that can happen.

State and local officials also can use the system during emergencies, which can range from extreme weather events to AMBER alerts. The alerts are delivered via the Integrated Public Alert and Warning System (IPAWS).

IPAWS for thought

The security industry can expect more such vulnerabilities to be found and exploited as more systems are interconnected, particularly at such a large scale, according to Erich Kron, security awareness advocate at security awareness training firm KnowBe4.

"In a case such as this that impacts emergency notifications, it may be easy to think that no real harm could come from a false alarm," Kron told The Register . "However, history proves that is not true."

He pointed to [7]the takeover of the Associated Press' Twitter account in 2013, when a bogus tweet on the account reported there had been two explosions at the White House that injured President Obama. The message panicked people and sent the Dow Jones Industrial Average plunging 150 points as it was retweeted.

[8]

Then-White House Press Secretary Jay Carny quickly reassured the country that nothing had happened and that President Obama was not hurt, and the stock market went back to normal within six minutes after the initial tweet.

A group that called itself the Syrian Electronic Army, which backed Syrian President Bashar al-Assad, would later claim responsibility for the attack, according to reports.

Interesting side note: The Syrian Electronic Army years and years ago tried to hack into The Register 's homegrown publishing system using a phishing email to one of our reporters. The message purported to come from one of our editors, and had a link to a page that looked just like our login process to harvest the username and password.

The biggest giveaway was that the email was far too cheery for that editor to have sent it, and the scam was rumbled. It also spurred us to add multi-factor authentication and other protections.

[9]US mobe owners will get presidential text message at 2:18 pm Eastern Time

[10]Hacked AP tweet claiming White House explosion causes Dow dip

[11]Samsung gets 2-year contract extensions to provide rugged handsets for UK's troubled Emergency Services Network

[12]Emergency alert system easily pwnable after epic ZOMBIE attack prank

In 2018, a ballistic missile alert in Hawaii was [13]accidently issued over the EAS and Wireless EAS via TV, radio, and cellphones. The alert claimed there was an incoming missile aimed at the state and urged residents to seek shelter. People panicked, phone systems were overloaded, and highways clogged, Kron said.

The accidental alert was the result of a miscommunication during a drill at Hawaii's Emergency Management Agency.

"Even false alerts such as these have real world impact, and at the very least dissolve public faith in these critical systems," he said. Kron said organizations involved with these systems should regularly patch these systems as a normal part of operations.

"While patching has been known to cause problems in IT systems, a mature and well-designed patch management program can ensure that any problems caused can be easily rolled back and the system kept online until a mitigation to the problem is found," he said. "It is simply too important for these systems to be working and secure to not keep them up to date with security patches." ®

Get our [14]Tech Resources



[1] https://content.govdelivery.com/accounts/USDHSFEMA/bulletins/3263326

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yu2TBH1didhn56Vudx2gZgAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.fema.gov/emergency-managers/practitioners/integrated-public-alert-warning-system/public/emergency-alert-system

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yu2TBH1didhn56Vudx2gZgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yu2TBH1didhn56Vudx2gZgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yu2TBH1didhn56Vudx2gZgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2013/04/23/hacked_ap_tweet_dow_decline/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yu2TBH1didhn56Vudx2gZgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2018/10/03/emergency_text_message/

[10] https://www.theregister.com/2013/04/23/hacked_ap_tweet_dow_decline/

[11] https://www.theregister.com/2021/12/16/samsung_esn_extension/

[12] https://www.theregister.com/2013/07/09/us_emergency_alert_system_still_flawed/

[13] https://www.theregister.com/2018/01/30/hawaii_missile_drill_attack_real/

[14] https://whitepapers.theregister.com/



The advantage of fake news

Yet Another Anonymous coward

Having had several years of totally ludicrous false news announcements - many of them from the Whitehouse press office - fake messages from N. Korean hackers and Macedonian teenagers will be a releif

Roll back

Eclectic Man

"a mature and well-designed patch management program can ensure that any problems caused can be easily rolled back"

Because, of course, everyone has one of those don't they?

Jilara

I do wonder how long this flaw might have been around. The system has never been invulnerable.

Many years ago, in a techscape far, far away, I hung out with some brilliant friends who had dubious hobbies. To their credit, they never profited from their antics, or engaged in actual sabotage. Their activities were mostly limited to chatting with lonely shut-ins half a world away and engaging in pranks. Which is leading up to their most infamous exploit.

In the 1970's, they hacked the phone system for Santa Barbara and Ventura Counties, here in California. People attempting to call in were routed to an announcement that the call could not be completed due to a state of National Emergency. Somehow, they managed to hack into the call system of at least one local radio station, and interrupt the program with an official-sounding alert from the Emergency Alert System, warning of a nuclear attack on Santa Barbara. While this prank was limited in scope, it caused quite a bit of consternation, and the perpetrators were never caught. (For the record, I haven't encountered any of them in decades, and the statute of limitations has long run out.)

What's the betting

cyberdemon

That he spends the duration of the conference in NSA custody

Walton Simons will see you now.

Re: What's the betting

Version 1.0

El Reg, please update the icons so that I can take the wire-cutters out of my jacket pocket to guarantee network security!

It took a while to surface, but it appears that a long-distance credit card
may have saved a U.S. Army unit from heavy casualties during the Grenada
military rescue/invasion. Major General David Nichols, Air Force ... said
the Army unit was in a house surrounded by Cuban forces. One soldier found
a telephone and, using his credit card, called Ft. Bragg, N.C., telling Army
officers there of the perilous situation. The officers in turn called the
Air Force, which sent in gunships to scatter the Cubans and relieve the unit.
-- Aviation Week and Space Technology