Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn't the main difference complexity and sophistication? You mostly see POC type work at conferences. What organizations can do better is integrate multiple exploits and relevant intelligence to architecture a targeted cyber weapon.

What's impressive about things like Stuxnet is the amount of work and coordination it must have took to make it. The actual techniques were rather unremarkable.



In my opinion, typical PoC academic work tends to underestimate the actual effort required to execute an exploit, and sometimes even describes exploits that can only ever occur under very stringent conditions.

Didn't Stuxnet involve backdooring Siemens PLCs? I find that pretty remarkable. In general, extremely sophisticated exploits that target critical infrastructure require attacks that haven't already been considered, be it for delivery or execution.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: