Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Warning! Critical flaws found in US Emergency Alert System
The Register ^

Posted on 08/05/2022 4:25:17 PM PDT by FarCenter

DEF CON may be about to blow lid off security hole

The US government is warning of critical vulnerabilities in its Emergency Alert System (EAS) systems that, if exploited, could enable intruders to send fake alerts out over television, radio, and cable networks.

The Department of Homeland Security (DHS) said in an advisory it was recently informed about the flaws in EAS encoder and decoder devices, adding that they were successfully exploited by Ken Pyle, a security researcher at cybersecurity firm CYBIR. There is a sense of urgency to the advisory because the exploit "may" be presented, with proof of concept code, at the DEF CON conference in Las Vegas next week.

"In short, the vulnerability is public knowledge and will be demonstrated to a large audience in the coming weeks," the agency wrote in the advisory, which was issued this week by DHS' Federal Emergency Management Agency (FEMA).

The DHS is urging organizations that operate the EAS to ensure that their devices and supporting systems are updated with the most recent software versions and security patches, are protected by a firewall, and are monitored, with audit logs being regularly reviewed to ensure there is no unauthorized access.

The exact nature of the security flaws was not disclosed by Homeland Security. However, it's reported that the holes are present in the Monroe Electronics R189 One-Net DASDEC EAS device, and this can be remotely compromised to send out fake alerts, lock out legit users, and cause other damage.

EAS has far-reaching capabilities nationally and locally, though it's probably best known for the irritating regular tests that loudly interrupt TV and radio broadcasts. The service on the federal level is run by FEMA and its partners, including the Federal Communications Commission (FCC) and National Oceanic and Atmospheric Administration.

The system is designed to ensure that the president can address US citizens within 10 minutes during a national emergency and requires that radio and TV broadcasters, cable TV, wireless cable systems, satellite, and wireline operators ensure that can happen.

State and local officials also can use the system during emergencies, which can range from extreme weather events to AMBER alerts. The alerts are delivered via the Integrated Public Alert and Warning System (IPAWS).


TOPICS: News/Current Events
KEYWORDS: dangerwillrobinson; dhs; eas; emergencyalert
Navigation: use the links below to view more comments.
first 1-2021-4041-54 next last

1 posted on 08/05/2022 4:25:17 PM PDT by FarCenter
[ Post Reply | Private Reply | View Replies]

To: FarCenter

Well, that’s just great.


2 posted on 08/05/2022 4:26:39 PM PDT by dfwgator (Endut! Hoch Hech!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

It’s gone woke ?


3 posted on 08/05/2022 4:27:18 PM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

4 posted on 08/05/2022 4:27:39 PM PDT by dfwgator (Endut! Hoch Hech!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

Great idea to announce this to the World.


5 posted on 08/05/2022 4:30:31 PM PDT by Huskrrrr (Alinsky, you magnificent Bastard, I read your book!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter
Warning! Critical flaws found in US Emergency Alert System

Yeah, it's Racist, Homophobic and doesn't use Green Energy, the Horror!.

6 posted on 08/05/2022 4:32:17 PM PDT by Navy Patriot (Celebrate Decivilization)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter
successfully exploited by Ken Pyle, a security researcher at cybersecurity firm CYBIR

I have no idea what's really going on, but I think it's not good.

I would also bet that there is no one named Ken Pyle. This feels like saying, "Osama Bin Laden was killed this morning by Tech Sgt John Smith who lives with his beloved family on Elm Street in Smalltown, Ohio."

Since when does the government identify people like this?

7 posted on 08/05/2022 4:33:04 PM PDT by ClearCase_guy (We are already in a revolutionary period, and the Rule of Law means nothing. It's "whatever".)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

Well, the government is focused on the important issues — tracking down all the white supremacists, Trump terrorists, opening the southern border, etc. — that it doesn’t have time to deal with the minor things like national security.


8 posted on 08/05/2022 4:33:16 PM PDT by odawg
[ Post Reply | Private Reply | To 1 | View Replies]

To: FarCenter

Going the way of car alarms, wrong most of the time so no one pays any attention to them anymore anyhow.


9 posted on 08/05/2022 4:35:03 PM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Huskrrrr

If the exploit is going to be announced next week at the DefCon conference in Las Vegas, you kind of need to disclose it to get folks to patch their gear.


10 posted on 08/05/2022 4:35:27 PM PDT by FarCenter
[ Post Reply | Private Reply | To 5 | View Replies]

To: odawg

Whoops, the test you just heard would have been followed by a gigantic flash in the east as NY and DC are burned to a crisp. This concludes this test of the Emergency Alert System..


11 posted on 08/05/2022 4:37:13 PM PDT by Shady (The #JihadJunta: "We are now a nation of Men, Not of Laws. You are not as equal as we are...")
[ Post Reply | Private Reply | To 8 | View Replies]

To: Shady

WOWO EBS False Alarm: February 20, 1971

https://www.youtube.com/watch?v=Yu4r79l8P8I


12 posted on 08/05/2022 4:38:04 PM PDT by dfwgator (Endut! Hoch Hech!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Navy Patriot

Fake News on a scale even CNN never envisioned! (and much higher ratings)


13 posted on 08/05/2022 4:38:21 PM PDT by FirstFlaBn
[ Post Reply | Private Reply | To 6 | View Replies]

To: FarCenter

Once upon a time these alerts had get by humans who could verify if they were real or not.

Now this system is about as secure as us voting machines.


14 posted on 08/05/2022 4:38:51 PM PDT by Revel
[ Post Reply | Private Reply | To 1 | View Replies]

To: ClearCase_guy

There seems to be a Ken Pyle. (Although I’ll admit to being at a meeting where a guy signed in with the last name of Undercoffer...)

https://www.rsaconference.com/experts/ken%20pyle

Ken Pyle is a partner of CYBIR, specializing in exploit development, penetration testing, and reverse engineering. As a highly rated and popular lecturer he has presented groundbreaking research at major industry events such as DEFCON, ShmooCon, Secureworld, HTCIA International, and others, focusing on fixing sets of problems that had been deemed unfixable or esoteric. He has discovered and published numerous critical software vulnerabilities in products from companies such as Cisco, Dell, Netgear, Sonicwall, HP, Datto, Kaseya, and ManageEngine, earning Multiple Hall of Fame acknowledgements. Pyle is a Graduate Professor of Cybersecurity at Chestnut Hill College. As an author, he has published several whitepapers and academic works on a wide range of topics.


15 posted on 08/05/2022 4:39:28 PM PDT by FarCenter
[ Post Reply | Private Reply | To 7 | View Replies]

To: dfwgator

Harry Morgan, Harry Fonda and an extremely convincing Larry Hagman.

Great movie.


16 posted on 08/05/2022 4:41:26 PM PDT by CTyank
[ Post Reply | Private Reply | To 4 | View Replies]

To: dfwgator

Sliding through the frequencies very fast (or was it quickly)


17 posted on 08/05/2022 4:42:06 PM PDT by SaveFerris (The Lord, The Christ and The Messiah: Jesus Christ of Nazareth - http://www.BiblicalJesusChrist.Com/)
[ Post Reply | Private Reply | To 4 | View Replies]

To: FarCenter

OK. Well, he has a security clearance, he’s really good at breaking into sensitive US systems and he knows a lot of stuff. Sure hope no one kidnaps him and gives him any enhanced interrogation.

Seems like poor OPSEC to put his name out there, but it’s not my problem.


18 posted on 08/05/2022 4:43:47 PM PDT by ClearCase_guy (We are already in a revolutionary period, and the Rule of Law means nothing. It's "whatever".)
[ Post Reply | Private Reply | To 15 | View Replies]

To: ClearCase_guy
(I have no idea what's really going on, but I think it's not good)

NYC with an absurd nuclear tutorial too. This does not bode well.

19 posted on 08/05/2022 4:44:20 PM PDT by SaveFerris (The Lord, The Christ and The Messiah: Jesus Christ of Nazareth - http://www.BiblicalJesusChrist.Com/)
[ Post Reply | Private Reply | To 7 | View Replies]

To: CTyank

The six B-58s taking off were the same plane. They just kept changing them zoom and possibly the angle. Maybe multiple cameras? 🎥

They snuck out to the fence to catch a B-58 lifting off.

4 - J-79s - ooh baby


20 posted on 08/05/2022 4:46:53 PM PDT by SaveFerris (The Lord, The Christ and The Messiah: Jesus Christ of Nazareth - http://www.BiblicalJesusChrist.Com/)
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-54 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson