frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

I Think the Military Commissary's Freezers Were Hacked

https://signalandsilence.substack.com/p/i-think-someone-hacked-the-commissary
47•jcurbo•1h ago

Comments

1284725•1h ago
Gilfoyle was here. Everything that has been mocked in the Silicon Valley Show has either already happened or will happen.
ggm•1h ago
Single source systems provider and integrator and a doom date?

Could be a hack or a design flaw. I await the root cause analysis.

fzeroracer•1h ago
There's a far simpler explanation than some outside actor (either state sponsored or otherwise) deciding that the best thing they can do is to muck around with freezers.

We know there's been a severe rot of operational capabilities in the military thanks for Hegseths purges and general stupidity. It's entirely possible and quite likely that over the course of his various drunken binges he decided to get rid of people who were in charge of operational control for stuff like freezers across military bases.

Kichererbsen•1h ago
General Stupidity should probably be demoted for this.
odyssey7•50m ago
This is exactly the sort of thing that a saboteur would want its targets to think.

“If sovereign and subject are in accord, put division between them.” —Sun Tzu, The Art of War

fzeroracer•47m ago
That's the exact sort of thing the military would want us to think, because 'we were hacked by another nation' sounds a lot better than 'we fired the people responsible for food logistics'. You're not going to be able to divine the real reason this way.
odyssey7•46m ago
There would be far better excuses here than saying “we’re incompetent.”
kjs3•42m ago
To be fair, if you want to mess with your adversaries troop morale, screwing up dinner is pretty effective.
astura•11m ago
These are commissary fridges, not galley fridges.
voidUpdate•29m ago
I would agree, but the freezers going into high heat defrost mode seems like an intentional action from someone, whether that be incompetence or malice on the side of DeCA, or malice from a third party. If they got rid of the people commanding the freezers what to do, I feel like they'd just stay on whatever mode they were already on, rather than suddenly command all the freezers to defrost
boesboes•1h ago
Welcome to the internet of shitty unsupported and insecure crap! Are we really this dumb as a society?
voidUpdate•55m ago
Yes
tialaramex•38m ago
And at some point in hindsight it will be obvious what fractions of problems were

A. This technology is inherently crap, that's our fault

B. A bored teenager broke it. Bored teenagers are a thing, it literally doesn't matter which country they are in, stop building things bored teenagers will blow up, this is also inherently our fault

C. Foreign Adversaries

It suits both mass media audience figures and a narrative of wily enemies rather than incompetence to pin everything on C and it seems eminently possible that a country with as many enemies as the US would attract this sometimes, but the reality is that both A and B are much more likely despite being embarrassing.

wlesieutre•47m ago
As the saying goes, the S in IoT stands for security

Not exactly strong evidence presented here, but it wouldn't be a surprise either

nom•39m ago
it's not AI generated so it must be true
DarmokTanagra•34m ago
homeonthemtn•58m ago
Very interesting article, very neurotically written. Definitely got grating by the end.
CarVac•52m ago
The bold text use make me think it was largely LLM-written. Maybe even LLM-researched.
codingdave•56m ago
The author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems?

Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.

odyssey7•53m ago
Obvious sabotage would be addressed promptly. Subtle sabotage could persist as a minor torment indefinitely.
pizzaiolo•19m ago
Stuxnet was a good example of that.
ckdarby•37m ago
The article has a post that says this happened across 14 bases at the same time.
ErroneousBosh•33m ago
Then I would suspect that this is either down to the common control system, or there has been a batch failure of the controllers in the freezers that were presumably ordered and supplied at the same time.

I've seen batch failures in radio equipment where I could predict 100% accurately which devices would fail based on the range of serial numbers.

jvanderbot
AppAttestationz•37m ago
I'm waiting for the OpenAI report that their agents defrosted everything.
tyingq•29m ago
This would be a bigger deal for the commissary locations outside the US, though I see none are on the list. Many of the very junior enlisted make very little money (~2400USD/month), and the low pricing at the commissary helps quite a lot. In the US, you would typically have some affordable off-base options. Overseas, it depends. Many of the locations are remote, or in places where the local groceries are significantly more expensive.
peterabbitcook•19m ago
A couple years ago I worked on a service that had to communicate with a Siemens S7-1500 PLC. Based on my experience with that project, none of what I’ve read recently about unsecured industrial PLCs is surprising.

I opened Siemens TIA Portal and PLCSIM for the first time and thought “wow, I didn’t think the Windows 95 GUI library was still supported.” None of the PLC contractors we had hired knew how to enable TLS on the thing (user/pass eg admin/admin was their usual). Anecdote: I once spent hours reading the docs and clicking around trying to get it to accept an SSL certificate signed by a real CA and it wouldn’t go, but it accepted one I self-signed in openssl.

In all fairness, the people who are experts in the field of Siemens PLC programming are usually mechanical-ish engineers and security is not in their skill set or on their mind.

sidewndr46•8m ago
Isn't this the industry expectation in that kind of equipment? If it was signed by a real CA the cert. could expire and render the equipment unable to communicate.
BobBagwill•12m ago
I would suspect a firmware bug. Or a "Service Required" timer that was ignored.
kotaKat•7m ago
I'm in the firmware bug camp too. Over/under on "the remote management server went down and a bug on all the freezers decided to put them back into some form of local control where its first action was to do a defrost cycle then put it back into offline service"?
How many people do you know that have always on microphones in their home so that they buy things from amazon or google trivia answers?
•
28m ago
So what's the denominator? Every base has some kid of refrigerator, and there must be 100s-1000s of bases.
schiffern•16m ago
OTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about.

Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late.

All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway.

Interesting times...

larrysalibra•7m ago
> I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.

according to the article, the denominator is ~235.

alephnerd•23m ago
There are a couple hundred US armed forces bases each with commissaries that would be managed by DeCA.

An attack like the author hypothesized would require a LOTL modus operandi, and doing so on 14 locations wouldn't justify completely blowing up an entire LOTL operation, because it exposes indicators, registers, and tradecraft that is then shared amongst all security vendors.

The way it's framed is clickbait at its worst with the added issue of limited security experience, but the same can be said of HN in general.

OpenShot 4.0: Record, Edit, and Color Like Never Before

https://www.openshot.org/blog/2026/08/30/openshot-40-record-edit-color-like-never-before/
189•metrofun•3h ago•55 comments

“I just chose words carefully”

https://unsung.aresluna.org/i-just-chose-words-carefully/
927•zdw•14h ago•245 comments

Agent Memory as a File Format

https://calpaterson.com/memoryfields.html
29•ingve•1h ago•19 comments

Breaking Claude Code Opus 5 Auto Mode

https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
144•Recursing•5h ago•48 comments

What I Learned About AI Trust from Reconciling over 100B Transactions

https://engineering.moniepoint.com/what-i-learned-about-ai-trust-from-reconciling
12•Cellz•1h ago•7 comments

Malleable software = solid bases and custom code

https://www.mdubakov.me/malleable-software-solid-bases-custom-code/
16•tablet•2h ago•5 comments

uv: Deduplicate all files in the wheel cache

https://github.com/astral-sh/uv/pull/21327
87•tosh•6h ago•26 comments

My hobby of building miniatures and taking pretty pictures

https://sandyuraz.com/blogs/tiny-cafe/
205•thecsw•2d ago•33 comments

P99 0 ms* autocomplete for 240M domain names

https://ruurtjan.com/articles/p99-0ms-autocomplete-for-240-million-domain-names
162•dbalatero•9h ago•69 comments

A CVE Dispute

https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/
68•theanonymousone•1h ago•9 comments

I Think the Military Commissary's Freezers Were Hacked

https://signalandsilence.substack.com/p/i-think-someone-hacked-the-commissary
47•jcurbo•1h ago•35 comments

I built a hardware-bound local password vault hidden in a photo

https://blindlock.app/en/
10•BlindLock•2h ago•3 comments

Using floci to emulate Cloud platforms (GCP, AWS, Azure)

https://flowg.cloud/blog/using-floci-local-emulators
12•linkdd•3d ago•2 comments

Notes on Private Trackers

https://www.jenn.site/notes-on-private-trackers/
4•surprisetalk•4d ago•0 comments

The startling 1960s theory that Stonehenge was a prehistoric computer

https://www.bbc.com/culture/article/20260828-the-startling-1960s-theory-that-stonehenge-was-a-pre...
9•dabinat•3h ago•2 comments

A 12TB Steam "teraleak" spills more than a decade of lost PC gaming history

https://arstechnica.com/gaming/2026/08/a-12tb-steam-teraleak-spills-more-than-a-decade-of-lost-pc...
212•WithinReason•6h ago•36 comments

The AI-Native SDLC Starts with Your Infrastructure

https://metalbear.com/blog/ai-native-sdlc-infrastructure/
7•aviramha•2h ago•0 comments

Matrox: Graphics for Professionals

https://www.abortretry.fail/p/matrox
146•BirAdam•13h ago•48 comments

Haiku R1/beta6 has been released

https://www.haiku-os.org/news/2026-08-26_haiku_r1_beta6
341•metrofun•21h ago•95 comments

Understanding ChatGPT Work

https://simonwillison.net/2026/Aug/30/understanding-chatgpt-work/
230•gmays•11h ago•124 comments

AI-Written Code Is Still *Your* Code. Are You OK with That?

https://martiansoftware.com/articles/ai-written-code-is-still-yours
34•martylamb•54m ago•43 comments

What 2000 Buried Underpants Revealed About Where Soil Is Most Alive

https://studyfinds.com/what-2000-buried-underpants-revealed-about-where-soil-is-most-alive/
51•mdp2021•4d ago•9 comments

The Universe as a Minified Bundle

https://andrewarrow.dev/2026/moons/2/day/9/the-universe-as-a-minified-bundle/
3•cs1996•1h ago•1 comments

How to build a diffusion language model

https://kuleshov-group.github.io/blog/blog/2026/how-to-build-a-diffusion-language-model/
124•volodia•13h ago•16 comments

Study: Blue light impairs the eye's ability to distinguish fine detail most

https://research.uga.edu/news/blue-light-has-a-surprising-effect-on-your-eyes-study-finds/
16•giuliomagnifico•4h ago•13 comments

The British state has lost the argument

https://jonathancook.substack.com/p/the-british-state-has-lost-the-argument
14•hackandthink•49m ago•1 comments

Creepy Crawlies

https://people.kernel.org/monsieuricon/creepy-crawlies
1250•zdw•1d ago•627 comments

Highlighting My Code Based on How Much I Care

https://hank.bond/posts/highlighting-my-code-based-on-how-much-i-care/
90•hankbond•2d ago•49 comments

Show HN: NFC Energy-Harvesting PCB Business Card with an MCU

https://wilsonharper.net/projects/businesscard/
193•WilsonHarper•2d ago•21 comments

Apple Caught Off Guard by AI Demand for Mac Mini and Mac Studio

https://www.macrumors.com/2026/08/30/apple-unexpected-mac-mini-and-studio-demand/
6•thm•21m ago•0 comments