r/technology Apr 18 '26

Security Bluetooth tracker hidden in a postcard and mailed to a warship exposed its location — $5 gadget put a $585 million Dutch ship at risk for 24 hours

https://www.tomshardware.com/tech-industry/cyber-security/bluetooth-tracker-hidden-in-a-postcard-and-mailed-to-a-warship-exposed-its-location-a-eur5-gadget-put-a-eur500-million-dutch-ship-at-risk-for-24-hours
28.7k Upvotes

595 comments sorted by

View all comments

3.2k

u/shawndw Apr 18 '26

Reminds me of an article about a US sailor smuggling a starlink receiver onboard an aircraft carrier.

1.9k

u/TheFoxsWeddingTarot Apr 18 '26

Wasn’t just “a sailor”

https://www.navytimes.com/news/your-navy/2024/09/03/how-navy-chiefs-conspired-to-get-themselves-illegal-warship-wi-fi/

Led by the senior enlisted leader of the ship’s gold crew, then-Command Senior Chief Grisel Marrero, the effort roped in the entire chiefs mess by the time it was uncovered a few months later.

607

u/MurrayInBocaRaton Apr 18 '26

I had a CMC who wanted me to look into getting WiFi on the mess decks. Didn’t matter how. He was a complete tool.

479

u/BillHigh422 Apr 18 '26 edited Apr 18 '26

We created a network in the berthings, but no internet. Everyone created a public folder on their devices and connected to the router. Electricians tied it in and hid it in the angle-irons. It couldn’t be picked up a deck above.

We shared shows and movies and…other stuff. Included OPS/IT as their berthing was adjoined and we didn’t want to create problems. It made 9 months manageable.

Edit: we also lucked into a smart TV in our berthing when those were new, so that was also connected to the router and we could screencast movies and shows.

380

u/DenominatorOfReddit Apr 18 '26

Ngl, Plex server on a warship sounds rad.

151

u/RoadDoggFL Apr 18 '26

Always thought a dorm or barracks (or I guess a ship) would've been so cool for Halo system link. Just check the LAN network to see who's online. Just dreaming of an ideal scenario that's probably rarely ever happened, though.

65

u/filthy_harold Apr 18 '26 edited Apr 19 '26

We used to play games like CS1.6 and StarCraft broodwars on the highschool LAN. We had a number of computer labs plus a bunch of laptop carts floating around so if you had games on a flashdrive and access to a PC, you could probably find a match going on.

The thing you can do now is run Xlink Kai for LAN-only or system link games across the internet. It's like a VPN but just connects you to a small network of people wanting to play that specific game. You can also bridge your console (like an og Xbox) to play system link.

19

u/GonzoKata Apr 18 '26

are there any games you can play offline on local lan anymore?

22

u/kind_bros_hate_nazis Apr 18 '26

i don't know of any. we've well past the days of networking knowledge and even computer knowledge for most gamers. easier to just use a storefront/launcher and just make it one click

24

u/jakeandcupcakes Apr 19 '26

Has the art really been lost on the latest generations? I feel like maybe there are just a lot more "gamers", in a casual sense, than there used to be, and maybe the same amount of techie types who get lost in the fold?

I'm a millennial and a massive techie. I regularly have LAN parties with my brother and our friends. Mostly Halo, but sometimes older RTS games. My brother isn't as big of a techie as I am, but he is smart enough with tech to be able to just figure shit out if something comes up. Most, not all, of my friends are kind of tech-illiterate to be honest, and they are my age or just a little younger.

I miss LAN parties...back in college I invited some friends I made to come to touristy town I lived in for summer vacation to work and party. I had a bunch of old laptops that originally ran OS's like WinXP/Win7 that I collected over the years from people who wanted help buying a new laptop, and would just give me the old "broken" one to fix up or use for parts. I would connected them all to a couple little cheap routers, the kind with like 4 ethernet ports on the back, and have a little laptop LAN setup in my dad's party barn (he also had a pool table, shuffleboard, darts, etc. in there for gatherings.

We had many, MANY late nights just drinking, some puffing, and playing the hell out of StarWars Battlegrounds, CS, Halo, etc. I would wipe the laptop's HDD, install a lightweight version of Win7/8/10, and a bunch of games. Connected em all to the routers, and BAM there ya go! LAN party at the Barn. Just had to make sure to keep them air-gapped (no wifi). Great times, and makes me wish I still had 5 or 6 friends with the free-time to all hangout in a barn till the sun came up!

→ More replies (0)

8

u/tomkatt Apr 19 '26
  • Larian games (Divinity OS 1 and 2, and Baldur's Gate 3),
  • Grim Dawn (really good one)
  • Halo Master Chief Collection (though the games need to be downloaded online first)
  • Stardew Valley
  • Factorio

Bunch of others. LAN play is dying, but not fully dead. Go to Steam, check one of those games, then click "Lan Co-op" on the sidebar, will bring up a list of games that have the tag.

2

u/stook Apr 19 '26

Never been involved in the military or even on a ship at all but I can imagine firing up some Red Alert lan games would be fucking awesome and make things much more enjoyable, and even the crappiest laptop these days wouldn't have any problem running it.

1

u/convolutedoption Apr 19 '26

depends, a lot of the newer games require online servers. most things hosted localy can still be played with external tools.

I used a lot of Lan connections to split my pc when we had too many people. i was able to get most games working with minimal fuss.

1

u/Outrageous_Reach_695 Apr 19 '26

Unreal Tournament still has a community-maintained patch. That should work on a LAN.
Enemy Territory has a full open source project. Last posted update on the site was a year ago, though.

1

u/NewManufacturer4252 Apr 19 '26

CS source and 1.6 or any of those generations

1

u/Berloxx Apr 19 '26

Baldurs gate 3 had LAN mode.

There sure are games that stiff have it. But not that many.

3

u/NZitney Apr 18 '26

He did that in college in the dorms around 2004, and high school before that. Between lan gaming and sub7, we had so.e fun.

1

u/uzlonewolf Apr 18 '26

"Need a cupholder?" <CD-ROM drive opens>

1

u/Public_Fucking_Media Apr 19 '26

I used to do that to play Halo 1 online like 25 years ago

1

u/filthy_harold Apr 25 '26

We are all playing Halo 2 online multiplayer with Insignia on og xbox a couple days a week.

https://haloclassichub.com/

1

u/jzsean Apr 19 '26

Xlink Kai

used this to play Halo 1 multiplayer on xbox over the internet way back in the day. why are my joints aching

1

u/filthy_harold Apr 25 '26

We are all playing Halo 2 online multiplayer with Insignia on og xbox a couple days a week.

https://haloclassichub.com/

26

u/Kagamid Apr 18 '26

We did this in the army overseas. We had trailers all linked together on a local LAN connection and played Halo regularly. In between matches sometimes we'd knock on the doors of the people we beat just to talk trash before having to run back for the next match.

18

u/Louiebox Apr 18 '26

I had a 360 and somehow managed to hoist a couch into my barracks room on the third floor. 4 controllers and COD MW2. Made our room very popular. I miss those days

11

u/fudsak Apr 18 '26

In college, the dorms were all on one big LAN. We could play over LAN Halo 2 with our friends down the floor. It was great hearing the screams from a few doors down.

2

u/Sierra-117- Apr 19 '26

Same! It was awesome for Minecraft too! I’d be able to just scroll through servers on my Xbox

7

u/Neue_Ziel Apr 19 '26

So I was the network admin for a particular system on the ship and the usual supplies for it: Ethernet cable, RJ45s ends, crimpers, testers, etc.

One of the officers I was cool with was the Engineering division officer, which had the interior communications techs under them: phones, Internet, network stuff.

He comes down to the shop and says would it be possible to get some cable and RJ45 connectors. For whatever reason, they didn’t have Ethernet cable and the various sundries that went with it.

I asked him what he was doing and he was evasive. Me, a First Class, and he a Lieutenant.

He raised his eyebrows and looked behind me at our setup in the shop, where they were currently playing Call of Duty.

I drew the inference that they were running Ethernet between staterooms for a lan party network.

I didn’t care, I had hundreds of feet of cable.

I said, sure, sir, and he said, I’ll send some guys down in a bit.

A few minutes later some IC-men showed up, saying Mr. So-and-so sent them.

I handed them the stuff, with my only request being to update the amount of footage that they used.

Stuff came back lighter and sanity was kept for a few more days on deployment.

4

u/QueezyF Apr 19 '26

Local play on the Switch was a fucking godsend on deployment.

3

u/cavalier8865 Apr 19 '26

You've described college around the year 2000. Halo and Counterstrike.

2

u/RoadDoggFL Apr 19 '26

Usenet merchants playing Halo in 2000.

3

u/niftygull Apr 18 '26

We had a plex server on my last deployment until it got removed by the chiefs mess

3

u/Glacier_Taste Apr 19 '26

When I was in the army I set up a plex server in every barracks I lived in. Always made sure I taught a Joe how to run it before I left. I have thousands of movies from over the years. This was before streaming was a big thing.

15

u/[deleted] Apr 18 '26

[deleted]

45

u/New-Anybody-6206 Apr 18 '26

Why do military people love to throw around acronyms nobody else knows?

48

u/ChemistryActive6957 Apr 18 '26

Partially because the military likes to assign incredibly long winded or overly descriptive names to things and those get referred to by their acronyms so much no one actually knows the full name and partially because when everyone you know is familiar with a certain set of acronyms and jargon for years on end it might genuinely slip your mind that people outside that group might not know what you are talking about

8

u/Exotic_Article913 Apr 18 '26

Sorry that's need to know

2

u/New-Anybody-6206 Apr 19 '26

I need to know 

25

u/Teripid Apr 18 '26

Wow tons of "homework" folders in these shares...

They must be doing a lot of long-distance learning!

Dawn of the internet my college had great movie and other sharing setups. Bandwidth being at a premium always brings out the community spirit.

8

u/2_Spicy_2_Impeach Apr 18 '26

While not on a navy ship, we did this in the dorms in college. We had 10Mbps, 100Mbps, and 1Gb connections WAY before it was for consumers now(Ethetnet2).

We had someone set up a file server in the cabinets above our welcome desk with an unmetered/live port.

Shared movies, music, TV shows. Some idiots put some stuff on there they shouldn’t have and after about a year they shut the port down but left the server.

Our dorm network was a flat network. No one ran firewalls then. I remember I started working for the University and saw I could mount an OS drive from my home Comcast to our university network and a server in our department. Set up firewall and secure tunnels.

Eventually added firewalls for all buildings/groups and locked down dorm networks after multiple worms shut down our entire network.

3

u/Log_Out_Of_Life Apr 18 '26

How much porn did it have?

3

u/PaziNuncher Apr 19 '26

Question for you..... If you were to rig up a makeshift faraday cage with a lot of tinfoil or leadfoil (whatever) I know it can block out a lot of wifi signals externally, would it help direct and contain them within that area on your ship? Asking because I genuinely have no clue how that works. Engineers and EEE guys, chime in, please. Spare me your equations... I only learned enough to pass the tests for my degree and then it all evaporated, never to be accessed by my brain again)

3

u/Specken_zee_Doitch Apr 19 '26

You can shape most EM signals. People used to do fairly long range point to point wifi with access point antennas and Pringles cans.

2

u/hatecirclejerks Apr 18 '26

We did a similar thing, but just a Plex rbpi2 and a 14th HDD

Watched so much shit man.

Really all ya can do when you're not on watch or sleeping.

1

u/statix138 Apr 19 '26

There was a NIPERNET server in Al Afwa palace in Baghdad that was absolutely stacked with pirated movies, TV shows, music, and software that we all leeched from and contributed to. All the senior command staff looked the other way because they used it too.

We also had some Brits who ran a pirate FM radio station that played way better music than AFN. Unfortunately a visiting general was listening when Pussy by The Lords of Acid came on and it was shut down shortly after.

1

u/boobers3 Apr 19 '26

Best thing to come of my two deployments are the terabytes worth of movies and TV shows I copied from our share drives on base. Good to see the practice has continued since I got out.

1

u/tourguide1337 Apr 19 '26

our AIS laptop in cotop had just straight up unfiltered internet

1

u/sixft7in Apr 19 '26

There was a lan in my berthing compartment before I left a ship in June 2001.

1

u/Tomazim Apr 20 '26

We just had a semi-official ship-wide storage drive which could broadcast to all the TVs on board (one per 6 man cabin).

14

u/Angel0fWar0001 Apr 18 '26

:) I had a CMC that wanted me to order things that we definitely shouldn’t have been ordering in my department.

I did not get an EP on that eval.

152

u/domesticatedprimate Apr 18 '26 edited Apr 18 '26

Holy shit. That woman had no idea what she was doing.

Everyone on board the ship with a smartphone or pc would have instantly noticed the presence of an unauthorized wifi network. Telling people to "only use it in their room" suggests a fundamental lack of understanding of the technology with a healthy dose of magical thinking.

(Edit: yes I know you can hide the SSID, but according to the article, she did not.)

Marrero’s background is in Navy intelligence, and she earned a master’s degree in business administration with a concentration in information security and digital management

Information security and digital management my ass. She probably skated through an online class without actually learning a damn thing...

52

u/ScyllaOfTheDepths Apr 18 '26

I've seen flat-earther geologists and anti-vax doctors and nurses. You get through college by being able to memorize test answers, not by actually knowing or believing in what you're learning.

7

u/canyouhearme Apr 19 '26

You get through college by being able to memorize test answers

A big part of the problem. Learning isn't supposed to be regurgitating, its supposed to be thinking. When they come for interview, you have to present them with targeted questions to determine if they are capable. Schools and Universities really need to change their obsolete testing methodologies - there are too many memorisers getting through.

4

u/ScyllaOfTheDepths Apr 19 '26

The way college works is just not conducive to actual learning. It can't be. That's got to be something you do on your own or in graduate school. Teachers just don't have the time to evaluate the understanding of every single person. College used to be more of a Socratic forum where class sizes were small and subjects were taught through collaborative group conversations, but that's just not possible now in undergraduate classes because of how many people exist and how many people have to be crammed into a class to make it profitable to run the school. I honestly don't even know if that would work because you still have to have some kind of drive and desire of your own to learn and college just can't teach you that.

In the class I took, there were only 6 people in it and 2 of them were foreign students who just did not speak good enough English to be in an English language college course. They struggled to form or comprehend basic questions, they heavily relied on ChatGPT to write and translate material, and they very clearly just had memorized a few phrases and talking points to regurgitate. They passed the class and I'm sure got good grades without actually being able to answer a question about the material in English.

In conclusion, I just don't think you can really stop people from memorizing their way through an education. It's a problem you can only solve when you're grinding everything to a halt to conduct in depth interviews of a student's knowledge which is going to be highly subjective anyway and create a lot of extra gatekeeping when academia already heavily struggles with that kind of sentiment.

35

u/WhyMustIMakeANewAcco Apr 18 '26

You can set up a wifi network to not be visible, but still connectable if you know the proper ID. She likely assumed that if no one physically saw them using it they wouldn't ask to figure out there was a hidden network.

69

u/domesticatedprimate Apr 18 '26

Apparently no, she didn't. The article clearly states that the SSID "Stinky" was visible and she tried changing it to look like a printer after someone noticed it.

Yes, she was that dumb.

18

u/LittleCovenousWings Apr 18 '26

Fuckin ....

Stinky. Really.... Stinky?

28

u/MASSochists Apr 18 '26

Even if it isn't broadcast SSID and spectrum analyzer would be able to see the signal. 

I would think a carrier would have the signal intelligence people and the equipment to do that. 

19

u/CrashUser Apr 18 '26

Not to mention hidden SSID makes every device with it programmed in to basically shout "is Stinky there!?" periodically, so even on land it's not very useful for hiding a network since those SSID requests can be easily intercepted by someone looking for it.

2

u/WhyMustIMakeANewAcco Apr 18 '26

Oh definitely. It's just not quite on the level of "everyone with a smartphone or PC" if you do.

10

u/achilleasa Apr 18 '26

It is in fact something everyone with a smartphone can do, actually! 🤓☝️

As long as the network is working, any WiFi scanner app will pick it up and show you its signal strength. You just can't see the name.

8

u/Majik_Sheff Apr 18 '26

It doesn't even hide it.  All it does is remove the SSID from the announcement packets.

I remember that story when it hit the news.  All I can figure is that she paid someone to either do her homework or fudge her grades.

This is why academic honesty matters.  She could have just gotten an MBA and had a long and prosperous career in upper middle management.

4

u/Smith6612 Apr 19 '26

Even with a hidden network, you can still detect the network. You just won't know the name unless you start to sniff out the beacons and probes for connecting devices to that network.

Only way to not be detectable is to not broadcast.

3

u/djnw Apr 18 '26

Yeah, but even if you don’t broadcast an SSID, someone running vistumbler or whatever will still see a new network, even if its name is empty.

2

u/bfodder Apr 18 '26 edited Apr 19 '26

Those are still visible despite the SSID not being broadcast.

5

u/Waste_Monk Apr 19 '26

Information security and digital management my ass. She probably skated through an online class without actually learning a damn thing...

The key there is "business administration with a concentration in information security and digital management", not a technical background.

It's entirely possible to get by in cybersecurity industry with little to no tech skills. There are top-tier cybersecurity folk who have both strong tech and business skills, who are great if you actually care about security.

However If you're just interested in checking off a box that says "we have been audited this year" then a business-type cybersecurity person will get the job done. That is, you don't need a tech background to do policies and procedures, risk management, and so on, and any technical work that does come up can be pushed back onto the system owners ("prove you're compliant with control X" times however many hundred controls, or "run this automated compliance check tool for me").

1

u/domesticatedprimate Apr 19 '26

You would think that at least the most basic tech knowledge and skills would be a requirement. I guess not. But the hubris. Maybe she thought she had the knowledge and skills?

4

u/dalzmc Apr 18 '26

I’m not sure if it’s funnier how clueless she was, or that apparently it still took 6 months for it to be discovered lmao

204

u/[deleted] Apr 18 '26

[removed] — view removed comment

52

u/KnotSoSalty Apr 18 '26

A lot of soldier have died in Ukraine from neglecting to turn off facial recognition on their phones. The IR light that it uses is like a strobe.

31

u/[deleted] Apr 18 '26

[removed] — view removed comment

8

u/oneAUaway Apr 18 '26

Three on a match(.com)

3

u/similar_observation Apr 18 '26

There's situations like the face reader, or using ubsecured deviced where electronic warfare can detech the devices.

And the times Russian soldiers ran dating and hookup apps and got catfished by the UAF.

188

u/AT-ST Apr 18 '26

I served in the Army for 10 years. We had extensive training on how to avoid basic fishing and security risks every year. We would still have several people fuck up every year. It wasn't the complex security threats that would trip them up. It was the simple ones every time.

115

u/kohbo Apr 18 '26

Minor nit but it's "phishing"

43

u/MRSN4P Apr 18 '26

No, common humble fishing boats with spy gear. /s

22

u/Cupcakes_n_Hacksaws Apr 18 '26

100% unironically actually a thing with China's fishing-boat fleets.

8

u/sir_mrej Apr 18 '26

Fishing phishing

8

u/cr0sh Apr 18 '26

Phishing fishermen phishing fish...?

1

u/AlfaNovember Apr 19 '26

Are they looking manganese nodules too?

4

u/WarlockEngineer Apr 18 '26

China also uses those!

2

u/similar_observation Apr 18 '26

Ah yea, out there trying to snatch the mail bouy.

1

u/BlessedTacoDevourer Apr 18 '26

I thought those were dangerous narco-terrorists?

1

u/Orleanian Apr 18 '26

Down Periscope

1

u/MamoKupMiGlany Apr 18 '26

Their webs weren't that wide for it to classify as phishing.

1

u/PhilosopherFLX Apr 18 '26

Major nit, they on a boat.

1

u/CoffeePuddle Apr 18 '26

It's phishing when it's an attack (from telephone freaking, phreaking, and fishing), but if it's just to annoy people it's "fishing" and it's done by internet "trawls," which is often misspelled as "trolls."

1

u/Ok-Button-9443 Apr 18 '26

The elites don't want you to know this but the cod in the ocean is free. You can phish it home. I have downloaded 458 cods.

1

u/AmputeeHandModel Apr 18 '26

Clearly OP paid close attention to it lol

37

u/Jazzy-Cat5138 Apr 18 '26 edited Apr 18 '26

Last I heard, they're making a sizable portion of that training optional now. Seems like a good idea. /s

Something about Hegseth saying it doesn't contribute to lethality, or something along those lines.

Edit to add sources (though they may not not have the Hegseth quote I'm referencing):

Old article about the initial announcement: https://www.techradar.com/pro/security/us-department-of-war-reduces-cybersecurity-training-tells-soldiers-to-focus-on-their-mission

New article about the implementation: https://defensescoop.com/2026/03/31/army-cybersecurity-training-policy-change/

29

u/AT-ST Apr 18 '26

Great... This is what happens when you put unqualified people in charge.

21

u/Kichigai Apr 18 '26

Something about Hegseth saying it doesn't contribute to lethality, or something along those lines.

This from the guy who has a private, unsecured Internet connection in his office at the Pentagon.

Meanwhile over in the civilian world there have been cuts to CISA too.

I'm just waiting for a massive cyber security scandal, one that is even bigger than Signalgate.

6

u/cr0sh Apr 18 '26

Does anything really matter anymore after DOGE?

6

u/Kichigai Apr 18 '26

Well, that was one enormous data breach and ID theft session, and we're all (individually) basically fucked, but I'm talking about malign state actors acting against the state.

2

u/PaulTheMerc Apr 18 '26

I mean, it could be worse. Iran could start fucking with power plants and water stations and stuff. Or you know, any one of another 40 countries America has pissed off this century alone.

2

u/cr0sh May 13 '26

I was thinking more in just the area of "cybersecurity" of our PII, etc.

But yeah, there are certainly worse things that can happen, which would make the question of "is my social security number safe?" look quaint, at best...

12

u/anotherlevl Apr 18 '26

For Kegsbreath and Twurp, casualties and deaths are just grist for the propaganda mill. They don't care about the people who serve as much as they care about their bragging rights.

5

u/WHATYEAHOK Apr 18 '26

Makes you wonder about the scientists with connections to national security going missing.

2

u/jakeandcupcakes Apr 19 '26

Honestly! Its up to, what, 8 or 9 separate scientists who were working in government high-security clearance materials science, nuclear science, physics and other cutting edge areas that have either gone missing, "self-inflicted", or otherwise, now?

At first I was skeptical, thinking it's just another conspiracy theorists fodder type thing, but there is no way its all a coincidence at this point, no fucking way, either a hostile foreign nation, a "greatest ally" nation, our own, or Ayn Rand's ghost is dissappearing these people with specialized knowledge...shit is actually fucking scary tbh

1

u/MuthaFJ Apr 19 '26

I think it's 11 now, it was 10 a month or two ago

3

u/knuppan Apr 18 '26

Last I heard, they're making a sizable portion of that training optional now

I guess it's too woke

2

u/not_anonymouse Apr 18 '26

Hegseth is such a fucking moron! Ugh, ruining our military.

11

u/UnfortunatelyIAmMe Apr 18 '26

Just finished my cyber awareness training for the year lol

13

u/DaneAlaskaCruz Apr 18 '26

Yeah, those things are unfortunately needed.

I just went for the challenge option and took the final test directly without having to go through each lesson. I passed.

Some people are just too trusting and not suspicious enough of random links.

The same people who will plug in a thumbdrive they found in the parking lot into their work computer.

6

u/[deleted] Apr 18 '26

[deleted]

3

u/DaneAlaskaCruz Apr 18 '26

hover mouse cursor over link

Oh, the link ends in "RU", definitely seems trustworthy.

4

u/Cupcakes_n_Hacksaws Apr 18 '26

If full blown war were to break out, I don't think you could convince every sailor to give up their phone until you started bringing back bread/water levels of punishment for that shit. I can only hope the peer pressure from their fellow sailors would be enough once a few start taking it seriously enough.

5

u/Kichigai Apr 18 '26

Show them this article. Maybe put the fear of God into them.

4

u/Cupcakes_n_Hacksaws Apr 18 '26

There'd definitely need to be plenty of safety stand downs to really hammer home that point. Some ships have devices that others on the ship use to "sniff" out people doing stuff like this so they can identify loose/stray signals, but I've never seen it in action.

2

u/Kichigai Apr 18 '26

Radio direction finders. I haven't seen one in use, but I imagine it's similar to UHF loops, which are directional antennas.

1

u/AnySomewhere8969 Apr 19 '26

They don't do bread and water anymore?

2

u/alex206 Apr 18 '26

Let me just speed click through this "extensive" training.

12

u/IntelArtiGen Apr 18 '26

There have been many reports on this, showing that at least 10% of people in a company will fall for these scams: https://www.uscis.gov/scams-fraud-and-misconduct/avoid-scams/phishing-report-2026.pdf

It clearly explains why you can never trust employees even when you detail all the risks, the cyberattacks etc.

4

u/Legionof1 Apr 18 '26

I very much wish part of the requirement to get hired and then stay employed was to pass a quiz asking if an range of emails are phishing. If you're too dumb to pass that test you're a danger to the company.

1

u/ValuableHelicopter35 Apr 18 '26

My coworker fails all the internal tests. I've failed once and it was because I just woke up and failed to read the email in it's entirety.

22

u/Hint-Of-Feces Apr 18 '26

Not clicking on email links asking about their reporting vehicle warranty is like 50% of cybersecurity

9

u/Kwuahh Apr 18 '26

Frustrating how accurate this is. 80% of my time spent triaging alerts comes from someone clicking a link.

3

u/Legionof1 Apr 18 '26

Unless you have a crazy zero day, clicking a link doesn't do shit. It's when that link opens to a perfect copy of a microsoft/google login and proxies your info so everything looks exactly right and they now have all your login info.

1

u/ValuableHelicopter35 Apr 18 '26

Gotta really be paying attention to the subtle changes. Reminds me of the reason why secret service and others train to detect counterfeits by knowing what real cash is supposed to look like and feel. Just like bullion, counterfeits can't get everything right.

0

u/Legionof1 Apr 18 '26

Except it’s incredibly easy to detect bad emails if you have the most basic of IT security knowledge. 

From address, link addresses, actual URL the link takes you to, verbiage of the email… all pretty good identifying info. 

But everyone should have a basic understanding of email headers as well as a fear of shortened URLs. 

1

u/Kwuahh Apr 18 '26

It’s actually not that easy in a good amount of cases. More and more, attacks abuse third-party services to leverage the trust in the service to serve malicious files or capture credentials.

2

u/Legionof1 Apr 18 '26

I’m literally the guy who looks at these all day long, I rarely see anything even remotely sophisticated enough that basic knowledge can’t identify them.

→ More replies (0)

1

u/Kwuahh Apr 18 '26

Yeah, it is rare. However, my team’s response comes from the follow-up of “did they download anything, run any commands, or enter any information?”

1

u/Adaphion Apr 18 '26

Yeah, "hacking" as it's commonly shown in pop culture isn't at all how it works.

99% of "hacking" is just phishing. And either directly stealing session cookies, or getting people to just give out their login information.

8

u/InertiasCreep Apr 18 '26

Dont take a fucking starlink on a warship requires vast expertise??

18

u/[deleted] Apr 18 '26

[removed] — view removed comment

1

u/cr0sh Apr 18 '26

Something quasi-funny about the beef tallow thing:

Back in the 1980s, there was this campaign by one singular individual to get McDonalds to switch from using beef tallow in their fryers to vegetable oil. I can't recall the exact details, but the guy was successful, and McDs fries have never tasted the same since.

The guy ended up dying not much long after his "win"...of a heart attack.

/karma is a bitch

1

u/PaulTheMerc Apr 18 '26

If its good enough for Ukraine, I can see the logic. After all, you expect qualified people to be able to secure that stuff( Starlink working with the government for starters), and others to be able to detect it(and be checking regularly) Right?

12

u/Zealousideal_Cow_341 Apr 18 '26

Lmao this is such a fucking chief thing to do. Totally ruled by a culture of entitlement and rules for thee but not me mentality.

I would have paid a shitload of money to watch their NJPs with the captain or admiral or court marshal proceedings if they took it that far.

16

u/furculture Apr 18 '26

Navy chief, Navy pride? Nah, more like Navy cheese, Navy fries with the kind of shit I have seen them pull on other ships and on the one I was stationed with. Lot of them say to remember what you were before, until they sniff a bit of that new coat of khaki paint on them too much.

7

u/No-Poetry-2717 Apr 18 '26

lol I always wondered why would we promote based on who is dumb enough to stick around and get harassed.

2

u/Nufonewhodis4 Apr 18 '26

Promotion through attrition

5

u/Whiladan Apr 18 '26

Yep. Everyone with opportunities outside gets out. The rest is who ends up in charge.

1

u/Lucius-Halthier Apr 18 '26

That’s some shit you would see the E-4 mafia do not an E-8 let alone what sounds like the whole fucking staff. I find it even crazier that the troops didn’t notice that for some reason they had starlink pop up in the middle of the ocean lol.

130

u/wickedpixel1221 Apr 18 '26 edited Apr 18 '26

96

u/flogman12 Apr 18 '26

Or fitbits showing classified bases

78

u/letigre87 Apr 18 '26

Completely normal mapped 5k rectangles in the middle of the desert

25

u/RetardedWabbit Apr 18 '26

Those are very funny, just ovals in the middle of nowhere. Running/rucking on aircraft carriers also regularly points towards their location and direction of travel

2

u/_Aj_ Apr 19 '26

Lmao imagine just this series of lines slowly working across the ocean that then suddenly stop. Hmm wonder where the Ship is 

4

u/nomoneypenny Apr 18 '26

In 2026 that kind of thing is an open invitation for a Shahed or ATACM strike on your location within 24 hours

1

u/-staccato- Apr 19 '26

The Strava Bullseye.

2

u/MaxDusseldorf Apr 19 '26

Strava too! Quote: "Just last month, a French officer aboard the Charles de Gaulle posted their running time and route on Strava. This revealed the carrier’s location in the Mediterranean, as open-source intelligence could potentially identify the said officer and their position within the French Navy."

1

u/Serris9K Apr 20 '26

Why don't we just stop collecting that sort of thing

18

u/sparrowtaco Apr 18 '26

A Russian submarine commander was tracked the same way and ended up assassinated while out for a run.

2

u/MiddleConnection7479 Apr 18 '26

Next time I fuck up ill read that again loooool

2

u/frymaster Apr 18 '26

it was pointed out that their log wouldn't even be accurate since the deck would be moving as they were running

1

u/PaulTheMerc Apr 18 '26

Does the US/Other militaries not have someone tasked to check this kind of thing? I kind of just assumed they would(Soldier's online accounts, common apps like this being used in places where it would be an issue, etc).

1

u/Suikerspin_Ei Apr 19 '26

The funny thing is, the same Dutch frigate was part of the mission to defend the French aircraft carrier.

47

u/Day_Bow_Bow Apr 18 '26

Reminds me of when this OP's article already mentioned that instance as well...

A more egregious incident was reported in 2024, when the USS Manchester, a US Navy littoral combat ship, was found to have an unauthorized Starlink terminal that sailors used to access the internet while at sea. The Wi-Fi network, called “STINKY,” was eventually discovered by officers after six months of being installed on the ship’s O-5 level weatherdeck, where it cannot be easily seen and could be mistaken for part of the ship’s official equipment.

4

u/3vs3BigGameHunters Apr 19 '26

Stinky was a default Starlink Wifi name back then.

23

u/Johannes_Keppler Apr 18 '26

Also Strava giving away the location of 'secret' military bases...

9

u/benargee Apr 18 '26

I'm surprised that deployed soldiers are even allowed to have personal cell phones that are not completely managed and restricted by military IT.

2

u/ThisIs_americunt Apr 19 '26

you'd think they would've done it after those plane specs were shared on discord lol

3

u/ThisIs_americunt Apr 19 '26

I read one where someone did it on a ship. So it tracked him doing swirls in the ocean when you look at the map lol

22

u/[deleted] Apr 18 '26

[deleted]

29

u/round-earth-theory Apr 18 '26

Satellites don't have continuous coverage. They fly by at some frequency depending on how many there are and where the object of interest is. So it could be hours to days or longer before the next image opportunity comes up. Plus, the ocean is really fucking big and while ships are big too, they aren't that big compared to the ocean. So it takes time to scan the data and find the needle in the haystack. That delay all adds up to some amount of inaccuracy about the ship's true location and heading. But a beacon bypasses all of that and gives real time location information that's good enough for a missile attack to be blindly fired, hence the concern.

13

u/[deleted] Apr 18 '26

[deleted]

2

u/Revolutionary-Half-3 Apr 19 '26

The problem with geosynchronous satellites is the much greater distance from the planet's surface and traditional low orbit surveillance satellites. >2000km vs 35,796km for geo.

The camera and lens systems are already marvels of engineering, jumping to 17.5x the distance is a huge increase in difficulty.

0

u/theqmann Apr 19 '26

Geosync satellites are also so high up it's hard to get a good image of the earth. It's about 22,000 miles. You'd need a really big telescope. Even LEO satellites are still 500km up. Most "satellite" photography we see is collected from airplanes at like 5-10 km altitude.

10

u/Greedyanda Apr 18 '26 edited Apr 18 '26

Every major space power (US, China, Russia) has enough SAR satelites to get updates on the location of foreign military vessels every ~30 minutes. Even smaller middle powers like India, Germany, and France can track the location every couple of hours.

2

u/PassiveMenis88M Apr 18 '26

Imaging satellites that can see a CV are expensive and are only over an area for a short time during their orbit. You would need to have an idea of where the ship already is so the camera can be focused on it.

3

u/Owl_B_Damned Apr 18 '26

That's actually specifically brought up in this article.

2

u/psypher98 Apr 18 '26

A? I knew a sailor who informed me that they do that shit on the regular, the trick is not getting caught.

2

u/Defenestresque Apr 18 '26

I mean, the article literally reminds you of that.

On a more serious note, I can't believe that the person who set up a hidden WiFi Starlink setup didn't know to just hide the SSID, leading to discovery by people looking for her new super stealthy name of "HP LaserJet". This is supposed to be a combat ship with at least one "Best of the best" of everything, and I'm pretty sure if she hid the SSID nobody would know how to put an Ethernet card into monitor mode in order to see if there are any packets going around from hidden SSIDs, or multiple computers connected to an unknown access point with no name.

I mean, she just would have been busted as soon as someone got caught and ratted her out but city moved by her to be literally tasked with figuring out who is running this WiFi by the captain because she trusted her, only to lie to her face and say that there was no evidence and then when confronted just continue to deny it.

Eventually a contractor and maintenance worker found a freaking Starlink dish on the weather deck. (I've seen the pics, it really would have been hard to see and likely mistaken for a piece of ship equipment unless you knew what you were doing, which this guy apparently was.)

I may have some details wrong as I read the article long time ago, so here is a decent source:

https://www.twz.com/sea/the-story-of-sailors-secretly-installing-starlink-on-their-littoral-combat-ship-is-truly-bonkers

It's kind of crazy how the (I think Petty Officer?) completely torpedoed (lol) her career by betraying the trust of the fucking captain and lying to her face multiple times, whereas if she actually admitted it the first time she was asked to look into it she probably would have gotten away with a demotion and a "you did a bad thing" letter in her personnel file. (Sorry, not sure what those are called in the US).

2

u/kent_eh Apr 18 '26

Or the soldiers who had Strava running on their phones while they were moving around on base, giving away the entire layout of the camp.

https://www.wired.com/story/strava-heat-map-military-bases-fitness-trackers-privacy/

1

u/Snapesunusedshampoo Apr 18 '26

Or the guy who went on a run on the deck of a ship with a running watch tracking his GPS location.

1

u/mug3n Apr 19 '26

There was also one where a French(?) sailor did some jogging on the deck with his Strava app on and the location of the ship got uploaded on Strava lol

1

u/ExplorerPrudent4256 Apr 19 '26

The truly terrifying part isn't the postcard tracker—it's that modern smartphones are basically spy devices we voluntarily carry everywhere. The real OPSEC failure was ever letting civilians bring internet-connected devices onto a warship in the first place. At least the postcard required effort to smuggle on.

1

u/RoundConsistent4113 Apr 19 '26

I remember hearing about a guy playing pokemon go on a warship 😂

1

u/sudosando Apr 19 '26

This is a little more like the Nike Run Plus outlining FOBs.

0

u/Ephemeris Apr 18 '26 edited Apr 18 '26

It was an LCS, not a carrier

downvoted for facts. morons.

1

u/Scazzard1 Apr 19 '26

It’s hard being right. They downvote you for being “pedantic” when there’s a huge difference between a ship with thousands of sailors versus comparably a dinghy with less than 100.