DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
11–20 of 225 posts
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#12They had some goofballs policies that made it seem like vulnerabilities were the goal. I could bitch at length. Their TSA style security theater practices were the order of the day. The IA training was an embarrassing joke and they made you do it often enough to make you a little crazy.
I just checked the certificate of networthiness page and they don't have a valid SSL certificate. I recall that being the case years ago too. I wonder if it's been that way for the last 7 years? That's a cute little terrarium of the whole biome I remember.
Off topic a bit, but that all aside... I am more proud of the work I did there than at any other place in my career. I got a lot of excitement and engaged feedback about the interactive learning materials I created.
I'll never know if it made any difference, but the mere fact that someone's son or daughter COULD have noticed an IED threat they wouldn't have otherwise because of my work gives me all sorts of proud fuzzies.
That work had way more meaning than all the other CRUD/ML/Advertainment schlock I'll get to do for the rest of my life :)
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#13Earlier quoted context omitted.
I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…
Many of your technical details are badly incorrect. Not sure who you talked to, but they're not well informed.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#14They'll really have to set the passwords properly though.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#15Earlier quoted context omitted.
> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.
The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#16Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#17The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…
"Do you want to play a game?"
This is some scary bad WarGames like security, password 'joshua' level.
> Program offices were aware of some of the weapon system vulnerabilities that test teams exploited because they had been identified in previous cybersecurity assessments. For example, one test report indicated that only 1 of 20 cyber vulnerabilities identified in a previous assessment had been corrected. The test team exploited the same vulnerabilities to gain control of the system. When asked why vulnerabilities had not been addressed, program officials said they had identified a solution, but for some reason it had not been implemented. They attributed it to contractor error.
Ah, the old blame the 'contractor error' and 'not invented here' syndrome. Looks like engineers aren't in the power structure to change these things, scary if the military is driven like an MBA only led business with no influence from engineering/security.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#18The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…
>Multiple weapon systems used commercial or open source software, but did not change the default password when the software was installed, which allowed test teams to look up the password on the Internet and gain administrator privileges for that software.
The last thing you want is someone forgetting their password to their tactical system while out at sea and having to sail back into port to get the vendor to reset it for you.
And really, the first case is no worse than the old days with manual controls that just anybody could walk up and fiddle with.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#19Earlier quoted context omitted.
Many of your technical details are badly incorrect. Not sure who you talked to, but they're not well informed.
Can you expand? Why are the IT people I talked to, working on these systems, so poorly informed about how they work?
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#20Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder of a time when we were so frightened by the capabilities of our enemies that we literally looked backward for protection. Modern battlestars resemble Galactica only in the most superficial ways...