Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

21–30 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#21
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a reg…

> scary if the military is driven like an MBA only led business with no influence from engineering/security

Having known many people that worked in/around the military and defense industry, this seems like our reality.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#22
post #8

Earlier quoted context omitted.

It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

I too toured the boat.

> The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet.

Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.

The Osprey is a marvelous piece of engineering that is difficult to replicate by other nations.

> Every system runs on the same network. This includes radar, weapons systems, anti-air, emergency comms, in-ship cameras...

Physical network or logical network?

> The only thing preventing access to a boat's network is standing orders and the threat of punishment. You can just plug right in.

And then do what once you are in? Unless we are assuming there is zero security, this doesn't mean much. Besides, you have to be on the ship already.

I'm not saying that the systems are adequately protected, they may not (as the article states), but there's too much information missing for us to play the role of security auditors.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#23
I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were:

1. Well, this is rapid deployment, we can't have everything.

2. The enemy here is fairly low-tech. Shouldn't be a problem.

Needless to say, I'm not surprised by this report.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#24
post #12

I was a dev contractor for the US Army for a few years. None of this surprises me. They had some goofballs policies that made it seem like vulnerabilities were the goal. I could bitch at length. Their TSA style security theater practices were the order of the day. The IA training was an embarrassing joke and they made you do it often enough to make you a little crazy. I just checked the certificate of networthiness p…

> I just checked the certificate of networthiness page and they don't have a valid SSL certificate. I recall that being the case years ago too. I wonder if it's been that way for the last 7 years? That's a cute little terrarium of the whole biome I remember.

That's not quite true. Internal use sites don't have a valid cart issued by a "default" external vendor.

Public sites use existing CAs that are in use by the public. E.g., the Marines public facing site[0] is signed by DigiCert. If you go to a site that's public facing but for internal use like MoL[1], you'll see that the cert is issue by an internal DoD CA. This is intentional.

The DoD has an internal CA already set up. These internal use sites are a gateway to sensitive information, so the DoD doesn't want to rely on an external CA for HTTPS. What I never understood was why these internal CAs weren't marked as trusted on the internal machines. That would avoid the browser warnings when accessing one of these site from DoD hardware, and it would (in theory) force the user to double check when accessing the site from an external device.

[0]: https://www.marines.com/ [1]: https://mol.tfs.usmc.mil/mol

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#27
post #6
post #3

Earlier quoted context omitted.

> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.

The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidentally making a protein that is turned off, but sometimes it turns out it's useful to have it around when the environment changes, but an error-free efficient system would not have made it).

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#28
post #8

Earlier quoted context omitted.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

I too toured the boat. > The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.…

>Well, this is not related to the main point about cyber security.

It's a testament to the attitude and quality control practices of the suppliers who also supply the networked equipment.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#29
post #20

You'll see things here that look odd, even antiquated to modern eyes. Phones with cords, awkward manual valves, computers that barely deserve the name. But all of it is intentional. It's all designed to operate in combat against an enemy who could infiltrate and disrupt all but the most basic computer systems. Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder…

Surprise... only one new 'modern battlestar' survived... because it was offline.
Post reply on HN