Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

51–60 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#51
post #21

Earlier quoted context omitted.

> scary if the military is driven like an MBA only led business with no influence from engineering/security Having known many people that worked in/around the military and defense industry, this seems like our reality.

The modern DoD is based around the Asst Sec Defs and business processes put in place by Robert McNamara, who came from Ford. It's all stats and businees. Engineers and scientists are generally considered a sideshow, a workforce to quantitate.

This is, unfortunately, all too true.

> “An interesting question is, ‘Where did the name, dynamic programming, come from?’ The 1950s were not good years for mathematical research. We had a very interesting gentleman in Washington named Wilson. He was Secretary of Defense, and he actually had a pathological fear and hatred of the word, research. I’m not using the term lightly; I’m using it precisely. His face would suffuse, he would turn red, and he would get violent if people used the term, research, in his presence. You can imagine how he felt, then, about the term, mathematical. The RAND Corporation was employed by the Air Force, and the Air Force had Wilson as its boss, essentially. Hence, I felt I had to do something to shield Wilson and the Air Force from the fact that I was really doing mathematics inside the RAND Corporation. What title, what name, could I choose? In the first place I was interested in planning, in decision making, in thinking. But planning, is not a good word for various reasons. I decided therefore to use the word, ‘programming.’ Iwanted to get across the idea that this was dynamic, this was multistage, this was time-varying—I thought, let’s kill two birds with one stone. Let’s take a word that has an absolutely precise meaning, namely dynamic, in the classical physical sense. It also has a very interesting property as an adjective, and that is it’s impossible to use the word, dynamic, in a pejorative sense. Try thinking of some combination that will possibly give it a pejorative meaning. It’s impossible. Thus, I thought dynamic programming was a good name. It was something not even a Congressman could object to. So I used it as an umbrella for my activities"

--Richard Bellman on the naming of dynamic programming [1]

[1]: http://smo.sogang.ac.kr/doc/dy_birth.pdf

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#53
post #6

Earlier quoted context omitted.

The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

That isn’t remotely how it works.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#54
post #23

I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.

> The enemy here is fairly low-tech. Shouldn't be a problem.

Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#55
post #20

You'll see things here that look odd, even antiquated to modern eyes. Phones with cords, awkward manual valves, computers that barely deserve the name. But all of it is intentional. It's all designed to operate in combat against an enemy who could infiltrate and disrupt all but the most basic computer systems. Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder…

No networked computers on my ship.

[deleted]

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#56
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

Aren’t there reams of security standards and thousands of man-years of security compliance bureaucracy for even the most basic DOD IT projects? And they still have trivial vulnerabilities like this? Is the process really that useless?

Bureaucracy not only does not discourage vulnerabilities unless they're on a very short list, it actively encourages them by driving away the kind of imaginitive thinking you need to think of them.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#57
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

[deleted]

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#58
post #20

You'll see things here that look odd, even antiquated to modern eyes. Phones with cords, awkward manual valves, computers that barely deserve the name. But all of it is intentional. It's all designed to operate in combat against an enemy who could infiltrate and disrupt all but the most basic computer systems. Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder…

No networked computers on my ship.

No networked computers? I do not believe you. Even my little soft-skinned two-person wheeled command vehicle has a network of about twenty discrete computer systems, such as multiple radios, GPS, displays, input terminals.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#59

Earlier quoted context omitted.

Is there any reason to believe the state of Russian/Chinese/etc. security is any better in this regard?

No, but all that does is ensure we all lose collectively

That is true of any war that the US has even a remote possibility of losing.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#60
post #4

> Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise. It's not too surprising and a little reminiscent of the security nightmare that are IoT devices. All those weapon systems come out of hardware/engineering companies with little background in software engineering and the accompanying security best pr…

They don't know how to hire a security advisor or external team?

What I'd be most concerned about is that the procurement process is favouring companies who clearly aren't up to designing in rudimentary security, in weapons systems, ... smh.

That seems like getting clothing made and not having anyone flag that it was glued together with PVA instead of being sewn; and the company you hiredb not having anyone who realises that's a fundamental problem.

Post reply on HN