Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

61–70 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#61
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a reg…

The problem isn't just MBAs. It's that scientific management has become central to the DoD's mode of functioning. Which is remarkably sad. The DoD in the WWII and post-WWII era actually developed a lot of good systems engineering practices and was largely successful on some massive projects.

Since then, however, there has been the constant desire to deskill workers. That is, they want explicit operating/work instructions that mean even a trained monkey could do the job. This is useful for some things (got a broken down Jeep? Pull out the manual and even your Lt can fix it!), but for development, acquisitions, and sustainment this is actually a horrible idea.

The infection of deskilling spread to the office. They've removed the office managers (among others) and left the work (critical, but time consuming and secondary to the mission) with the highly educated and trained staff. This diminishes their ability to focus on real work (see [0] from yesterday). From there, they continued to try to document precisely how engineering work is done. Believing that the process of the work is the same as the work. So if only my engineers knew how to properly fill out SF-1234 it wouldn't matter how educated they are, magically the work would be done.

Of course, we all know this is bullshit. Knowledge work is called that for a reason. The capacity for work is based on the knowledge of the workers. You cannot deskill computer science or aerospace engineering. You can deskill aspects of it, or really the workflow, but not the science and engineering work itself. I can eliminate or largely reduce the need for a classical configuration manager by establishing a (automated) peer review and version control workflow. But the creative act producing content that enters the workflow will always require skilled, competent, knowledgeable engineers and scientists.

[0] https://news.ycombinator.com/item?id=18157885

EDIT: I will not change the above, but I will make a note. After re-reading the Wikipedia page on Scientific Management [1] I see that some people consider Lean and others to also be extensions of it. So read the above as describing Fordism and Taylorism, not scientific management in general. Any management largely based on, or influenced by, statistics, models, and experimentantion could be argued to be "scientific management", that doesn't mean it's bad. It's when it's taken to an extreme. Like, in Taylor's case, where workers are treated with contempt. The purpose of the management being to make them fully expendable. They had no unique knowledge or skills that could really contribute to the business beyond their physical presence and ability to follow directions. His goal was to disempower workers, whereas other examples (Lean particularly) work to empower workers.

[1] https://en.wikipedia.org/wiki/Scientific_management

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#62
post #20

You'll see things here that look odd, even antiquated to modern eyes. Phones with cords, awkward manual valves, computers that barely deserve the name. But all of it is intentional. It's all designed to operate in combat against an enemy who could infiltrate and disrupt all but the most basic computer systems. Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder…

No networked computers on my ship.

Reminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#63
post #23

I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.

> The enemy here is fairly low-tech. Shouldn't be a problem. Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.

Sounds like classic underestimation of your opposition.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#64
post #20

You'll see things here that look odd, even antiquated to modern eyes. Phones with cords, awkward manual valves, computers that barely deserve the name. But all of it is intentional. It's all designed to operate in combat against an enemy who could infiltrate and disrupt all but the most basic computer systems. Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder…

No networked computers on my ship.

Your car probably has a dozen networked computers, unless it's a really old one.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#65
post #42

Earlier quoted context omitted.

Based on what? He's quoting people he talked to and reports what he's seen. Whereas you just naysay.

Based on my first-hand experience as a solider in the US Army, talking to 4-5 low-ranked sailors is unlikely to give a meaningful picture of the whole system. I don't have specific experience with Navy systems to judge the technical details of komali2's post, but I would caution against taking a summary of second-hand accounts from operators as fact.

>>I don't have specific experience with Navy systems to judge the technical details of komali2's post

Well, there you go then. Thanks for being honest at least.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#66

Earlier quoted context omitted.

No networked computers on my ship.

Reminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.

There's a reason it reminds you of it...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#67
post #53

Earlier quoted context omitted.

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

That isn’t remotely how it works.

What exactly do you mean? The specific scenario I described in very, very broad terms was from a lecture by Eric S. Lander about a specific bacterial cell. If you have an issue with the general description I don't understand it, since you don't say anything at all apart from some snide comment that doesn't even make sense to me. At the very least I would expect someone who bothers to reply because they disagree to say what exactly it is they disagree with, and also be specific about it. While I'm a CS person I have a broad background in life sciences too.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#68

Earlier quoted context omitted.

> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a reg…

> an MBA only led business with no influence from engineering/security As an MBA holder and avid HN user, I take issue with that statement...

You should note specific issues, rather than a general complaint.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#69
post #21

Earlier quoted context omitted.

> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a reg…

> scary if the military is driven like an MBA only led business with no influence from engineering/security Having known many people that worked in/around the military and defense industry, this seems like our reality.

[deleted]

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#70
post #19
post #10

Earlier quoted context omitted.

Can you expand? Why are the IT people I talked to, working on these systems, so poorly informed about how they work?

First, most IT personnel on ships (especially one as ancient as the Bonhomme Richard) do not work on weapon systems. Most of them would not even be able to discuss where on the ship they are intelligently, let alone what they connect to. The people you talked to simply aren't informed. You even note that you were talking to 19 year old kids, and they're not generally the ones who know what's going on.

Well that's a question I have as well - who actually knows what's going on there?
Post reply on HN