DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
71–80 of 225 posts
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#72Earlier quoted context omitted.
The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .
They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#73Earlier quoted context omitted.
They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…
That isn’t remotely how it works.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#74Earlier quoted context omitted.
I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…
I too toured the boat. > The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.…
Whatever I have heard about the Osprey nobody should want to replicate it. Too expensive, too complex.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#75Earlier quoted context omitted.
They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…
It's not about taking over. Disabling them is sufficient.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#76Earlier quoted context omitted.
The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .
They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…
But that doesn't mean the enemy can't learn information and be able to predict our next moves in a conflict. Like what we did with the enigma in WWII, we are subject to the same type of listening where someone knows our next move before we make it.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#77I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.
> The enemy here is fairly low-tech. Shouldn't be a problem. Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#78Earlier quoted context omitted.
>Multiple weapon systems used commercial or open source software, but did not change the default password when the software was installed, which allowed test teams to look up the password on the Internet and gain administrator privileges for that software.
Even worse is that institutional problem where you have people constantly cycling on and off of this hardware that was never designed for a multi-user environment, so default passwords are the order of the day. At best they changed the password and then put it on a sticky note attached to the monitor. The last thing you want is someone forgetting their password to their tactical system while out at sea and having to…
In that case, you could trust physical security to some extent; someone really not intended to be in contact with the device could be prevented from doing so by some dude with a big gun. Now, those devices are networked, so someone could figure out an access method and use it on all the devices in the field at will.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#79Earlier quoted context omitted.
That isn’t remotely how it works.
Itsme, I believe the disagreement is not with your statement about biology, but with its comparison with software systems.
When I later also took biology classes (and org. chem., biochem., physiology etc etc) I could not help but see parallels - I say parallels, not transferring the models over! - to how we develop huge systems, be it software, hardware or the combination of both. No single human understands even a significant part of them any more. "Deliberate design" is not the sole force working on those systems any more.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#80Earlier quoted context omitted.
> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.
It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.
Security can't be imposed by the system on its users. They have to cooperate.