Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

71–80 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#72
post #6

Earlier quoted context omitted.

The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

It's not about taking over. Disabling them is sufficient.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#73
post #53

Earlier quoted context omitted.

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

That isn’t remotely how it works.

Itsme, I believe the disagreement is not with your statement about biology, but with its comparison with software systems.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#74
post #8

Earlier quoted context omitted.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

I too toured the boat. > The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.…

"The Osprey is a marvelous piece of engineering that is difficult to replicate by other nations."

Whatever I have heard about the Osprey nobody should want to replicate it. Too expensive, too complex.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#75
post #72

Earlier quoted context omitted.

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

It's not about taking over. Disabling them is sufficient.

I did not specify an exact scenario because that was not the point I was trying to make (it was actually meant mostly as a joke, no?). If they already have to fight with so many bugs, disabling it will be just as hard on the one hand, and the operators already have top live with disabling issues in the non-invaded system, as one comment posted here said, they didn't even notice the invasion because it didn't feel different from normal operation :-)

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#76
post #6

Earlier quoted context omitted.

The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

Actually yes. It takes a horde of military personnel to operate the hodgepodge of modern military information systems and technologies. There's nothing easy about it. All sorts of incompatible and buggy tools. Our enemies would have a hard time putting to work the military command & control apparatus -- I mean, we already have trouble enough as it is.

But that doesn't mean the enemy can't learn information and be able to predict our next moves in a conflict. Like what we did with the enigma in WWII, we are subject to the same type of listening where someone knows our next move before we make it.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#77
post #23

I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.

> The enemy here is fairly low-tech. Shouldn't be a problem. Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.

I think this can be a downfall of the US military if they ever get into a conflict with a capable enemy. They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. I wonder what would happen to the B-2 bomber or aircraft carriers if they had to fight China. My guess is these weapons would be eliminated very quickly.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#78
post #7

Earlier quoted context omitted.

>Multiple weapon systems used commercial or open source software, but did not change the default password when the software was installed, which allowed test teams to look up the password on the Internet and gain administrator privileges for that software.

Even worse is that institutional problem where you have people constantly cycling on and off of this hardware that was never designed for a multi-user environment, so default passwords are the order of the day. At best they changed the password and then put it on a sticky note attached to the monitor. The last thing you want is someone forgetting their password to their tactical system while out at sea and having to…

> And really, the first case is no worse than the old days with manual controls that just anybody could walk up and fiddle with.

In that case, you could trust physical security to some extent; someone really not intended to be in contact with the device could be prevented from doing so by some dude with a big gun. Now, those devices are networked, so someone could figure out an access method and use it on all the devices in the field at will.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#79
post #53

Earlier quoted context omitted.

That isn’t remotely how it works.

Itsme, I believe the disagreement is not with your statement about biology, but with its comparison with software systems.

The joke was not about software specifically, but about the whole system, everything. But even software feels like evolutionary forces are at work - when you work on huge systems developed and added-to over years, sometimes decades, often by new people (lots of churn, contractors), the "design" is less and less visible and it becomes a mess, the role of deciding whether a new "gene" (feature/big fix) works is taken by the (also messy) huge test suite and since nobody understands the whole system any more people code to pass those tests. I made the comparison looking back at when I once was part of those adding to a huge existing piece of software without understanding (it had become impossible, the only objective was to have the tests pass, or even just most of them).

When I later also took biology classes (and org. chem., biochem., physiology etc etc) I could not help but see parallels - I say parallels, not transferring the models over! - to how we develop huge systems, be it software, hardware or the combination of both. No single human understands even a significant part of them any more. "Deliberate design" is not the sole force working on those systems any more.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#80
post #3

Earlier quoted context omitted.

> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.

It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.

I don't know that it's just the procurement strategies to blame. Many years ago, I was asked to bring a command and control system into (Orange Book) C2 compliance. Among the things I introduced were personal user accounts with some restrictions around allowable passwords. The users of the system (most of which were "former" fighter pilots) were furious with the restrictions, which they viewed as getting in the way of their jobs. They invariably created a shared login with the simplest password they could come up with that would meet the requirements (e.g., Abc123 or some such).

Security can't be imposed by the system on its users. They have to cooperate.

Post reply on HN