Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

91–100 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#91
post #41

Earlier quoted context omitted.

Is there any reason to believe the state of Russian/Chinese/etc. security is any better in this regard?

Russia's aging military hardware is an asset in this case, as it's not as vulnerable to electronic intrusion as a result of having little to intrude.

Then there's a good argument the billions the DOD spends on its "modernization efforts" should be spent elsewhere.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#92
post #68

Earlier quoted context omitted.

You should note specific issues, rather than a general complaint.

When people blame things on MBAs here, they tend to not elaborate with specifics either. MBAs are used as straw man punching bags on HN. Anything that goes wrong with a company where there’s the perception that the “obvious technical solution” was ignored, is blamed on this nebulous cabal of MBAs, who are apparently hired in droves just to sabotage their employer. For some reason it’s totally ok to vaguely blame the…

> MBAs are used as straw man punching bags on HN. Anything that goes wrong with a company where there’s the perception that the “obvious technical solution” was ignored, is blamed on this nebulous cabal of MBAs, who are apparently hired in droves just to sabotage their employer. For some reason it’s totally ok to vaguely blame the business folks.

I think you're building a bit of a straw man. I think the criticism of MBAs rests on criticism of the idea that good decisions can be made by people that chiefly have "management skill" but lack "domain skill." A lot of people believe domain skill is extremely important, and if you stuff an organization full of empowered people who only have management skill, you'll get more bad decisions. You'll also get a lot of dysfunction as they spend too much time pursing the "management ideas" they're more comfortable with, and neglect "domain ideas."

This comment actually touches on some of these issues in detail: https://news.ycombinator.com/item?id=18179247

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#93

Earlier quoted context omitted.

No networked computers on my ship.

Reminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.

No shields, and this is a direct quote... from a character... who's a cylon!

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#94
post #89
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

"Show me the incentive, I'll show you the outcome"

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#95
I guess my question then is why have a computer attached to these systems in the first place, or if you must, why not make it as dumb as possible? Why include more points of failure?

Also, I couldn't help it, the DOD plans to spend 1.66 Trillion on these systems! Perhaps if we instead stop making new fangled, more complicated devices that with have tenfold more vulnerabilities to catch, how about we just stick with the machines we have and make then hardened. I imagine that it would save us loads if we just do that.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#96
post #35

Earlier quoted context omitted.

They are trusted by internal machines -- since a lot of internal authentication relies on these certificates. The DOD long ago moved away from password-based authentication mechanisms to certificate-based authentication (GSC-IS initially (CAC), now NIST SP 800-73 (PIV; CAC II)) and so the system will have the correct certificates or the user generally won't be able to login. What I find as the most common error is th…

This bit is curious. I was issued a CAC while I was in, and as you said, it eliminated the need for passwords. But the internal sites (no matter if it was a laptop from the comm section, a hardwired desktop in a unit's building, or a desktop in a base facility) always failed the check for the certificate store. I always got the security warning (or insecure message) regardless of browser.

Slightly off-topic - but its semi-relevant here as this conversation involves the requirement of knowing (1) the state of the system security store (2) the state of an application's security store ... and maybe in some cases (3) understanding how an application modifies any trusted stores.

It seems we end up with a lot of possibilities for the states of these stores to diverge from our expectations ... I've been wondering how to verify a sane state for all these stores for even a use as simple as my own personally owned/controlled notebook ...

I'd really like a way to audit the system trust store in macOS and enforce that is in alignment with whatever the current 'blessed by apple' certificate trust relationships are and that any trust relationships I ever manually added by mistake/debugging have been removed...

I asked a question about this on stackoverflow but no one has responded ...

https://stackoverflow.com/questions/52527886/revert-all-cert...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#97
post #72

Earlier quoted context omitted.

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

It's not about taking over. Disabling them is sufficient.

Precisely.

> expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized use of an asset

This is the objective of the adversary in a conflict with respect to information and systems security. It doesn't matter if they can control a system, if they can make it less reliable it's still a win (but not as good). If they can get it to feed out false or misleading information to their opponent, it's a win (hacked a radar, can you show an extra blip on the screen or cause them to sometimes shift position and reduce the confidence of the operator?).

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#98
post #53

Earlier quoted context omitted.

That isn’t remotely how it works.

What exactly do you mean? The specific scenario I described in very, very broad terms was from a lecture by Eric S. Lander about a specific bacterial cell. If you have an issue with the general description I don't understand it, since you don't say anything at all apart from some snide comment that doesn't even make sense to me. At the very least I would expect someone who bothers to reply because they disagree to sa…

If the bugs were annoying enough that they'd prevent proper functioning of the system, they'd be fixed. If the current users are able to get some utility out of the system with all the bugs, then you can be rest assured so will the hackers.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#99
post #86
post #23

I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.

The catch is that on DOD systems, encryption is very difficult to add. That is, to be certified by the NSA and compatible with the military key infrastructure. So its better to avoid mentioning it unless its forced on you. Better is a relative term here. I mean, in terms of cost and effort to add. Not security.

So since it's hard to get the rubber stamp you just do include encryption, that seems worse.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#100
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

"Show me the incentive, I'll show you the outcome"

This is more like: "Show me the outcome, I'll guess the incentive"
Post reply on HN