Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

101–110 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#101

Earlier quoted context omitted.

Reminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.

No shields, and this is a direct quote... from a character... who's a cylon!

*If by some chance you haven't seen the BG reboot by now, this is a bit of a spoiler. :)

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#102
post #4

> Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise. It's not too surprising and a little reminiscent of the security nightmare that are IoT devices. All those weapon systems come out of hardware/engineering companies with little background in software engineering and the accompanying security best pr…

They don't know how to hire a security advisor or external team? What I'd be most concerned about is that the procurement process is favouring companies who clearly aren't up to designing in rudimentary security, in weapons systems, ... smh. That seems like getting clothing made and not having anyone flag that it was glued together with PVA instead of being sewn; and the company you hiredb not having anyone who reali…

Meanwhile, the software companies capable of fixing these issues face internal revolt at the idea of defense contracts. Apparently inaccurate targeting systems and vulnerable firmware in equipment that is going to deployed (regardless of protest) is better for pacifism?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#103
post #21

Earlier quoted context omitted.

> scary if the military is driven like an MBA only led business with no influence from engineering/security Having known many people that worked in/around the military and defense industry, this seems like our reality.

The modern DoD is based around the Asst Sec Defs and business processes put in place by Robert McNamara, who came from Ford. It's all stats and businees. Engineers and scientists are generally considered a sideshow, a workforce to quantitate.

This discussion doesn't make much sense. Economics is the science of making organisations work. It doesn't come with rigid objectives; Those are inputs to the process. Now I'd be glad if the DOD accidentally let a pack of MBAs with default settings do their thing, because they'd probably create a world-wide cartel within the first year, and reduce all the world's standing armies to just themselves in a very fancy conference room within four.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#104
post #89
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth.

I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, actual software doesn't have to work; it only has to serve as an object of trade between companies, and all the problems will disappear in general organizational noise & inertia.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#105
post #12

I was a dev contractor for the US Army for a few years. None of this surprises me. They had some goofballs policies that made it seem like vulnerabilities were the goal. I could bitch at length. Their TSA style security theater practices were the order of the day. The IA training was an embarrassing joke and they made you do it often enough to make you a little crazy. I just checked the certificate of networthiness p…

Thank you for your work and for this comment. Regarding the last line: if you can work in the US and are not hamstrung by personal circumstances, there is no way, given the skills you imply having, that you can't find meaningful work: health care, education, energy all have dozens of good companies straining to find additional competent technical staff.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#106

Earlier quoted context omitted.

The modern DoD is based around the Asst Sec Defs and business processes put in place by Robert McNamara, who came from Ford. It's all stats and businees. Engineers and scientists are generally considered a sideshow, a workforce to quantitate.

This discussion doesn't make much sense. Economics is the science of making organisations work. It doesn't come with rigid objectives; Those are inputs to the process. Now I'd be glad if the DOD accidentally let a pack of MBAs with default settings do their thing, because they'd probably create a world-wide cartel within the first year, and reduce all the world's standing armies to just themselves in a very fancy con…

I think the problem of releasing MBA types on an organization is that they're specialists in business in general, not in whatever a particular organization wants to do. The actual goal is just a parameter - input to the process. And that input can be changed, or abstracted away, and as a result you get a typical soulless corporation - an organization that lost its soul, it's actual object-level goal, and remains a mindless automaton optimizing profits.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#108
post #42

Earlier quoted context omitted.

Based on what? He's quoting people he talked to and reports what he's seen. Whereas you just naysay.

Based on my first-hand experience as a solider in the US Army, talking to 4-5 low-ranked sailors is unlikely to give a meaningful picture of the whole system. I don't have specific experience with Navy systems to judge the technical details of komali2's post, but I would caution against taking a summary of second-hand accounts from operators as fact.

I would take his recollection with a grain of salt but what they told him most likely was more true than false.

So that leaves a number of specific statements which you could each refute, in part or in their entirety. Judging from the title of this article and a number of other anecdotes in this thread (some by other people that served) it seems his anecdote is entirely believable.

That you can't extrapolate to all of the army would be a given.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#109

Earlier quoted context omitted.

Itsme, I believe the disagreement is not with your statement about biology, but with its comparison with software systems.

The joke was not about software specifically, but about the whole system, everything. But even software feels like evolutionary forces are at work - when you work on huge systems developed and added-to over years, sometimes decades, often by new people (lots of churn, contractors), the "design" is less and less visible and it becomes a mess, the role of deciding whether a new "gene" (feature/big fix) works is taken b…

I'd add that most software systems compete on the market, which is as close to direct evolutionary process as you can get in modern environment. And that process has a fitness function that's quite misaligned with what a designer wants at any step of the process.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#110
post #89
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

I would suggest that the problem is too much wriggle room / dissonance during the design process (in nice safe meeting rooms admittedly) We can all persuade ourselves that as all items are ticked, the job is done.

But testing gives the lie to all this. The patriot system was battle tested in the 1990s and its deficiencies became apparent - and lessons seem to have been learnt.

So perhaps more adversarial testing is the right approach - set the marines to take out the air forces weapons, the navy to destroy the army.

If people know their beloved weapons systems are going to get roughed up, then the tick box stops being the determinant of achievement - it becomes "what would one of those navy/marine/air force/army bar stewards do?" That's a much higher bar.

tl;dr blow shit up and see if it still works

Post reply on HN