Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

131–140 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#132
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…

It is absolutely happening in enterprise software. I have met sales guys and startup advisors that prided themselves in being able to play that game well. In a certain segment of this industry, you get laughed at if you try to actually come up with a solution.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#133
post #130

Earlier quoted context omitted.

The assumption that MBAs do not have domain experience is often incorrect. Stereotyping is supposedly frowned on in the comments here.

> The assumption that MBAs do not have domain experience is often incorrect. Stereotyping is supposedly frowned on in the comments here. Obviously not. I think the critique is about MBAs who don't have domain experience and don't think they need it, because they have a generically-applicable "management skill." That ponderous specification is typically shortened to "MBAs" for brevity, since it apparently has some roo…

No modern business school actually teaches such an ideology. Have you ever attended one?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#134
post #77

Earlier quoted context omitted.

> The enemy here is fairly low-tech. Shouldn't be a problem. Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.

I think this can be a downfall of the US military if they ever get into a conflict with a capable enemy. They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. I wonder what would happen to the B-2 bomber or aircraft carriers if they had to fight China. My guess is these weapons would be eliminated very quickly.

> They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance.

Tell that to Vietnam and Afghanistan. Historically the US does well against standing armies (Iraq for example), but absolutely terribly against low-tech enemies who don't engage in a way that allows these super high tech weapons to be used effectively.

Reminds me of this: http://www.kiplingsociety.co.uk/poems_arith.htm

  A scrimmage in a Border Station-
  A canter down some dark defile
  Two thousand pounds of education
  Drops to a ten-rupee jezail[1].
  The Crammer's boast, the Squadron's pride,
  Shot like a rabbit in a ride!
1. https://en.wikipedia.org/wiki/Jezail

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#135
post #72

Earlier quoted context omitted.

It's not about taking over. Disabling them is sufficient.

I have been thinking the recent Navy navigation related crashes are related to enemies tampering with systems. They are testing live how weak a windows based fighting ship is. https://www.wired.com/1998/07/sunk-by-windows-nt/

There is zero evidence of enemy tampering in recent Navy ship collisions / allisions. It was simple incompetence and bad luck. There's really no way to tamper with shipboard surface radars, binoculars, horns, and VHF radios. As long as that equipment is working correctly all collisions can be avoided.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#136
post #8

Earlier quoted context omitted.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

I too toured the boat. > The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.…

The Osprey is shit engineering. It can't even fly in a dust cloud, which makes it essentially useless for one of its main intended missions.

https://medium.com/war-is-boring/the-v-22-can-t-spend-even-o...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#137

Earlier quoted context omitted.

"Show me the incentive, I'll show you the outcome"

This is more like: "Show me the outcome, I'll guess the incentive"

That's fair, parent is post-hoc theorizing.

I have to hope that the people in charge of these things -do- care, and that it's simply difficult to get this right. However, given some of the things in the PDF, one has to wonder...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#138

If you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about…

If this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#139
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…

>It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth.

If that was the whole story, the military budget would be plummeting as our representatives realized that they could also, and far more legitimately, take money away from the military to put in their pet projects.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#140

If you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about…

If this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.

Yup! We’re all employees of the federal government, so we have to meet the requirements of all Federal positions.

Honestly, you don’t do this job for the money. I took a pay cut when I joined, on top of losing bonuses and equity. You join because you want to make a real difference in people’s lives, in a visceral, real way.

I can say without exaggeration that there are people who would have died except for the work that our team had done. Even when the stakes aren’t life or death, the impact you can have working for USDS is massive compared to anywhere else. You can personally change the lives of hundreds of thousands or millions of people. That’s the kind of hook that beats equity for me any day.

Post reply on HN