Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

141–150 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#141
post #134
post #77

Earlier quoted context omitted.

I think this can be a downfall of the US military if they ever get into a conflict with a capable enemy. They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. I wonder what would happen to the B-2 bomber or aircraft carriers if they had to fight China. My guess is these weapons would be eliminated very quickly.

> They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. Tell that to Vietnam and Afghanistan. Historically the US does well against standing armies (Iraq for example), but absolutely terribly against low-tech enemies who don't engage in a way that allows these super high tech weapons to be used effectively. Reminds me of this: http://www.kiplingsociety.co.uk…

I meant it in a sense of an enemy that can take on the high tech weapons. Since the Korea war nobody challenged the high tech equipment in meaningful way.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#142
Most of the comments outline how awful and dire the situation is (or probably is).

I'm less interested in this than I am in what we could do to fix it. Is it just more money to hire competent security engineers? Is it a more responsive talent acquisitions process that gets the right people in at the right time?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#143

Earlier quoted context omitted.

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…

> It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. If that was the whole story, the military budget would be plummeting as our representatives realized that they could also , and far more legitimately, take money away from the military to put in their pet projects.

For political reasons it can be easier to justify defense spending. Then you just make sure that it's _your_ pet project that gets the spending.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#144

If you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about…

How can one best reach you?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#145

Most of the comments outline how awful and dire the situation is (or probably is). I'm less interested in this than I am in what we could do to fix it. Is it just more money to hire competent security engineers? Is it a more responsive talent acquisitions process that gets the right people in at the right time?

There is no motivation on the defense contractor side to do anything more than satisfy the requirements of the contract. And any R&D spent should result in an interesting demonstration that brings in more business.

Standard operating procedure would need to change so the government entity has security as a requirement, details on how the requirement can be satisfied, and a bunch of money to pay for it.

So tack on $X million for each contract to have a 3rd party audit the code, documentation, and hardware for security vulnerabilities. And an added maintenance contract to fix any future vulnerabilities for the lifetime of the program (20+ years most likely).

From the higher up side, what do you get for all that money spent? No new functionality, no fancy demos. Going to be hard to convince them security is important when they can fund something they view as more critical or more interesting.

EDIT: To answer the question of what can be done, I think it'd require a culture change on the contracting side. The engineering side of the house is mandated to only do work that relates directly to the contract. The hours bid will likely be for the minimum necessary to satisfy those requirements. You can create a new interface, but you won't have the time to do any fuzz testing for example.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#147

Earlier quoted context omitted.

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…

> It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. If that was the whole story, the military budget would be plummeting as our representatives realized that they could also , and far more legitimately, take money away from the military to put in their pet projects.

False they can’t cut it back for economic reasons. The economy is based on it

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#148

If you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about…

How can one best reach you?

You can reach me at harlan@dds.mil!

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#150
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

A side note: the picture in the first few pages of the pdf looks like the original authors intent, aka, not pointing to a particular part of the fake plane for each subsystem. The picture on the web was "upgraded" editorially to point to specific parts for... ? Marketing reasons? Not sure but its hilarious because the logistics system of the web version of the fake plane is in a missile.

> the logistics system of the web version of the fake plane is in a missile.

To be fair, it could also be a death ray laser. The whole thing looks a lot more like Star Wars than a real plane. It has asymmetrical wings.

Post reply on HN