Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

161–170 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#161
post #134

Earlier quoted context omitted.

> They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. Tell that to Vietnam and Afghanistan. Historically the US does well against standing armies (Iraq for example), but absolutely terribly against low-tech enemies who don't engage in a way that allows these super high tech weapons to be used effectively. Reminds me of this: http://www.kiplingsociety.co.uk…

I meant it in a sense of an enemy that can take on the high tech weapons. Since the Korea war nobody challenged the high tech equipment in meaningful way.

> Since the Korea war nobody challenged the high tech equipment in meaningful way

Le Duan tried to in Vietnam, the Easter Offensive. Despite fighting to a strategic draw, he under-estimated the effectiveness of US airpower and lost 100,000 men on the field.

https://en.wikipedia.org/wiki/Easter_Offensive#Aftermath

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#163
post #154

Earlier quoted context omitted.

I have to quibble with that a bit. The US regularly overflew the USSR and China through at least the mid 70s, meaning our best aircraft were in a very real sense fighting their best air defense systems 20 years+ after the Korean war ended. There have almost certainly been satellite, submarine and other engagements too, they just aren't generally publicized by either side until 30-40+ years later.

True. However, I think in a real shooting war those aircraft could be attacked by a huge number of low tech weapons and get overwhelmed. From what I know about warfare often large numbers will eventually overwhelm every kind of defense. For example could an aircraft carrier handle 10000 incoming drones? I hope we'll never find out...

10,000 drones? How big a drone are we talking? They would have to be big enough to carry a weapon big enough to penetrate at least 1/2" steel (at the thinnest, only accessible from the side). If out to sea, a small EMP could drop them all.

Battles won by numerical superiority are usually won by defenders. If it's an invader, it's almost certainly early in the game. Even at the end of WW2, Germany wasn't invaded so much as it lost in France and Russia. The Allied rush to Berlin was an early aftermath. By the time supply chains necessary to conduct a protracted war have been committed, the true cost starts making invaders progressively less interested.

A more interesting concern is the major powers using proxies to demonstrate their new tech. If Russia sold Syria 10,000 drones, that might get interesting.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#164
post #92

Earlier quoted context omitted.

> MBAs are used as straw man punching bags on HN. Anything that goes wrong with a company where there’s the perception that the “obvious technical solution” was ignored, is blamed on this nebulous cabal of MBAs, who are apparently hired in droves just to sabotage their employer. For some reason it’s totally ok to vaguely blame the business folks. I think you're building a bit of a straw man. I think the criticism of…

The assumption that MBAs do not have domain experience is often incorrect. Stereotyping is supposedly frowned on in the comments here.

I think MBA in its usage implicit means 'with no domain experience' because otherwise there would be a reference to as their most relevant skillset in the field. If someone has domain experience they are a 'senior engineer' with the MBA only coming up if that aspect is relevant. If someone doesn't have and they make it they are just a MBA.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#165
post #128

Earlier quoted context omitted.

The modern DoD is based around the Asst Sec Defs and business processes put in place by Robert McNamara, who came from Ford. It's all stats and businees. Engineers and scientists are generally considered a sideshow, a workforce to quantitate.

While we're on the topic of McNamara, I'd like to plug the documentary The Fog of War: Eleven Lessons from the Life of Robert S. McNamara [1]. It's great to watch, and you can see how McNamara's perspective has changed. I would recommend it to everyone, especially anyone who cares about defense/foreign policy. [1] https://www.imdb.com/title/tt0317910/

I recommend Ken Burns' Vietnam series to put McNamara's statements in Fog of War in context.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#166
post #77

Earlier quoted context omitted.

> The enemy here is fairly low-tech. Shouldn't be a problem. Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.

I think this can be a downfall of the US military if they ever get into a conflict with a capable enemy. They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. I wonder what would happen to the B-2 bomber or aircraft carriers if they had to fight China. My guess is these weapons would be eliminated very quickly.

Thankfully the answer is "If we are fighting another nuclear power such that they are trying to shootdown a Bomber that didn't invade their airspace or sink an aircraft carrier something has already gone horribly wrong." Pax Atomica is in effect and there is a very reason why all of the wars were proxy wars. Everybody knows that it can only end in everyone losing.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#167

If you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about…

If this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.

It's almost if they are trying to limit their candidate pool to the smallest possible set of potential employees.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#168
post #4

> Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise. It's not too surprising and a little reminiscent of the security nightmare that are IoT devices. All those weapon systems come out of hardware/engineering companies with little background in software engineering and the accompanying security best pr…

Most hardware engineering companies have no idea about software. To them, software is just another line item on the BOM, like a bolt or a piece of sheet metal. Something that you need to source as cheaply as possible and stick into the package somewhere on the assembly line. Nobody cares what it does or how buggy it is as long as it meets the checklist of requirements written into the contract with the supplier.

Look at things like cable set top boxes, and automotive entertainment systems. It's like they don't care what the software is as long as some bits that some supplier sent them are flashed onto the device.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#169
post #77

Earlier quoted context omitted.

I think this can be a downfall of the US military if they ever get into a conflict with a capable enemy. They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. I wonder what would happen to the B-2 bomber or aircraft carriers if they had to fight China. My guess is these weapons would be eliminated very quickly.

Thankfully the answer is "If we are fighting another nuclear power such that they are trying to shootdown a Bomber that didn't invade their airspace or sink an aircraft carrier something has already gone horribly wrong." Pax Atomica is in effect and there is a very reason why all of the wars were proxy wars. Everybody knows that it can only end in everyone losing.

Let's hope it stays that way but I am not too optimistic.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#170

Earlier quoted context omitted.

They don't know how to hire a security advisor or external team? What I'd be most concerned about is that the procurement process is favouring companies who clearly aren't up to designing in rudimentary security, in weapons systems, ... smh. That seems like getting clothing made and not having anyone flag that it was glued together with PVA instead of being sewn; and the company you hiredb not having anyone who reali…

Meanwhile, the software companies capable of fixing these issues face internal revolt at the idea of defense contracts. Apparently inaccurate targeting systems and vulnerable firmware in equipment that is going to deployed (regardless of protest) is better for pacifism?

There's been companies around willing to do the work for a small premium for a long time. There's also software designed for security or making it easier. Here's a few, semi-random examples:

http://www.sis.pitt.edu/jjoshi/Devsec/CorrectnessByConstruct...

https://www.ghs.com/products/safety_critical/integrity-do-17...

https://runtimeverification.com/match/

https://galois.com/blog/

http://sel4.systems/

https://muen.codelabs.ch/

The defense buyers just don't use such companies or products in most cases. They know they don't have to due to corruption mostly. The money they save might even get someone a bonus for achieving some metric like keeping costs down. Mass market is similar where they don't buy the stuff either. So, the supply of high-security systems are extremely low, usually high per-unit as a result, and not prevalent.

Sad but true...

Post reply on HN