Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

181–190 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#181
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

Honestly I'm really offended by this comment. To suggest that coders writing weapons systems have little skin in the game is condescending and shows how ignorant of the environment you are. Low effort comment. Every industry is for the most part disturbingly bad at security in general. Maybe write some weapons systems or work with people that do and you would have a different perspective.

It's possible for every coder to be committed and the system as a whole to be a disaster due to poor integration or even decisions at the contract or legislative level.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#182

Earlier quoted context omitted.

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…

> It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. If that was the whole story, the military budget would be plummeting as our representatives realized that they could also , and far more legitimately, take money away from the military to put in their pet projects.

Military is the pet project. It's the only form of public spending with broad support even from anti Federal government people.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#183
post #182

Earlier quoted context omitted.

> It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. If that was the whole story, the military budget would be plummeting as our representatives realized that they could also , and far more legitimately, take money away from the military to put in their pet projects.

Military is the pet project. It's the only form of public spending with broad support even from anti Federal government people.

> Military is the pet project. It's the only form of public spending with broad support even from anti Federal government people.

Law enforcement has about equally broad support, including from anti-federal-government groups (though not always the same ones that back the military, as their are pro-law-and-order anti-interventionist groups that aren't keen on military spending, and pro-military groups that are federal law enforcement as jackbooted authoritarian thugs.)

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#184
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…

Bullshit Jobs!

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#185
post #39
post #31

Earlier quoted context omitted.

I'm not sure what specific training you're talking about regarding DIACAP (which it would likely have been when you were working there; now replaced with RMF), but over all the goal of certification and accreditation is about assuming risk, and the DAA (Designated Approving Authority) assumes the risk so they need to be informed about the risk. More information can be found in DoD Directive 8500 (DoD Instruction 8500…

Looks like I was remembering the wrong acronyms. It was information assurance training. We had to do it every 6 months, and like twice in a month when Snowden did his thing. My first year there it was a goofy flash game with uncanny valley cartoon characters awkwardly telling you not to share secrets at the bar to get laid. Every year I stayed it seemed to get longer and more awkward. At some point they added a boxin…

The increased training around the time of the Snowden-based leaks was largely focused around informing people who hold a national security clearance about the fact that information remains classified even if it has been published on the Internet. There was concern that people holding a national security clearance may use their unclassified information systems to process this (still classified) material, causing those machines to need to be treated at the highest classification of information on which they process (as they are not "periods processing" machines). Additionally the "need to know" principles still apply, and looking at classified information without satisfying that criteria could cause revocation of sponsorship for holding a national security clearance.

The training likely stressed that just the source of the classified information was somewhere "outside" DoD it did not change the classification. This is because changing the classification requires an Declassification Authority to act on it, which is generally the Original Classification Authority -- of which there are very few.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#186

Earlier quoted context omitted.

Some years ago I worked for a DoD contractor that builds systems like this, and honestly I think people do care, but they are wildly, woefully, ignorant about the risks. They truly do not understand the vulnerabilities. I'm not making excuses for them (especially given the pushback I received when I started calling out the more egregious things), but I think it does help understand the problem better.

What are some examples of pushback you received? If it’s sensitive I’d enjoy hearing a made up scenario that followed along the same lines with a problem pointed out and a deflection response given

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights:

- Stovepiped organisations: stick in your own lane. But security is cross cutting.

- Security orgs want to stick to what they know about, not what the threat scope is.

- Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle, a cost rather than a benefit.

- True lack of expertise at stakeholder level. Particularly in the US, the experts are contracted, and never speak out of turn.

- Staying quiet. Americans are extremely conscious of organisational (rather than technical) status and embarassment, and it isn't career enhancing to identify naked emperors.

- Good security costs money upfront, and pays back over time. Bad security is free at the beginning, and costs massive amounts to fix, but: (a) fixing is someone else's problem, (b) fixing is new contracts and more work, (c) systems might not be noticeably hacked.

Large companies (e.g. Lockheed Martin) are often very adversarial, and deny fault with lawyers. I've often wondered if places like Japan, with more cooperative cultures, can address this differently.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#187

Earlier quoted context omitted.

What are some examples of pushback you received? If it’s sensitive I’d enjoy hearing a made up scenario that followed along the same lines with a problem pointed out and a deflection response given

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights: - Stovepiped organisations: stick in your own lane. But security is cross cutting. - Security orgs want to stick to what they know about, not what the threat scope is. - Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle…

Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle, a cost rather than a benefit.

How well this statement retains its correctness across time and space. Pretty much my experience in every company beyond certain size.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#189

Earlier quoted context omitted.

If this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.

Yup! We’re all employees of the federal government, so we have to meet the requirements of all Federal positions. Honestly, you don’t do this job for the money. I took a pay cut when I joined, on top of losing bonuses and equity. You join because you want to make a real difference in people’s lives, in a visceral, real way. I can say without exaggeration that there are people who would have died except for the work t…

> You join because you want to make a real difference in people’s lives, in a visceral, real way.

What that difference may entail varies greatly though. For one, it might be not being blown up by that IED. For another, it might be being bombed to bits at your cousins wedding, along with the other 40 members of your family, by a drone operator in Nevada. Very visceral indeed.

If you think that working for the military is "doing good" and the US is oh so innocent I suggest you watch the excellent documentary The Untold History of the United States by Oliver Stone [0].

[0] https://en.wikipedia.org/wiki/The_Untold_History_of_the_Unit...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#190

Earlier quoted context omitted.

True. However, I think in a real shooting war those aircraft could be attacked by a huge number of low tech weapons and get overwhelmed. From what I know about warfare often large numbers will eventually overwhelm every kind of defense. For example could an aircraft carrier handle 10000 incoming drones? I hope we'll never find out...

10,000 drones? How big a drone are we talking? They would have to be big enough to carry a weapon big enough to penetrate at least 1/2" steel (at the thinnest, only accessible from the side). If out to sea, a small EMP could drop them all. Battles won by numerical superiority are usually won by defenders. If it's an invader, it's almost certainly early in the game. Even at the end of WW2, Germany wasn't invaded so mu…

> Even at the end of WW2, Germany wasn't invaded so much as it lost in France and Russia

Sorry, no. Germany was very quickly overrun in 1945.

https://commons.wikimedia.org/wiki/File:1945-05-01GerWW2Batt... https://commons.wikimedia.org/wiki/File:1945-05-15GerWW2Batt...

Post reply on HN