Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

191–200 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#191

If you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about…

Thanks for chiming in. Curiously, I had a few questions:

1.) Does DDS really pen test developmental/operational weapon systems? I'm talking about custom flavors of standalone PIT systems at the lowest embedded level, not just public-facing unclassified commidity IT systems. Maybe I'm missing something, but the projects highlighted on DDS's website suggest otherwise.

2.) How's your Blue team ops? The current RMF meta in the field strikes me as an all-Red team party, while the Blue side of business is pretty much always MIA. I suspect it's partly because pen testing is fashionable these days, successful outcomes can be quite dramatic and perceivably understood by stakeholders, and avoidance of the inherent liablility of defensive posturing without significant impact to performance/capability if a complex system's requirements are not well understood (a compounded issue not exclusive to weapon systems), to name a few.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#192
post #72

Earlier quoted context omitted.

It's not about taking over. Disabling them is sufficient.

I have been thinking the recent Navy navigation related crashes are related to enemies tampering with systems. They are testing live how weak a windows based fighting ship is. https://www.wired.com/1998/07/sunk-by-windows-nt/

From what I understood the recent Navy collisions are caused by under-staffing => sailors having to work too long days => sailors literally falling asleep at their posts / seeing things that aren't there / not seeing things that are there

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#193

Silver lining: when the DOD find good ways to harden their systems, we can all copy them. Cloud: it's probably unplug the aerial / network cable

I'm afraid they need to catch up with the rest of the world before advancing the state of the art.

The best case scenario is a quick cultural shift, with awareness of computer security threats overflowing from the military to laws and society in general.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#194
post #86

Earlier quoted context omitted.

The catch is that on DOD systems, encryption is very difficult to add. That is, to be certified by the NSA and compatible with the military key infrastructure. So its better to avoid mentioning it unless its forced on you. Better is a relative term here. I mean, in terms of cost and effort to add. Not security.

So since it's hard to get the rubber stamp you just do include encryption, that seems worse.

You're waiving encrypted channels around as if it were de facto mandatory. Without knowing the ConOps of the system, how could you possibly conclude that confidentiality was an imperative? Effective acquisition of weapon systems is about balancing budget, schedule, performance, and risk--a lot easier said that done.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#195

Earlier quoted context omitted.

What are some examples of pushback you received? If it’s sensitive I’d enjoy hearing a made up scenario that followed along the same lines with a problem pointed out and a deflection response given

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights: - Stovepiped organisations: stick in your own lane. But security is cross cutting. - Security orgs want to stick to what they know about, not what the threat scope is. - Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle…

I mostly agree with the points you're making, but...

> Security unwilling to own risk

Security cannot fundamentally own risks created by other parts of the organisation. I'd actually put it the other way around - the organisation is often unwilling to own risks identified by security.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#196
post #6

Earlier quoted context omitted.

The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

A company I worked for had a CEO who was rather paranoid about the Chinese stealing the software for our innovative product, and would often rant about it at our all-hands meetings. To which I could only think "Well, if they can make sense of it, good luck to them." I really think it would have been easier for them to re-do the implementation from scratch!

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#197
post #42

Earlier quoted context omitted.

Based on my first-hand experience as a solider in the US Army, talking to 4-5 low-ranked sailors is unlikely to give a meaningful picture of the whole system. I don't have specific experience with Navy systems to judge the technical details of komali2's post, but I would caution against taking a summary of second-hand accounts from operators as fact.

>>I don't have specific experience with Navy systems to judge the technical details of komali2's post Well, there you go then. Thanks for being honest at least.

I have multiple decades of experience with Navy and Army systems and personnel, and he's correct.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#198
post #70
post #19

Earlier quoted context omitted.

First, most IT personnel on ships (especially one as ancient as the Bonhomme Richard) do not work on weapon systems. Most of them would not even be able to discuss where on the ship they are intelligently, let alone what they connect to. The people you talked to simply aren't informed. You even note that you were talking to 19 year old kids, and they're not generally the ones who know what's going on.

Well that's a question I have as well - who actually knows what's going on there?

People like me.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#199

Earlier quoted context omitted.

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights: - Stovepiped organisations: stick in your own lane. But security is cross cutting. - Security orgs want to stick to what they know about, not what the threat scope is. - Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle…

I mostly agree with the points you're making, but... > Security unwilling to own risk Security cannot fundamentally own risks created by other parts of the organisation. I'd actually put it the other way around - the organisation is often unwilling to own risks identified by security.

Security needs to accept that is their job to secure the operations of the org, not prevent the org from doing things which don't fit into easy use cases.

For example, the chem eng group own the risk of the chemistry being wrong and the plant blowing up. They don't get to say 'let's outsource production to ChemCorp'. Likewise, security needs to secure the ICS, not just ignore it and say 'the SCADA guys do that, it needs SMB1' or when the risks are pointed out say 'you must now change the passwords every 30 days'.

Business units burying their head in the sand? Well, that can happen too. Pen-tests are great for demonstrating problems, but how many security orgs have the ovaries to do them and force realisation? Did security work with the business unit to mitigate risk, or just want to shut it down?

I'd love to get specific but my point is that there is a lack of holistic vision across the enterprise, and incentivising cooperation between stovepipes is needed, and being willing to take risk -- not throwing away the rule book, but writing a new chapter on how to apply it in context.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#200
post #8

Earlier quoted context omitted.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

I too toured the boat. > The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.…

>And then do what once you are in?

"Running a port scan caused the weapons system to fail"

Post reply on HN