Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

201–210 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#201
I have read rumors to the effect that our own rogue elements in the spy agencies are exploiting these known vulnerabilities. It seems not everyone is on the same team in our own government, which totally sucks, but it has been that way for a long time.

We need a government by and for the people.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#202

Earlier quoted context omitted.

What are some examples of pushback you received? If it’s sensitive I’d enjoy hearing a made up scenario that followed along the same lines with a problem pointed out and a deflection response given

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights: - Stovepiped organisations: stick in your own lane. But security is cross cutting. - Security orgs want to stick to what they know about, not what the threat scope is. - Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle…

Based on what took place at Fukushima, I would say no.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#203

Earlier quoted context omitted.

the fact that this one test is news suggests, no. I seem to remember a story about "how good is the SAS" because they were asked, after years of development, to try and destroy an armoured train that carried nuclear material from power plant to disposal (it ran through populated areas so was proof against head on collisions at a gazillion miles per hour and so on) The guy took a calor gas canister, filled the train h…

Now -that- sounds like a fun job to have that comes with lots of dinner stories to tell. Course I guess they’d assassinate the guy if he was telling these stories Willy nilly (to protect national secrecy)

Is that reasonable to you?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#204
post #190

Earlier quoted context omitted.

10,000 drones? How big a drone are we talking? They would have to be big enough to carry a weapon big enough to penetrate at least 1/2" steel (at the thinnest, only accessible from the side). If out to sea, a small EMP could drop them all. Battles won by numerical superiority are usually won by defenders. If it's an invader, it's almost certainly early in the game. Even at the end of WW2, Germany wasn't invaded so mu…

> Even at the end of WW2, Germany wasn't invaded so much as it lost in France and Russia Sorry, no. Germany was very quickly overrun in 1945. https://commons.wikimedia.org/wiki/File:1945-05-01GerWW2Batt... https://commons.wikimedia.org/wiki/File:1945-05-15GerWW2Batt...

What they possibly meant was: the war was already lost when they got invaded at all.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#205

Earlier quoted context omitted.

What are some examples of pushback you received? If it’s sensitive I’d enjoy hearing a made up scenario that followed along the same lines with a problem pointed out and a deflection response given

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights: - Stovepiped organisations: stick in your own lane. But security is cross cutting. - Security orgs want to stick to what they know about, not what the threat scope is. - Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle…

Japan doesn't appear to be doing much better.

https://securityaffairs.co/wordpress/53856/cyber-warfare-2/d...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#206
post #205

Earlier quoted context omitted.

I could write a long paper on this, and I would have if I thought it would've made a difference... But some highlights: - Stovepiped organisations: stick in your own lane. But security is cross cutting. - Security orgs want to stick to what they know about, not what the threat scope is. - Security unwilling to own risk, fall back on ass-covering checklists and mandatory processes. This leads to them being an obstacle…

Japan doesn't appear to be doing much better. https://securityaffairs.co/wordpress/53856/cyber-warfare-2/d...

There isn't really sufficient information to judge. Persistent attackers would almost certainly achieve eventual compromise on the type of network described. It's really a question of whether when they find a problem (crashed system, non-compliant senior staff, buggy security protocols, etc) they report it, and then it gets acted on.

Japan invented some of the best aspects of safety culture, like being process driven, checklists, point & call https://www.atlasobscura.com/articles/pointing-and-calling-j...

It has been remarked before that if security was treated the same as safety critical systems (like aviation operations, and increasingly, hospitals) then we would have much better security. Tbh, I'm not sure, because of the adversarial nature of attack and defence, but it would be interesting to test.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#207
post #190

Earlier quoted context omitted.

> Even at the end of WW2, Germany wasn't invaded so much as it lost in France and Russia Sorry, no. Germany was very quickly overrun in 1945. https://commons.wikimedia.org/wiki/File:1945-05-01GerWW2Batt... https://commons.wikimedia.org/wiki/File:1945-05-15GerWW2Batt...

What they possibly meant was: the war was already lost when they got invaded at all.

That certainly was true. The war was already lost when they were still deeply into Russia. the last 2 years of WW2 were just trying to fight off the inevitable.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#208
post #198
post #70

Earlier quoted context omitted.

Well that's a question I have as well - who actually knows what's going on there?

People like me.

People named jki275 that post one-sentence replies on Hackernews? ;)

What kind of work do you do? You're in the military? What's your rank / job description? That's the kind of information I'm curious about. If the answer is "I can't tell you because it'll expose personal information," well, I'm not the one that outed you lol.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#209
post #192

Earlier quoted context omitted.

I have been thinking the recent Navy navigation related crashes are related to enemies tampering with systems. They are testing live how weak a windows based fighting ship is. https://www.wired.com/1998/07/sunk-by-windows-nt/

From what I understood the recent Navy collisions are caused by under-staffing => sailors having to work too long days => sailors literally falling asleep at their posts / seeing things that aren't there / not seeing things that are there

They seem to work twelve on, twelve off, with requiring that some of their personal time being used to maintain physical fitness, so does seem like a disaster waiting to happen.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#210
post #182

Earlier quoted context omitted.

Military is the pet project. It's the only form of public spending with broad support even from anti Federal government people.

> Military is the pet project. It's the only form of public spending with broad support even from anti Federal government people. Law enforcement has about equally broad support, including from anti-federal-government groups (though not always the same ones that back the military, as their are pro-law-and-order anti-interventionist groups that aren't keen on military spending, and pro-military groups that are federal…

Unfortunately federal law enforcement has lost some of its support among the law and order crowd because of the perception that they are in bed with the political opposition.
Post reply on HN