Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

211–220 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#211
post #198

Earlier quoted context omitted.

People like me.

People named jki275 that post one-sentence replies on Hackernews? ;) What kind of work do you do? You're in the military? What's your rank / job description? That's the kind of information I'm curious about. If the answer is "I can't tell you because it'll expose personal information," well, I'm not the one that outed you lol.

I gave very specific comments above, and explained that I have many years of experience with these systems. No, I'm not going to give you details other than that I'm a very senior person in the field. And I'm not 19 years old...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#212

Earlier quoted context omitted.

They don't know how to hire a security advisor or external team? What I'd be most concerned about is that the procurement process is favouring companies who clearly aren't up to designing in rudimentary security, in weapons systems, ... smh. That seems like getting clothing made and not having anyone flag that it was glued together with PVA instead of being sewn; and the company you hiredb not having anyone who reali…

Meanwhile, the software companies capable of fixing these issues face internal revolt at the idea of defense contracts. Apparently inaccurate targeting systems and vulnerable firmware in equipment that is going to deployed (regardless of protest) is better for pacifism?

It's a conundrum. Do you not work on it, and have innocent people accidentally killed? Or do you work on it, and have innocent people purposefully killed?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#213

Earlier quoted context omitted.

If this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.

Yup! We’re all employees of the federal government, so we have to meet the requirements of all Federal positions. Honestly, you don’t do this job for the money. I took a pay cut when I joined, on top of losing bonuses and equity. You join because you want to make a real difference in people’s lives, in a visceral, real way. I can say without exaggeration that there are people who would have died except for the work t…

I don't understand why the benefits have to be so terrible when we spend 600 billion a year on military

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#214

GDC4S (now General Dynamics Mission Systems) and NICTA have been working on seL4, and it at least seems that USDOD has something to build on, if they want to start providing assurances of some form on weapons systems. They'll really have to set the passwords properly though.

What's eyebrow-raising is that it's been used as para/virtualization platform for Linux. (Ordinarily, SELinux MLS/MCS is pretty good though.)

If something like Minix 3 "NetBSD" in Rust ran on seL4, that would inspire more confidence.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#217

Earlier quoted context omitted.

Some years ago I worked for a DoD contractor that builds systems like this, and honestly I think people do care, but they are wildly, woefully, ignorant about the risks. They truly do not understand the vulnerabilities. I'm not making excuses for them (especially given the pushback I received when I started calling out the more egregious things), but I think it does help understand the problem better.

What are some examples of pushback you received? If it’s sensitive I’d enjoy hearing a made up scenario that followed along the same lines with a problem pointed out and a deflection response given

I hesitate to say, because there's a possibility that even years later many of the vulnerabilities are still there.

However, one that I know eventually got fixed I'll talk about (it makes a great example anyway). When port scanning one of our pieces of equipment, I noticed a strange port number that was accepting packets. I started sending random packets to it and for the most part it ignored them, but occasionally I could get the system to crash and restart.

Turns out, the server had a debug port enabled and active, even in the production build. This allowed you to essentially invoke any C function you wanted, remotely, if you knew the format (which was published in the OS manual)! Very, very bad.

When I reported it, I got a lot of responses like, "Well, this will be on a closed net anyway." and "If they get on this network, there's much bigger problems." Both statements were true for the most part, but still a very dangerous attitude to have. Just because a network compromise would be bad, doesn't mean you should make it worse by neglecting defense-in-depth. And never assume that somebody isn't going to plug an ethernet cable into your equipment that shouldn't be there (this happens all the time).

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#218

Earlier quoted context omitted.

Now -that- sounds like a fun job to have that comes with lots of dinner stories to tell. Course I guess they’d assassinate the guy if he was telling these stories Willy nilly (to protect national secrecy)

Is that reasonable to you?

Ok maybe assassinate is a bit of a hyperbole for USA but I wouldn’t be surprised if Russia did that

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#219

Earlier quoted context omitted.

This discussion doesn't make much sense. Economics is the science of making organisations work. It doesn't come with rigid objectives; Those are inputs to the process. Now I'd be glad if the DOD accidentally let a pack of MBAs with default settings do their thing, because they'd probably create a world-wide cartel within the first year, and reduce all the world's standing armies to just themselves in a very fancy con…

I think the problem of releasing MBA types on an organization is that they're specialists in business in general , not in whatever a particular organization wants to do. The actual goal is just a parameter - input to the process. And that input can be changed, or abstracted away, and as a result you get a typical soulless corporation - an organization that lost its soul, it's actual object-level goal, and remains a m…

They're like those fungi that infect snails and cause them to become zombies, crawling to the tops of blades of grass, where the birds eat them, they infect the birds, the birds die, and then the next generation of snails come along and eat the dead bird, re-infecting themselves.

MBAs are a zombie fungus disease upon companies

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#220

Earlier quoted context omitted.

This discussion doesn't make much sense. Economics is the science of making organisations work. It doesn't come with rigid objectives; Those are inputs to the process. Now I'd be glad if the DOD accidentally let a pack of MBAs with default settings do their thing, because they'd probably create a world-wide cartel within the first year, and reduce all the world's standing armies to just themselves in a very fancy con…

I think the problem of releasing MBA types on an organization is that they're specialists in business in general , not in whatever a particular organization wants to do. The actual goal is just a parameter - input to the process. And that input can be changed, or abstracted away, and as a result you get a typical soulless corporation - an organization that lost its soul, it's actual object-level goal, and remains a m…

The main problem with MBAs is that they all are taught from the same standard playbook. I have yet to meet any independent thinkers who hold an MBA.
Post reply on HN