Like hugh says, this doesn't add up at all. “We keep wiping it off, and it keeps coming back,” says a source familiar with the network infection, one of three that told Danger Room about the virus. “We think it’s benign. But we just don’t know.” C'mon. You're the military. "It just keeps coming back?" So you decide to do a press release about it? Please. I wouldn't have whined like that when I was de-malwareing neigh…
This reminds me of that other news story from 2009 claiming that people were intercepting drone video feeds with $30 of software.
I guarantee UAV's are not running XP or Windows 2000. The government has heard of things called RTOS.
I wouldn't be so sure about that. http://gcn.com/articles/1998/07/13/software-glitches-leave-n... And, have you seen all the computers necessary to carry out a drone operation? I guarantee you not all of them are running an RTOS. Probably not even all of them onboard the drone.
The article is from 1998. Please forgive me if I don't see it as framing the situation of today.
Like hugh says, this doesn't add up at all. “We keep wiping it off, and it keeps coming back,” says a source familiar with the network infection, one of three that told Danger Room about the virus. “We think it’s benign. But we just don’t know.” C'mon. You're the military. "It just keeps coming back?" So you decide to do a press release about it? Please. I wouldn't have whined like that when I was de-malwareing neigh…
There is definitely some high level shit going on right here.
Such as: they discovered and disabled the virus but are still sending fake info over the virus's communication channel and want the Chinese/Iran/whoever to think it is still working?
That sounds much better than a technically incompetent military with dangerous toys.
I don't know how I can be any more clear here: If they are not smart enough to keep malware off of what should be the most secure systems around, perhaps they shouldn't be building the fricking FLYING REMOTE-CONTROL DEATH MACHINES for a while, until they can figure out the basics. Capisce, guys?
I am totally with you. If software is going to operate deadly weapons, it sure as hell better be secure. But you are glossing over a LOT of detail here. The military doesn't work like Apple: they don't design, oversee, or directly control the construction of the hardware they use. And they shouldn't - the government is woefully inefficient at building products, that's what corporations are good at. Here's the situati…
teej, I assure you, I am under no illusion that they can "slap Norton on these things and call it a day". I am at least somewhat conversant with the realities of designing complex military systems. But if the systems really are so highly specialized, and I assume they are, that's still no excuse. At all. If they can't keep malware off them, they have no business flying them, at least for the time being. Which is all I was saying. I know it's not easy.
"usb ports with glue" Keyboards, Mice, Joysticks for these systems were probably designed with the idea that a USB bus would be available. It will take a while to replace all of these systems with their non-USB configurations. Given that BlueTooth is probably a no-no as well, how would one build a system these days that needs to support Mice, Joysticks, and Keyboards without using USB?
A few options include: http://en.wikipedia.org/wiki/PS/2_connector and http://en.wikipedia.org/wiki/Game_port
Lenovo on their business machines still includes PS/2 ports, and USB can be completely disabled by setting a jumper on the motherboard, or changing a setting in the BIOS.
When asked why they were told that for government contracts, and for businesses that wanted to make sure that USB devices could not just be used at random.
Perhaps they shouldn't use a platform that runs Norton in the first place? I suspect that under it all, you'll find an unpatched XP or even Win2000.
I guarantee UAV's are not running XP or Windows 2000. The government has heard of things called RTOS.
The UAV itself will have a computer running a commercial RTOS. The computer on the ground which the operator sits and and uses to interact with the UAV is almost certainly a Windows box. And as someone else said, the military's way of securing Windows machines like those has traditionally been not to hook them up to a network in the first place, instead of installing anti-virus software. That actually worked really well until portable USB devices came along. The result is that the military is only now getting up to speed on securing these types of computers; it's not that they're dumb about computers, it's that in the past they dealt with the threat operationally rather than technically.
The article says that USB keys are used to move data on to the system from other networks. If this is true it would be better to assume that all data from that other network is bad, and require it to be serialized in a none executable format. The software then needs to validate the data against a schema. This is something websites have done for years and is very basic.
The mistake that is made here is to assume that a network can ever be secure. It is like assuming that no one will ever pee in a swimming pool.
The way it works is some AF guy in Nevada remotely controls the drones flying half way across the world. My guess is it's not the drones themselves running Windows, but the consoles used to communicate with the drones. It makes sense. AF guy gets to work, plugs in his USB drive filled with music and pulls up the drone control program... Though, now that I think about it, I would be disappointed, but not entirely surp…
No modern UAV has hardware capable of running an entire Windows installation. Think of arduino boards; those things can control huge robotics systems and they are very simple (and thus simple to debug). If you're designing a robot from the ground-up, why would you scale all the way to Windows? No one is going to be playing minesweeper inside the plane
spoilers: Microsoft has a significant enterprise support organization, which the military is probably already dealing with, and Windows scales farther down than you'd think.