Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

151–160 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#151
post #80

Earlier quoted context omitted.

It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.

I don't know that it's just the procurement strategies to blame. Many years ago, I was asked to bring a command and control system into (Orange Book) C2 compliance. Among the things I introduced were personal user accounts with some restrictions around allowable passwords. The users of the system (most of which were "former" fighter pilots) were furious with the restrictions, which they viewed as getting in the way o…

A decent fraction of the population views password restrictions as a challenge to come up with the shittiest, least secure password that they possibly can while still meeting all restrictions. You can blame users for that with some justice, but as a system designer, it's still your responsibility provide security despite shitty but reasonably likely human behavior.

With modern crypto there are very few systems where it's appropriate to have a user-selected <=12 character password for primary auth, yet unfortunately that continues to be widespread for banks, ecommerce, and (probably) some military systems. High-end security people seem to almost universally hate short user-selected passwords (except when they have to break them..) but old practices die hard and old systems take a long time to be replaced.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#152

Earlier quoted context omitted.

If this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.

Yup! We’re all employees of the federal government, so we have to meet the requirements of all Federal positions. Honestly, you don’t do this job for the money. I took a pay cut when I joined, on top of losing bonuses and equity. You join because you want to make a real difference in people’s lives, in a visceral, real way. I can say without exaggeration that there are people who would have died except for the work t…

Keep up the good work. If you see Matt Cutts, say hi for me.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#154
post #134

Earlier quoted context omitted.

> They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. Tell that to Vietnam and Afghanistan. Historically the US does well against standing armies (Iraq for example), but absolutely terribly against low-tech enemies who don't engage in a way that allows these super high tech weapons to be used effectively. Reminds me of this: http://www.kiplingsociety.co.uk…

I meant it in a sense of an enemy that can take on the high tech weapons. Since the Korea war nobody challenged the high tech equipment in meaningful way.

I have to quibble with that a bit. The US regularly overflew the USSR and China through at least the mid 70s, meaning our best aircraft were in a very real sense fighting their best air defense systems 20 years+ after the Korean war ended.

There have almost certainly been satellite, submarine and other engagements too, they just aren't generally publicized by either side until 30-40+ years later.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#155

Earlier quoted context omitted.

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

Actually yes. It takes a horde of military personnel to operate the hodgepodge of modern military information systems and technologies. There's nothing easy about it. All sorts of incompatible and buggy tools. Our enemies would have a hard time putting to work the military command & control apparatus -- I mean, we already have trouble enough as it is. But that doesn't mean the enemy can't learn information and be abl…

all they have to be able to do is make a piece or two break or become unresponsive at the correct time

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#156
post #89
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

Honestly I'm really offended by this comment. To suggest that coders writing weapons systems have little skin in the game is condescending and shows how ignorant of the environment you are. Low effort comment. Every industry is for the most part disturbingly bad at security in general.

Maybe write some weapons systems or work with people that do and you would have a different perspective.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#157
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

Honestly I'm really offended by this comment. To suggest that coders writing weapons systems have little skin in the game is condescending and shows how ignorant of the environment you are. Low effort comment. Every industry is for the most part disturbingly bad at security in general. Maybe write some weapons systems or work with people that do and you would have a different perspective.

>Maybe write some weapons systems or work with people that do and you would have a different perspective.

Given that that's not really reasonable, maybe you want to give us some perspective? You can't go around accusing others of low effort comments and then not provide any insight yourself.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#158
post #154

Earlier quoted context omitted.

I meant it in a sense of an enemy that can take on the high tech weapons. Since the Korea war nobody challenged the high tech equipment in meaningful way.

I have to quibble with that a bit. The US regularly overflew the USSR and China through at least the mid 70s, meaning our best aircraft were in a very real sense fighting their best air defense systems 20 years+ after the Korean war ended. There have almost certainly been satellite, submarine and other engagements too, they just aren't generally publicized by either side until 30-40+ years later.

True. However, I think in a real shooting war those aircraft could be attacked by a huge number of low tech weapons and get overwhelmed. From what I know about warfare often large numbers will eventually overwhelm every kind of defense. For example could an aircraft carrier handle 10000 incoming drones? I hope we'll never find out...

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#159
post #8

Earlier quoted context omitted.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

I too toured the boat. > The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. Well, this is not related to the main point about cyber security. If true, it's just a piece of equipment that was found to be flawed. It is a non-essential system that was made INOP.…

>Besides, you have to be on the ship already.

That's a problem if you just encounter the ship on open sea, but if you anticipate a conflict it shouldn't be hard to turn one of the literally thousand people crewing the ship. Just find one person who you can force/incentivize to plug an LTE enabled network device in and start hacking from a safe distance (bring your own LTE base station for hacking on open sea).

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#160
post #89

Earlier quoted context omitted.

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…

Honestly I'm really offended by this comment. To suggest that coders writing weapons systems have little skin in the game is condescending and shows how ignorant of the environment you are. Low effort comment. Every industry is for the most part disturbingly bad at security in general. Maybe write some weapons systems or work with people that do and you would have a different perspective.

I agree that the comment came across as from some one without skin in the game themselves. But I also believe the current procurement process is broken and after spending time using these systems I don’t hold the people building them responsible, but the Admirals, Generals, Executives, and Politicians who smooze at places like Tailhook and shoot down opposition to the status quo. The parent may be right that we won’t course correct until a catastrophe happens. All industries have issues, but the military isn’t an industry and deserves better for $1.6 Trillion. This report is terrifying and exemplifies the sad state of the military’s conventional weapons systems. But agree that most those in defense are often trying their best to do good.
Post reply on HN