Earlier quoted context omitted.
Reminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.
There's a reason it reminds you of it...
DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
171–180 of 225 posts
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#172Earlier quoted context omitted.
The problem isn't just MBAs. It's that scientific management has become central to the DoD's mode of functioning. Which is remarkably sad. The DoD in the WWII and post-WWII era actually developed a lot of good systems engineering practices and was largely successful on some massive projects. Since then, however, there has been the constant desire to deskill workers. That is, they want explicit operating/work instruct…
Specialization, metrics that don't capture true growth/success, and too large of teams also ends up to skilled workers that care less because they have less power or responsibility/ownership. Small teams with skilled people, the startup model, works best even in large companies. Closer to the customer and more cohesive unit makes for a better project, that is why innovation happens at smaller companies or small resea…
This reminds me of bystander effect [0]. The demarkation of responsibility in large enough teams could invoke delays just in finding who is responsible for what.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#173The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#174Earlier quoted context omitted.
You should note specific issues, rather than a general complaint.
I’ll bite. There was no indication in the article of anyone with an MBA in particular being responsible for these issues. The reasoning reads as: “lots of stuff is going wrong” ==> “must be because they have management with MBAs” Why try to make this link if it isn’t there? What if I replace MBAs with ‘foreigners’, ‘women’, ‘people who read HN’, etc? Why do we need this? Does blaming non-technical people for the fail…
The thesis that parties who have negligible expertise in a given area given charge of people with substantial expertise in that area contribute minimal or negative value seems at least arguable.
Maybe we as a society value the idea of teaching people to lead people irrespective of what those people actually do instead of elevating skilled individuals in that area because it allows us to reward all the rich peoples kids that aren't smart enough to do.
This needn't mean you automatically are unintelligent or bad at what you do. You could personally be awesome and contribute greatly to the efforts you work with/lead.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#175Earlier quoted context omitted.
This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…
Some years ago I worked for a DoD contractor that builds systems like this, and honestly I think people do care, but they are wildly, woefully, ignorant about the risks. They truly do not understand the vulnerabilities. I'm not making excuses for them (especially given the pushback I received when I started calling out the more egregious things), but I think it does help understand the problem better.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#176Earlier quoted context omitted.
This is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, a…
It is absolutely happening in enterprise software. I have met sales guys and startup advisors that prided themselves in being able to play that game well. In a certain segment of this industry, you get laughed at if you try to actually come up with a solution.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#177Earlier quoted context omitted.
I always assumed the US military does such tests routinely. Don't they?
the fact that this one test is news suggests, no. I seem to remember a story about "how good is the SAS" because they were asked, after years of development, to try and destroy an armoured train that carried nuclear material from power plant to disposal (it ran through populated areas so was proof against head on collisions at a gazillion miles per hour and so on) The guy took a calor gas canister, filled the train h…
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#178Earlier quoted context omitted.
> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a reg…
> scary if the military is driven like an MBA only led business with no influence from engineering/security Having known many people that worked in/around the military and defense industry, this seems like our reality.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#179The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…
> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a reg…
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#180Earlier quoted context omitted.
I would suggest that the problem is too much wriggle room / dissonance during the design process (in nice safe meeting rooms admittedly) We can all persuade ourselves that as all items are ticked, the job is done. But testing gives the lie to all this. The patriot system was battle tested in the 1990s and its deficiencies became apparent - and lessons seem to have been learnt. So perhaps more adversarial testing is t…
I always assumed the US military does such tests routinely. Don't they?