Live data from Hacker News

US Navy to pay $1M to make Android more secure

sbirsource.com

31–40 of 53 posts

Re: US Navy to pay $1M to make Android more secure

#31
post #27
post #5

The DoD is committing to Android as a platform in a massive way. Apps 4 Army is a key example. The push is so large and widespread that I think it will force the whole US Gov't along with it. Everyone from political leaders, to soldiers, to doctors at VA hospitals, to employees at defense contractors, will be required to use Android because of government security certifications and custom apps. There's a good chance…

Android is going to be the low cost field deployable random gadget, and this is an investment in bringing a minimum level of security to the platform. For actual classified applications, the NSA (which provides solutions downstream to DoD and other groups) is already trying to standardize on a highly customized version of Windows CE built by General Dynamics that runs on XScale processors with NSA specific modificati…

Windows CE? I'm surprised. I always thought the NSA really seemed to be embracing Linux.

Re: US Navy to pay $1M to make Android more secure

#32
post #10
post #8

Earlier quoted context omitted.

Now there is some pie-in-the-sky hope. I don't think it is going to play out that way though.

It would be pretty irresponsible for them to standardize on a single source vendor for this, so what are the alternatives? WinMo? Plus the government already has a long history of investing R&D into securing linux-based systems.

> It would be pretty irresponsible for them to standardize on a single source vendor

What they typically do is write the specs to an existing product sometimes it is laughable really, you can tell exactly the product they mean without them actually mentioning its name. That is one way to put out bids that on paper look open and not tied to a particular vendor but in practice they are.

The other way is to do a pie in the sky kind of write-up. We want something that does everything and we're requesting quotes for it. That is silly as well.

Re: US Navy to pay $1M to make Android more secure

#35
post #19
post #4

Summary - The US navy wants to use (near) commercial android devices. These might be used to display confidential reports (as in a normal buisness), but may also be used to control the ship. The navy already have secure versions of Linux and Windows, and want something similar for android. This will take the form of additional security layers, similar to the ones the NSA did for Linux[1]. Some of them will be made co…

Hmm, who actually is the one to usually do this sort of thing? Clearly it is a good idea, but I don't think it really makes sense for the Navy to do it for themselves. Isn't this more the sort of thing the NSA should be doing on the behalf of everyone else in government?

I think the Naval Research Laboratory is more than capable.

http://www.nrl.navy.mil

Re: US Navy to pay $1M to make Android more secure

#36
post #33

The whole device hardware and software needs to be certified. It is hard to make a secure piece of software and prove it so if the hardware or firmware it is running on is compromised.

Pfft. Have you ever had a project EALx/Common Criteria certified? The program is a joke. You can certify a ham sandwich if you document what brand of mayo you use.

Re: US Navy to pay $1M to make Android more secure

#37
post #27

Earlier quoted context omitted.

Android is going to be the low cost field deployable random gadget, and this is an investment in bringing a minimum level of security to the platform. For actual classified applications, the NSA (which provides solutions downstream to DoD and other groups) is already trying to standardize on a highly customized version of Windows CE built by General Dynamics that runs on XScale processors with NSA specific modificati…

Windows CE? I'm surprised. I always thought the NSA really seemed to be embracing Linux.

I guess the way the Government see the situation is. If they're paying Microsoft to provide them with a service/software with guarantees drafted up into a contract when SHTF the Government can turn it all back on Microsoft and say, "But the contracted stated you would be providing a secure platform..." You'd be surprised how popular Windows CE actually is. I've seen it used a lot on touchscreen kiosks here in Australia.

Re: US Navy to pay $1M to make Android more secure

#38

Earlier quoted context omitted.

Windows CE? I'm surprised. I always thought the NSA really seemed to be embracing Linux.

I guess the way the Government see the situation is. If they're paying Microsoft to provide them with a service/software with guarantees drafted up into a contract when SHTF the Government can turn it all back on Microsoft and say, "But the contracted stated you would be providing a secure platform..." You'd be surprised how popular Windows CE actually is. I've seen it used a lot on touchscreen kiosks here in Austral…

Yes, its used in single board applications like the mini2440. Though android 2.3 is quickly gaining popularity due to how simple it is to adapt and run.

Re: US Navy to pay $1M to make Android more secure

#39
post #12
post #5

The DoD is committing to Android as a platform in a massive way. Apps 4 Army is a key example. The push is so large and widespread that I think it will force the whole US Gov't along with it. Everyone from political leaders, to soldiers, to doctors at VA hospitals, to employees at defense contractors, will be required to use Android because of government security certifications and custom apps. There's a good chance…

I've heard this before. Remember 15+ years ago when the US Army chose WebObjects because it was so obscure it had no security issues? How is their adoption of Apple server gear since then?

DoD has a very effective PKI system using smart-cards deployed, so I wouldn't be as surprised as you to see them develop a baseline of software for Android.

What I would be surprised about is whether it's usable without needing 7 different contractor apps installed, or less than 3 years behind the times.

Post reply on HN