Live data from Hacker News

US Navy to pay $1M to make Android more secure

sbirsource.com

41–50 of 53 posts

Re: US Navy to pay $1M to make Android more secure

#41
post #28

Earlier quoted context omitted.

yes, that struck me as odd actually. What about those submarines make them a good fit with android technology?

There's very little space on board a submarine. If the Navy was willing/interested in putting paper-based workflows onto Android devices, it could save a good amount of physical space on board.

I just don't see the phone-sized form factor working too well. Maybe for taking log readings or simple lineups shifts it would be nice, but anything beyond that is either going to require SUBSAFE certification (e.g. fly-by-wire interfacing) or need to be tablet-sized or larger (e.g. running DC Central or looking up operating procedures).

And God only forbid you drop one of those mobiles in the bilge...

Re: US Navy to pay $1M to make Android more secure

#42
post #34

Can anybody comment on how the Navy restriction to US citizens only developing this plays into the FOSS ecosystem of Android? I assume most of it is GPLv2, so isn't this immaterial? Why would it matter when the code is completely FOSS?

Because it's a legal and/or regulatory requirement, which are not required to make sense in the scope of unusual market environments, let alone normal ones. :-/

Re: US Navy to pay $1M to make Android more secure

#43
post #19
post #4

Summary - The US navy wants to use (near) commercial android devices. These might be used to display confidential reports (as in a normal buisness), but may also be used to control the ship. The navy already have secure versions of Linux and Windows, and want something similar for android. This will take the form of additional security layers, similar to the ones the NSA did for Linux[1]. Some of them will be made co…

Hmm, who actually is the one to usually do this sort of thing? Clearly it is a good idea, but I don't think it really makes sense for the Navy to do it for themselves. Isn't this more the sort of thing the NSA should be doing on the behalf of everyone else in government?

NSA handles crypto, certainly (though even that is being pushed ahead by NIST), but the Navy already has been developing software (or overseeing its development) for decades.

They named a ship after Admiral Grace Murray Hopper, after all, and even today their Virginia-class SSNs already use Linux in some areas.

Re: US Navy to pay $1M to make Android more secure

#44

Fucking Navy. First they waste tons of money on NMCI and then tons more on Navy ERP. I'm amazed anything works.

NMCI is actually quite successful in meeting most of its design criteria. Unfortunately said criteria don't seem to include rolling releases to recent software, or cost effectiveness (the contract seems optimized to ensure you have to go through the help desk for anything and incur a charge).

I can't speak to ERP but I'd be surprised if it were any worse than our existing menagerie of mainframe-based "corporate data" systems that run batch transactions once a day and require tedious manual correction seemingly all the time.

Re: US Navy to pay $1M to make Android more secure

#45
post #36
post #33

The whole device hardware and software needs to be certified. It is hard to make a secure piece of software and prove it so if the hardware or firmware it is running on is compromised.

Pfft. Have you ever had a project EALx/Common Criteria certified? The program is a joke. You can certify a ham sandwich if you document what brand of mayo you use.

We had some experience with it but indirectly. EALx is a bureaucratic joke, but I see FIPS 140-2 more emphasized.

The higher the level of the customer (the more authority they have) the more flexible they are. Some lower level labs don't really have much of a choice but accept a standard boiler plate set of certification stamps.

Re: US Navy to pay $1M to make Android more secure

#46
post #45
post #36

Earlier quoted context omitted.

Pfft. Have you ever had a project EALx/Common Criteria certified? The program is a joke. You can certify a ham sandwich if you document what brand of mayo you use.

We had some experience with it but indirectly. EALx is a bureaucratic joke, but I see FIPS 140-2 more emphasized. The higher the level of the customer (the more authority they have) the more flexible they are. Some lower level labs don't really have much of a choice but accept a standard boiler plate set of certification stamps.

FIPS 140-2 is very narrowly constrained and the parts that aren't crypto-related are the same kind of boilerplate make-work that EAL2/EAL3 is. But also bear in mind that you can pull a list of EAL4+ products right now, and quickly see how many of them have had ridiculous vulnerabilities.

Re: US Navy to pay $1M to make Android more secure

#47

Earlier quoted context omitted.

Windows CE? I'm surprised. I always thought the NSA really seemed to be embracing Linux.

I guess the way the Government see the situation is. If they're paying Microsoft to provide them with a service/software with guarantees drafted up into a contract when SHTF the Government can turn it all back on Microsoft and say, "But the contracted stated you would be providing a secure platform..." You'd be surprised how popular Windows CE actually is. I've seen it used a lot on touchscreen kiosks here in Austral…

Well, I certainly hope of all our governmental organizations the NSA is going to be the least inclined to satisfy themselves with "passing the blame to the supplier when security is inevitably compromised"

Re: US Navy to pay $1M to make Android more secure

#48
post #19

Earlier quoted context omitted.

Hmm, who actually is the one to usually do this sort of thing? Clearly it is a good idea, but I don't think it really makes sense for the Navy to do it for themselves. Isn't this more the sort of thing the NSA should be doing on the behalf of everyone else in government?

I think the Naval Research Laboratory is more than capable. http://www.nrl.navy.mil

[deleted]

Re: US Navy to pay $1M to make Android more secure

#49
post #28

Earlier quoted context omitted.

yes, that struck me as odd actually. What about those submarines make them a good fit with android technology?

There's very little space on board a submarine. If the Navy was willing/interested in putting paper-based workflows onto Android devices, it could save a good amount of physical space on board.

This made me think of Halo/Star Trek, I can imagine a commander on deck speaking into a navy spec android device 'Captain's log, gregorian calendar date ...'

In all seriousness though, I forgot how premium physical space is on a submarine, this makes sense to me!

Re: US Navy to pay $1M to make Android more secure

#50
post #41
post #28

Earlier quoted context omitted.

There's very little space on board a submarine. If the Navy was willing/interested in putting paper-based workflows onto Android devices, it could save a good amount of physical space on board.

I just don't see the phone-sized form factor working too well. Maybe for taking log readings or simple lineups shifts it would be nice, but anything beyond that is either going to require SUBSAFE certification (e.g. fly-by-wire interfacing) or need to be tablet-sized or larger (e.g. running DC Central or looking up operating procedures). And God only forbid you drop one of those mobiles in the bilge...

Don't forget that Android is not just for mobile phones (cell phones for our friend from across the pond). Think of it as a portable personal device running an open sourced operating system with an emphasis on touch based UI.
Post reply on HN