Earlier quoted context omitted.
Is there any reason to believe the state of Russian/Chinese/etc. security is any better in this regard?
Russia's aging military hardware is an asset in this case, as it's not as vulnerable to electronic intrusion as a result of having little to intrude.
DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
91–100 of 225 posts
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#92Earlier quoted context omitted.
You should note specific issues, rather than a general complaint.
When people blame things on MBAs here, they tend to not elaborate with specifics either. MBAs are used as straw man punching bags on HN. Anything that goes wrong with a company where there’s the perception that the “obvious technical solution” was ignored, is blamed on this nebulous cabal of MBAs, who are apparently hired in droves just to sabotage their employer. For some reason it’s totally ok to vaguely blame the…
I think you're building a bit of a straw man. I think the criticism of MBAs rests on criticism of the idea that good decisions can be made by people that chiefly have "management skill" but lack "domain skill." A lot of people believe domain skill is extremely important, and if you stuff an organization full of empowered people who only have management skill, you'll get more bad decisions. You'll also get a lot of dysfunction as they spend too much time pursing the "management ideas" they're more comfortable with, and neglect "domain ideas."
This comment actually touches on some of these issues in detail: https://news.ycombinator.com/item?id=18179247
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#93Earlier quoted context omitted.
No networked computers on my ship.
Reminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#94The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…
My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#95Also, I couldn't help it, the DOD plans to spend 1.66 Trillion on these systems! Perhaps if we instead stop making new fangled, more complicated devices that with have tenfold more vulnerabilities to catch, how about we just stick with the machines we have and make then hardened. I imagine that it would save us loads if we just do that.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#96Earlier quoted context omitted.
They are trusted by internal machines -- since a lot of internal authentication relies on these certificates. The DOD long ago moved away from password-based authentication mechanisms to certificate-based authentication (GSC-IS initially (CAC), now NIST SP 800-73 (PIV; CAC II)) and so the system will have the correct certificates or the user generally won't be able to login. What I find as the most common error is th…
This bit is curious. I was issued a CAC while I was in, and as you said, it eliminated the need for passwords. But the internal sites (no matter if it was a laptop from the comm section, a hardwired desktop in a unit's building, or a desktop in a base facility) always failed the check for the certificate store. I always got the security warning (or insecure message) regardless of browser.
It seems we end up with a lot of possibilities for the states of these stores to diverge from our expectations ... I've been wondering how to verify a sane state for all these stores for even a use as simple as my own personally owned/controlled notebook ...
I'd really like a way to audit the system trust store in macOS and enforce that is in alignment with whatever the current 'blessed by apple' certificate trust relationships are and that any trust relationships I ever manually added by mistake/debugging have been removed...
I asked a question about this on stackoverflow but no one has responded ...
https://stackoverflow.com/questions/52527886/revert-all-cert...
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#97Earlier quoted context omitted.
They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…
It's not about taking over. Disabling them is sufficient.
> expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized use of an asset
This is the objective of the adversary in a conflict with respect to information and systems security. It doesn't matter if they can control a system, if they can make it less reliable it's still a win (but not as good). If they can get it to feed out false or misleading information to their opponent, it's a win (hacked a radar, can you show an extra blip on the screen or cause them to sometimes shift position and reduce the confidence of the operator?).
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#98Earlier quoted context omitted.
That isn’t remotely how it works.
What exactly do you mean? The specific scenario I described in very, very broad terms was from a lecture by Eric S. Lander about a specific bacterial cell. If you have an issue with the general description I don't understand it, since you don't say anything at all apart from some snide comment that doesn't even make sense to me. At the very least I would expect someone who bothers to reply because they disagree to sa…
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#99I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.
The catch is that on DOD systems, encryption is very difficult to add. That is, to be certified by the NSA and compatible with the military key infrastructure. So its better to avoid mentioning it unless its forced on you. Better is a relative term here. I mean, in terms of cost and effort to add. Not security.
Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
#100Earlier quoted context omitted.
My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no…
"Show me the incentive, I'll show you the outcome"