Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

1–10 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#2
The good stuff is in the PDF:

https://www.gao.gov/assets/700/694913.pdf

- Running a port scan caused the weapons system to fail

- One admin password for a system was guessed in nine seconds

- "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise."

- Taking over systems was pretty much playing on easy mode: "In one case, it took a two-person test team just one hour to gain initial access to a weapon system and one day to gain full control of the system they were testing."

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#3
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#4
> Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise.

It's not too surprising and a little reminiscent of the security nightmare that are IoT devices.

All those weapon systems come out of hardware/engineering companies with little background in software engineering and the accompanying security best practices.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#5
post #3
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.

It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#6
post #3
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.

The massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#7
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

>Multiple weapon systems used commercial or open source software, but did not change the default password when the software was installed, which allowed test teams to look up the password on the Internet and gain administrator privileges for that software.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#8
post #3

Earlier quoted context omitted.

> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.

It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week.

My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between boats (or 4 max as most of these kids are just putting in their 4), and training is extremely specialized. Most parts of the systems (this especially from the mechanics) usually perform to about 10% their pitched lifespan from whoever made them before they fail, repeatedly.

The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet.

The only thing preventing access to a boat's network is standing orders and the threat of punishment. You can just plug right in.

Every system runs on the same network. This includes radar, weapons systems, anti-air, emergency comms, in-ship cameras...

This on top of the fact that half the people I talked to, the ones actually running these systems, are overworked 19 year olds with circles under their eyes. The only people over 25 seemed to be officers and pilots, maybe those guys know about the systems and can offer expertise? I'm not sure, I didn't get to talk to any of them.

I'm hoping my perception of the military is completely wrong, which is entirely possible because I didn't get to talk to that many people, maybe like 4 or 5 mechanics, a couple marines, and a couple of the network IT people, all relatively low rank. But, as of right now, I have absolutely no confidence in the military to withstand a full on cyberattack from a similarly provisioned military.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#9
post #8

Earlier quoted context omitted.

It's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

Many of your technical details are badly incorrect. Not sure who you talked to, but they're not well informed.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#10
post #9
post #8

Earlier quoted context omitted.

I had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between b…

Many of your technical details are badly incorrect. Not sure who you talked to, but they're not well informed.

Can you expand? Why are the IT people I talked to, working on these systems, so poorly informed about how they work?
Post reply on HN