22 ms·
DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities
- danielvf 8y agoThe good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mode: "In one case, it took a two-person test team just one hour to gain initial access to a weapon system and one day to gain full control of the system they were testing."
- orf 8y ago> Operators reported that they did not suspect a cyber attack because unexplained crashes were normal for the system.
- Latteland 8y agoIt's like the worst possible scenario. Could it be this will be a wakeup call to the people that work on these systems? I doubt it, based on government procurement strategies like we saw with the website for obama care.
- komali2 8y agoI had the opportunity to tour the "USS BONHOMME RICHARD," as well as talk to visiting sailors and marines, this weekend during SF Fleet Week. My takeaway impressions (other than that god damn do these people drink and holy shit are they young), especially after talking to the mechanics and network IT folks, is that a ton of their systems are old, the manpower turnover is between 1-2 years as they get cycled between boats (or 4 max as most of these kids are just putting in their 4), and training is extremely specialized. Most parts of the systems (this especially from the mechanics) usually perform to about 10% their pitched lifespan from whoever made them before they fail, repeatedly. The windshield wipers on all Ospreys (those dank helicopter/plane things, think Ghost in the Shell) have been disabled/removed because their motors would catch fire in inaccessible places near the pilot's feet. The only thing preventing access to a boat's network is standing orders and the threat of punishment. You can just plug right in. Every system runs on the same network. This includes radar, weapons systems, anti-air, emergency comms, in-ship cameras... This on top of the fact that half the people I talked to, the ones actually running these systems, are overworked 19 year olds with circles under their eyes. The only people over 25 seemed to be officers and pilots, maybe those guys know about the systems and can offer expertise? I'm not sure, I didn't get to talk to any of them. I'm hoping my perception of the military is completely wrong, which is entirely possible because I didn't get to talk to that many people, maybe like 4 or 5 mechanics, a couple marines, and a couple of the network IT people, all relatively low rank. But, as of right now, I have absolutely no confidence in the military to withstand a full on cyberattack from a similarly provisioned military.
- jki275 8y agoMany of your technical details are badly incorrect. Not sure who you talked to, but they're not well informed.
- komali2 8y agoCan you expand? Why are the IT people I talked to, working on these systems, so poorly informed about how they work?
- jki275 8y agoFirst, most IT personnel on ships (especially one as ancient as the Bonhomme Richard) do not work on weapon systems. Most of them would not even be able to discuss where on the ship they are intelligently, let alone what they connect to. The people you talked to simply aren't informed. You even note that you were talking to 19 year old kids, and they're not generally the ones who know what's going on.
- komali2 8y agoWell that's a question I have as well - who actually knows what's going on there?
- jki275 8y agoPeople like me.
- komali2 8y agoPeople named jki275 that post one-sentence replies on Hackernews? ;) What kind of work do you do? You're in the military? What's your rank / job description? That's the kind of information I'm curious about. If the answer is "I can't tell you because it'll expose personal information," well, I'm not the one that outed you lol.
- alarge 8y agoI don't know that it's just the procurement strategies to blame. Many years ago, I was asked to bring a command and control system into (Orange Book) C2 compliance. Among the things I introduced were personal user accounts with some restrictions around allowable passwords. The users of the system (most of which were "former" fighter pilots) were furious with the restrictions, which they viewed as getting in the way of their jobs. They invariably created a shared login with the simplest password they could come up with that would meet the requirements (e.g., Abc123 or some such). Security can't be imposed by the system on its users. They have to cooperate.
- rphlx 8y agoA decent fraction of the population views password restrictions as a challenge to come up with the shittiest, least secure password that they possibly can while still meeting all restrictions. You can blame users for that with some justice, but as a system designer, it's still your responsibility provide security despite shitty but reasonably likely human behavior. With modern crypto there are very few systems where it's appropriate to have a user-selected <=12 character password for primary auth, yet unfortunately that continues to be widespread for banks, ecommerce, and (probably) some military systems. High-end security people seem to almost universally hate short user-selected passwords (except when they have to break them..) but old practices die hard and old systems take a long time to be replaced.
- komali2 8y agoThe massive weight of the American military is going to be a wonderful addition to its enemies when they take it all over using "admin:admin" .
- CPLX 8y agoSHALL WE PLAY A GAME?
- ItsMe000001 8y agoThey will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidentally making a protein that is turned off, but sometimes it turns out it's useful to have it around when the environment changes, but an error-free efficient system would not have made it).
- rhexs 8y agoThat isn’t remotely how it works.
- ItsMe000001 8y agoWhat exactly do you mean? The specific scenario I described in very, very broad terms was from a lecture by Eric S. Lander about a specific bacterial cell. If you have an issue with the general description I don't understand it, since you don't say anything at all apart from some snide comment that doesn't even make sense to me. At the very least I would expect someone who bothers to reply because they disagree to say what exactly it is they disagree with, and also be specific about it. While I'm a CS person I have a broad background in life sciences too.
- pcnix 8y agoIf the bugs were annoying enough that they'd prevent proper functioning of the system, they'd be fixed. If the current users are able to get some utility out of the system with all the bugs, then you can be rest assured so will the hackers.
- GraemeL 8y ago>Multiple weapon systems used commercial or open source software, but did not change the default password when the software was installed, which allowed test teams to look up the password on the Internet and gain administrator privileges for that software.
- jandrese 8y agoEven worse is that institutional problem where you have people constantly cycling on and off of this hardware that was never designed for a multi-user environment, so default passwords are the order of the day. At best they changed the password and then put it on a sticky note attached to the monitor. The last thing you want is someone forgetting their password to their tactical system while out at sea and having to sail back into port to get the vendor to reset it for you. And really, the first case is no worse than the old days with manual controls that just anybody could walk up and fiddle with.
- InitialLastName 8y ago> And really, the first case is no worse than the old days with manual controls that just anybody could walk up and fiddle with. In that case, you could trust physical security to some extent; someone really not intended to be in contact with the device could be prevented from doing so by some dude with a big gun. Now, those devices are networked, so someone could figure out an access method and use it on all the devices in the field at will.
- TeMPOraL 8y agoWhile not trying to reason from fictional evidence, this reminds me of Battlestar Galactica. In the series, they made a point of Galactica running on non-networked computers (unlike the rest of the fleet), as networking them together made it easy for the adversary to pwn the whole ship.
- sjg007 8y agoThey'd probably helicopter the IT guy in to reset it but still I'm going to posit that they have a procedure for this that may not require physical access and may have remote-access via a secure line.
- drawkbox 8y ago> Test reports we reviewed make it clear that simply having cybersecurity controls does not mean a system is secure. How the controls are implemented can significantly affect cybersecurity. For example, one test report we reviewed indicated that the system had implemented rolebased access control, but internal system communications were unencrypted. Because the system’s internal communications were unencrypted, a regular user could read an administrator’s username and password and use those credentials to gain greater access to the system and the ability to affect the confidentiality, integrity, or availability of the system. "Do you want to play a game?" This is some scary bad WarGames like security, password 'joshua' level. > Program offices were aware of some of the weapon system vulnerabilities that test teams exploited because they had been identified in previous cybersecurity assessments. For example, one test report indicated that only 1 of 20 cyber vulnerabilities identified in a previous assessment had been corrected. The test team exploited the same vulnerabilities to gain control of the system. When asked why vulnerabilities had not been addressed, program officials said they had identified a solution, but for some reason it had not been implemented. They attributed it to contractor error. Ah, the old blame the 'contractor error' and 'not invented here' syndrome. Looks like engineers aren't in the power structure to change these things, scary if the military is driven like an MBA only led business with no influence from engineering/security.
- k_sh 8y ago> scary if the military is driven like an MBA only led business with no influence from engineering/security Having known many people that worked in/around the military and defense industry, this seems like our reality.
- killjoywashere 8y agoThe modern DoD is based around the Asst Sec Defs and business processes put in place by Robert McNamara, who came from Ford. It's all stats and businees. Engineers and scientists are generally considered a sideshow, a workforce to quantitate.
- drawkbox 8y ago
- closeparen 8y agoAren’t there reams of security standards and thousands of man-years of security compliance bureaucracy for even the most basic DOD IT projects? And they still have trivial vulnerabilities like this? Is the process really that useless?
- 0xffff2 8y agoI think the difference is between "DoD IT projects" and DoD projects that have networked computer systems. My hunch is that most of these vulnerabilities are in systems that are not labeled as "IT projects".
- thrower123 8y agoMaybe? I somewhat doubt it, since I work for a company that has a couple of DOD IT products that are in fairly widespread use, and I don't know that we have done any security compliance to speak of over the past seven or eight years. In that time period we haven't done a ton of work, but we have had to make some changes to move from a really ancient JRE version to a slightly less ancient one.
- pjc50 8y agoBureaucracy not only does not discourage vulnerabilities unless they're on a very short list, it actively encourages them by driving away the kind of imaginitive thinking you need to think of them.
- jfrankamp 8y agoA side note: the picture in the first few pages of the pdf looks like the original authors intent, aka, not pointing to a particular part of the fake plane for each subsystem. The picture on the web was "upgraded" editorially to point to specific parts for... ? Marketing reasons? Not sure but its hilarious because the logistics system of the web version of the fake plane is in a missile.
- PhasmaFelis 8y ago> the logistics system of the web version of the fake plane is in a missile. To be fair, it could also be a death ray laser. The whole thing looks a lot more like Star Wars than a real plane. It has asymmetrical wings.
- deleted 8y ago[deleted]
- whatupmd 8y ago"In operational testing, DOD routinely found mission-critical cyber vulnerabilities in systems that were under development, yet program officials GAO met with believed their systems were secure and discounted some test results as unrealistic. "
- pjc50 8y agoMy thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works? Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference. But since then? All the wars have been overseas with no real threat to the mainland US; there was a real technological race against the Soviet Union, but that ended in the 1990s. The post-911 wars were more of an excuse to settle scores and play the Great Game than a real effort against terrorism (no pursuit of the Saudis for example). The consequence is that the main thing that matters is selling the technology to the Pentagon, or promoting a career inside it. Nobody really believes that if they procure a crappy IT system the enemy is going to fly a 747 into their office. Someone might get killed, but nobody they know or who matters, and it's never going to come back to the project manager or procurement person who made terrible, expensive, uninformed choices about technology.
- willidiots 8y ago"Show me the incentive, I'll show you the outcome"
- polyomino 8y agoThis is more like: "Show me the outcome, I'll guess the incentive"
- willidiots 8y agoThat's fair, parent is post-hoc theorizing. I have to hope that the people in charge of these things -do- care, and that it's simply difficult to get this right. However, given some of the things in the PDF, one has to wonder...
- TeMPOraL 8y agoThis is a very good question I've been pondering for years, and I generally came to the same conclusion wrt. military-industrial complex in general - not just software. It seems to me that no one expects any war that would hurt the US any time soon, so it's an open season for fleecing the military budget for all it's worth. I also wonder sometimes if a similar thing isn't happening in enterprise software - that is, actual software doesn't have to work; it only has to serve as an object of trade between companies, and all the problems will disappear in general organizational noise & inertia.
- shpx 8y agoThe day they stop calling it "cyber" is the day we can rest easy, knowing that people who know what they're doing have been put in charge. https://xkcd.com/1573/ https://xkcd.com/1573/
- the_duke 8y ago> Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise. It's not too surprising and a little reminiscent of the security nightmare that are IoT devices. All those weapon systems come out of hardware/engineering companies with little background in software engineering and the accompanying security best practices.
- pbhjpbhj 8y agoThey don't know how to hire a security advisor or external team? What I'd be most concerned about is that the procurement process is favouring companies who clearly aren't up to designing in rudimentary security, in weapons systems, ... smh. That seems like getting clothing made and not having anyone flag that it was glued together with PVA instead of being sewn; and the company you hiredb not having anyone who realises that's a fundamental problem.
- drak0n1c 8y agoMeanwhile, the software companies capable of fixing these issues face internal revolt at the idea of defense contracts. Apparently inaccurate targeting systems and vulnerable firmware in equipment that is going to deployed (regardless of protest) is better for pacifism?
- nickpsecurity 8y agoThere's been companies around willing to do the work for a small premium for a long time. There's also software designed for security or making it easier. Here's a few, semi-random examples: http://www.sis.pitt.edu/jjoshi/Devsec/CorrectnessByConstruction.pdf http://www.sis.pitt.edu/jjoshi/Devsec/CorrectnessByConstruct... https://www.ghs.com/products/safety_critical/integrity-do-178b.html https://www.ghs.com/products/safety_critical/integrity-do-17... https://runtimeverification.com/match/ https://runtimeverification.com/match/ https://galois.com/blog/ https://galois.com/blog/ http://sel4.systems/ http://sel4.systems/ https://muen.codelabs.ch/ https://muen.codelabs.ch/ The defense buyers just don't use such companies or products in most cases. They know they don't have to due to corruption mostly. The money they save might even get someone a bonus for achieving some metric like keeping costs down. Mass market is similar where they don't buy the stuff either. So, the supply of high-security systems are extremely low, usually high per-unit as a result, and not prevalent. Sad but true...
- Sniffnoy 8y agoNon-mobile link: https://www.gao.gov/products/GAO-19-128 https://www.gao.gov/products/GAO-19-128
- MrLeap 8y agoI was a dev contractor for the US Army for a few years. None of this surprises me. They had some goofballs policies that made it seem like vulnerabilities were the goal. I could bitch at length. Their TSA style security theater practices were the order of the day. The IA training was an embarrassing joke and they made you do it often enough to make you a little crazy. I just checked the certificate of networthiness page and they don't have a valid SSL certificate. I recall that being the case years ago too. I wonder if it's been that way for the last 7 years? That's a cute little terrarium of the whole biome I remember. Off topic a bit, but that all aside... I am more proud of the work I did there than at any other place in my career. I got a lot of excitement and engaged feedback about the interactive learning materials I created. I'll never know if it made any difference, but the mere fact that someone's son or daughter COULD have noticed an IED threat they wouldn't have otherwise because of my work gives me all sorts of proud fuzzies. That work had way more meaning than all the other CRUD/ML/Advertainment schlock I'll get to do for the rest of my life :)
- noxToken 8y ago> I just checked the certificate of networthiness page and they don't have a valid SSL certificate. I recall that being the case years ago too. I wonder if it's been that way for the last 7 years? That's a cute little terrarium of the whole biome I remember. That's not quite true. Internal use sites don't have a valid cart issued by a "default" external vendor. Public sites use existing CAs that are in use by the public. E.g., the Marines public facing site[0] is signed by DigiCert. If you go to a site that's public facing but for internal use like MoL[1], you'll see that the cert is issue by an internal DoD CA. This is intentional. The DoD has an internal CA already set up. These internal use sites are a gateway to sensitive information, so the DoD doesn't want to rely on an external CA for HTTPS. What I never understood was why these internal CAs weren't marked as trusted on the internal machines. That would avoid the browser warnings when accessing one of these site from DoD hardware, and it would (in theory) force the user to double check when accessing the site from an external device. [0]: https://www.marines.com/ https://www.marines.com/ [1]: https://mol.tfs.usmc.mil/mol https://mol.tfs.usmc.mil/mol
- 8y ago
- microcolonel 8y agoGDC4S (now General Dynamics Mission Systems) and NICTA have been working on seL4, and it at least seems that USDOD has something to build on, if they want to start providing assurances of some form on weapons systems. They'll really have to set the passwords properly though.
- anon49124 8y agoWhat's eyebrow-raising is that it's been used as para/virtualization platform for Linux. (Ordinarily, SELinux MLS/MCS is pretty good though.) If something like Minix 3 "NetBSD" in Rust ran on seL4, that would inspire more confidence.
- microcolonel 8y ago> If something like Minix 3 "NetBSD" in Rust ran on seL4, that would inspire more confidence. Yeah, I've been thinking about that for a while. There is Genode/seL4, but it's hard to say if it makes as much sense.
- Animats 8y agoThe US is going to lose a war this way.
- ceejayoz 8y agoIs there any reason to believe the state of Russian/Chinese/etc. security is any better in this regard?
- airstrike 8y agoNo, but all that does is ensure we all lose collectively
- kazagistar 8y agoThat is true of any war that the US has even a remote possibility of losing.
- vermilingua 8y agoThat is true of any war that the US has even a remote possibility of entering.
- dleslie 8y agoRussia's aging military hardware is an asset in this case, as it's not as vulnerable to electronic intrusion as a result of having little to intrude.
- noobermin 8y agoThen there's a good argument the billions the DOD spends on its "modernization efforts" should be spent elsewhere.
- Analemma_ 8y agoUS military strategy and tactics are much more reliant on high-tech advantages than other countries though. If everyone’s tech all goes down, we’re going to be hit a lot harder.
- ISL 8y agoYou'll see things here that look odd, even antiquated to modern eyes. Phones with cords, awkward manual valves, computers that barely deserve the name. But all of it is intentional. It's all designed to operate in combat against an enemy who could infiltrate and disrupt all but the most basic computer systems. Of course, those attitudes have changed through the years and Galactica is something of a relic. A reminder of a time when we were so frightened by the capabilities of our enemies that we literally looked backward for protection. Modern battlestars resemble Galactica only in the most superficial ways...
- WrtCdEvrydy 8y agoSurprise... only one new 'modern battlestar' survived... because it was offline.
- AlimJaffer 8y ago.. and now I need to re-watch the series again. Or at least the opener.
- admiralEyebrows 8y agoNo networked computers on my ship.
- deleted 8y ago[deleted]
- chrisseaton 8y agoNo networked computers? I do not believe you. Even my little soft-skinned two-person wheeled command vehicle has a network of about twenty discrete computer systems, such as multiple radios, GPS, displays, input terminals.
- enraged_camel 8y agoReminds me of Battlestar Galactica, where the all the ships in the fleet get hacked by Cylons, have their shields taken down and promptly destroyed, but Galactica survives because it's computers aren't networked.
- unit91 8y agoI was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.
- WrtCdEvrydy 8y ago> The enemy here is fairly low-tech. Shouldn't be a problem. Would be perfectly acceptable if your hardware was only used for 2-3 years against only low tech enemies that don't have access to electricity during that whole time.
- pbhjpbhj 8y agoSounds like classic underestimation of your opposition.
- TeMPOraL 8y agoYup. The enemy may be poorest of poor, but in this day and age, their entire population probably has smartphones (or at least dumbphones), and there's plenty of smart people with nothing better to do than to play with computers. There aren't many low-tech places left on this planet, where it comes to computing.
- maxxxxx 8y agoI think this can be a downfall of the US military if they ever get into a conflict with a capable enemy. They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. I wonder what would happen to the B-2 bomber or aircraft carriers if they had to fight China. My guess is these weapons would be eliminated very quickly.
- orf 8y ago> They are so used to use super complex and expensive weapons against enemies who can't really put up a resistance. Tell that to Vietnam and Afghanistan. Historically the US does well against standing armies (Iraq for example), but absolutely terribly against low-tech enemies who don't engage in a way that allows these super high tech weapons to be used effectively. Reminds me of this: http://www.kiplingsociety.co.uk/poems_arith.htm http://www.kiplingsociety.co.uk/poems_arith.htm A scrimmage in a Border Station- A canter down some dark defile Two thousand pounds of education Drops to a ten-rupee jezail[1]. The Crammer's boast, the Squadron's pride, Shot like a rabbit in a ride! 1. https://en.wikipedia.org/wiki/Jezail https://en.wikipedia.org/wiki/Jezail
- underthelevel 8y agoTelnet: the backbone of our Defense Industry
- titzer 8y agoIt's like, on a civilizational level, we're just begging for a scenario where we accidentally destroy ourselves.
- ourmandave 8y agoNot to play the Whataboutism card, (proceeds to play whataboutism card), but has anybody pen tested the Soviet's or Chinese' systems? Just thinking this isn't a U.S. only problem.
- 1001101 8y agoNow they can queue up some multi-billion dollar contracts to fix it. I'm in the wrong business.
- _audakel 8y agoLol let's do a startup
- deleted 8y ago[deleted]
- noobermin 8y agoI guess my question then is why have a computer attached to these systems in the first place, or if you must, why not make it as dumb as possible? Why include more points of failure? Also, I couldn't help it, the DOD plans to spend 1.66 Trillion on these systems! Perhaps if we instead stop making new fangled, more complicated devices that with have tenfold more vulnerabilities to catch, how about we just stick with the machines we have and make then hardened. I imagine that it would save us loads if we just do that.
- hlieberman 8y agoIf you are interested in helping the US Government fix this particular trashfire, consider joining the Defense Digital Service. We work on a variety of DoD projects as part of the US Digital Service "tech peace corps". https://www.dds.mil/ https://www.dds.mil/ If you're not ready for that level of commitment (though it's amazing work), and you're interested in being involved as a security researcher, reach out to me and we can talk about joining our bug bounty program.
- iaabtpbtpnn 8y agoIf this intrigued anyone else, just a quick summary: 3-6 week interview process, no relocation assistance, no bonuses, no equity, citizenship requirement, oh and the kicker: drug testing.
- hlieberman 8y agoYup! We’re all employees of the federal government, so we have to meet the requirements of all Federal positions. Honestly, you don’t do this job for the money. I took a pay cut when I joined, on top of losing bonuses and equity. You join because you want to make a real difference in people’s lives, in a visceral, real way. I can say without exaggeration that there are people who would have died except for the work that our team had done. Even when the stakes aren’t life or death, the impact you can have working for USDS is massive compared to anywhere else. You can personally change the lives of hundreds of thousands or millions of people. That’s the kind of hook that beats equity for me any day.
- killjoywashere 8y agoKeep up the good work. If you see Matt Cutts, say hi for me.
- BurnGpuBurn 8y ago> You join because you want to make a real difference in people’s lives, in a visceral, real way. What that difference may entail varies greatly though. For one, it might be not being blown up by that IED. For another, it might be being bombed to bits at your cousins wedding, along with the other 40 members of your family, by a drone operator in Nevada. Very visceral indeed. If you think that working for the military is "doing good" and the US is oh so innocent I suggest you watch the excellent documentary The Untold History of the United States by Oliver Stone [0]. [0] https://en.wikipedia.org/wiki/The_Untold_History_of_the_United_States https://en.wikipedia.org/wiki/The_Untold_History_of_the_Unit...
- degenerate 8y agoThe graphic on page 26 of the report is kind of cute: https://i.imgur.com/MWrM2i8.png https://i.imgur.com/MWrM2i8.png The inclusion of this graphic makes me realize the report is not intended to explain the situation to engineers. It's to explain the problem to well-decorated higher ups that probably don't understand modern technology all that well, yet are calling all the budget shots.
- sesteel 8y agoA ton of commercial systems have similar vulnerabilities. Teslas have gotten hacked remotely a multitude of times over several years. People who attack/hack systems are specialized in ways that those engineers that build systems are not. None of this should be all that surprising. New recommendations on proper system design should mean future programs should have budgets to hire people to mitigate these problems. However, it should always be assumed there are vulnerabilities that can be exploited by others; any claims to the contrary should be met with extreme skepticism.
- samstave 8y agoWhen I was at Lockheed - we were building the RFID tracking systems they used to track various everythings all over - and they were trying to make it a part of the Port Security for every port... and even had Tom Ridge join the board... well, I recall asking about the security of the systems (I was the IT lead and was to help design the global port tracking system which they hoped to track all shipping containers) -- there was no encryption/authentication on any of the tags. If you had a reader, you could read/write the tags. They had not even thought about securing these systems - and they were trying to tout them as a security system for weapons shipments. They even had tags that had G-sensors that were to be able to tell you if a munition was dropped, if it had armed (some weapons will only arm themselves once a certain g-force is reached which indicates to the weapon they have been launched.)
- lifeisstillgood 8y agoSilver lining: when the DOD find good ways to harden their systems, we can all copy them. Cloud: it's probably unplug the aerial / network cable
- HelloNurse 8y agoI'm afraid they need to catch up with the rest of the world before advancing the state of the art. The best case scenario is a quick cultural shift, with awareness of computer security threats overflowing from the military to laws and society in general.
- remarkEon 8y agoMost of the comments outline how awful and dire the situation is (or probably is). I'm less interested in this than I am in what we could do to fix it. Is it just more money to hire competent security engineers? Is it a more responsive talent acquisitions process that gets the right people in at the right time?
- arink 8y agoThere is no motivation on the defense contractor side to do anything more than satisfy the requirements of the contract. And any R&D spent should result in an interesting demonstration that brings in more business. Standard operating procedure would need to change so the government entity has security as a requirement, details on how the requirement can be satisfied, and a bunch of money to pay for it. So tack on $X million for each contract to have a 3rd party audit the code, documentation, and hardware for security vulnerabilities. And an added maintenance contract to fix any future vulnerabilities for the lifetime of the program (20+ years most likely). From the higher up side, what do you get for all that money spent? No new functionality, no fancy demos. Going to be hard to convince them security is important when they can fund something they view as more critical or more interesting. EDIT: To answer the question of what can be done, I think it'd require a culture change on the contracting side. The engineering side of the house is mandated to only do work that relates directly to the contract. The hours bid will likely be for the minimum necessary to satisfy those requirements. You can create a new interface, but you won't have the time to do any fuzz testing for example.
- dzonga 8y ago$1.7T is a lot of money just to protect your major investments in killing people efficiently. Modern society I guess.
- jvanderbot 8y ago"Another test team reported that they caused a pop-up message to appear on users’ terminals instructing them to insert two quarters to continue operating."
- diogenescynic 8y agoGood luck closing the barn door after the horse has bolted: https://www.wired.com/2011/11/counterfeit-missile-defense/ https://www.wired.com/2011/11/counterfeit-missile-defense/ I am no military expert, but it seriously looks like China has us in a stranglehold.
- jhabdas 8y agoMurderers the lot of them. If this kind of filth piques your interest perhaps you should question the motives of your king.
- Illniyar 8y agoAre these remotely activated systems that are at risk (like drones)? if not, why is any weapon system that doesn't need remote activation actually plugged into a public network?
- ataturk 8y agoI have read rumors to the effect that our own rogue elements in the spy agencies are exploiting these known vulnerabilities. It seems not everyone is on the same team in our own government, which totally sucks, but it has been that way for a long time. We need a government by and for the people.
- gpvos 8y agoIf I were the Russians, Chinese, or North Koreans, I would heavily invest in offensive hacking capability. Oh wait, they're already doing that.