5 ms·
The number of flaws in software running critical infrastructure is terrifying- very very little of it was ever designed or implemented with serious threats in m
by randomfool 11y ago
The number of flaws in software running critical infrastructure is terrifying- very very little of it was ever designed or implemented with serious threats in mind.
If you look at what was done at Natanz then think of what that group could have done against your local power grid, or water supply, or grocery store supply chain, it is scary.
As an American, our current wars are all fought in distant lands- out of sight and mostly out of mind. The next generation of warfare will strike home.
- maze-le 11y agoInteresting notion... has anyone at the DOD even considered stricter software-QA standards for critical infrastructure-projects? Or anything regarding ... you know defense -- defense as in defending, not as an euphemism for warfare...
- 616c 11y agoSo, as per usual, an anecdote. In high school, as a budding Middle East geek, I was told to apply to Saint Andrews of Scotland. Ironically, beyond golf, they had a top notch group of counter-terrorism experts in their security studies (the fact that this was what dawned on people when I studied Arabic in HS without question should have been a red flag for Arabic language academia in the West, but I digress). I never went, but they said another guy in my high school years before did. What did he end up doing after studying with these guys? The state of Illinois in the US apparently had a rare Office of Counter-Terrorism (as did NJ, but it was reorganized into their state level DHS) and all he did was analyze the physical security and threat risks around reservoirs and other infrastructure. Primarily reservoirs. If you are worried about the software stack, you are wasting your time. The end game is far easier and just requires jumping a fence.
- mauricemir 11y agoI thought it was CIT that was the top dog for this sort of thing after Shrivenham merged with them. And with the really sensitive CS jobs I suspect the USA will be similar to how the Uk used to be ie all 4 grandparents as native citizens.
- 616c 11y agoI cannot really tell from the details re Shrivenham but you know better than me. As for the grandparents thing: it depends. I have European friends told it was not a problem, and Arab friends that have been warned before applying there will be no rainbows or unicorns in their road to security clearances, and likely be full-on rejected.
- mauricemir 11y agoDidn't realize that Non US Citizens could even get TS clearance except in special circumstances ie your on secondment from MI5 or MI6 or similar organization
- xnull2guest 11y agoIt is a lucky fact that for the past 10 years huge investments have been made in securing infrastructure inside the United States. That's not to say we aren't assailable (look at Natanz - it was an air gapped network; or better yet look at the attacks on US infrastructure we do know about). Washington has compared cyberwarefare to Basketball rather than Soccer. In Soccer the offense and defense are mostly matched and the team to score those few big shots take the victory. Cyberwar isn't like that. Cyberwar is like Basketball. The defense can only slow the offense - and the victor is the team that scores more points, more often. I do not know about the implication about wars being fought on the homefront. As far as kinetic warfare it seems less likely - but yeah when it comes to cyber essentially every country has a home there. One more note. The military, from this year onward, is investing in something known as red teaming as a standard process for military R&D. Red teaming is the active no holds barred exercise where hackers are set loose on a target while a blue team tries to detect, mitigate and expunge them. Red teaming will now until forever be featuring in the development of new US weapon systems. Everything from RPGs to tanks and helicopters to drones to radar to radios.
- m0dc 11y agoA relevant quote from Chris Inglis, former NSA Deputy Director: "If we were to score cybersecurity the way we score soccer, the tally would be 462-456 twenty minutes into the game."
- rjaco31 11y agoOn the other hand, it's his job to promote FUD in order to get more funding for his agency..
- tomjen3 11y ago>As an American, our current wars are all fought in distant lands- out of sight and mostly out of mind. The next generation of warfare will strike home. To invade the US you have to be Mexico, Canada or send an entire invasion fleet across the Pacific or the Atlantic oceans. That means you are look at supply lines 3000 miles long, after you have contended with the most powerful navy in the world. To launch a cyber attack you have to be on the internet. By shrinking space so much every single country is placed next to all the other countries. This effectively means that you no supply lines and can hack the US no problem. The mainland US is relatively poorly defended in cyber space, but that has normally never been an issue.