Slashdot Mirror


The World's Most Dangerous Password

NonNullSet writes "Minutemen ICBMs were deployed in the early 1960s, and grew to over 1000 in number. They were allegedly protected from a "rogue launch" by an approach known as PAL (Permissive Action Link). The PAL required that the correct 8-digit launch code be entered by the missiliers before the missile would establish ignition. What if all the PAL codes had been set to '00000000,' and 'everyone' in the Strategic Air Command knew it? That is unbelievably what happened, as described in this article from the Center for Defense Information. Not exactly a great example for getting people to choose difficult passwords!"

20 of 696 comments (clear)

  1. trust by Doc+Ruby · · Score: 4, Insightful

    This is why we trust politicians, ridiculous as they are, with our lives, and make the warriors answer to them. Because incompetent politics generally inhibits war, while incompetent warriors encourage it. And they're all incompetent - nobody knows the right way to do it.

    --

    --
    make install -not war

    1. Re:trust by Tiro · · Score: 4, Insightful
      No, you're wrong;

      In the current political establishment in the US, it is the politicians & Pentagon civilians who are promoting war, and the officers were generally very skeptical of what they were doing.

      Basically one portion of the political elite has decided that we should start acting like Israel if we are to maintain political power in the world, and they have gone on the offensive, entering into many regional conflicts around the world. I would argue this goes back to the Clinton administration at least; Wolfowitz and Pearle have taken it to the logical extreme.

      Remember how skeptical retired General Clark was of the war when he became a politician? So was Eisenhower; he warned us of the military-industrial complex, which becomes dangerous because the big money/corporate side of it has lots of influence on Washington politicians. Guys with military experience often know better than the politicians, and this is why Kerry or McCain would be much better leaders than the wide array of war cheerleaders in power now who avoided the draft in various ways [see last couple of weeks of doonesbury].

    2. Re:trust by Zak3056 · · Score: 4, Insightful

      Because incompetent politics generally inhibits war, while incompetent warriors encourage it.

      You, sir, are completely incorrect in your assertation. Once upon a time, you might have been largely correct--back in the days when those who had military power were the same people as those with political power (Napoleon for example) the warriors would be the ones to start the wars.

      OTOH, looking at the history of 20th century US wars, not one was started by soldiers. Politicians are the ones who lead us into wars. Soldiers are the ones who die fighting them. Learn the difference.

      --
      What part of "shall not be infringed" is so hard to understand?
    3. Re:trust by Jerf · · Score: 4, Insightful

      As has been clearly demonstrated recently in Iraq...

      Indeed; incompetent politics can start wars as well as prevent them.

      If Saddam Hussein didn't have WMDs, all he had to do was cooperate with the inspecters, verify he didn't have them, and there would have been no war. He'd still be alive, running the country, and killing whoever he pleased, whenever he pleased.

      Instead, he let his ego get in the way of his politics, he fought the inspecters tooth and nail, and it ended up running his regime into the ground.

      (There's some more to the story then that, such as how stupid it is to run a "shoot the messenger" regime if you actually want to survive, but that outline is true.)

      Incompetent politics can definately start wars.

      (Oh, you were trying to blame the current President? Maybe if he'd actually started this war that would make sense, but since there is an unbroken string of broken UN resolutions dating back to Saddam's invasion of Kuwait, I'd say it makes just as much sense to call this a continuation of that, Saddam's Greatest Mistake. Not saying Bush is blameless, just saying that if you want to point at one person who's utterly incompetent politics for over a decade started this war, it's much, much more rational to point at Saddam. One little thing he had to do to remove any pretense, and his ego wouldn't let him do it.)

    4. Re:trust by Zork+the+Almighty · · Score: 4, Insightful

      "The reason we start a war is to fight a war, win a war, thereby causing no more war!"

      --

      In Soviet America the banks rob you!
    5. Re:trust by LPetrazickis · · Score: 4, Insightful

      If Saddam Hussein didn't have WMDs, all he had to do was cooperate with the inspecters, verify he didn't have them, and there would have been no war. He'd still be alive, running the country, and killing whoever he pleased, whenever he pleased.

      Yes, announcing that you don't have significant weapons and appearing weak is a good idea when you have a powerful and belligerent Iran next door.

      --
      Is this a sigs-optional kind of place? 'Cause I am totally down with that if you know what I mean.
    6. Re:trust by Anonymous Coward · · Score: 5, Insightful

      " but since there is an unbroken string of broken UN resolutions dating back to Saddam's invasion of Kuwait, I'd say it makes just as much sense to call this a continuation of that"

      Then I guess we'll be taking out Israel next, for all the UN resolutions they've broken/ignored?

    7. Re:trust by thdexter · · Score: 4, Insightful

      Oh, you were trying to blame the current President? Maybe if he'd actually started this war that would make sense, but since there is an unbroken string of broken UN resolutions dating back to Saddam's invasion of Kuwait[...]

      Link me to the UN resolution that gives the US executive power and the ability to act as its security council without oversight or resolution.

      --
      I'm on a road shaped like a figure eight; I'm going nowhere but I'm guaranteed to be late.
    8. Re:trust by Bald+Wookie · · Score: 5, Insightful

      Yes, announcing that you don't have significant weapons and appearing weak is a good idea when you have a powerful and belligerent Iran next door.

      Given a choice of fighting Iran or the US, I'd take Iran every single time.

    9. Re:trust by GSloop · · Score: 4, Insightful

      Holy cow...

      We overthrew an deomcratically elected gvmt in Iran in 1953 and supported the subsequest Iranian governments in large style.

      When the Shah oppressed his people without consience for more than 20 years, and was finally thrown out, the Iranian revolution occured in 1979.

      Jimmy Carter was elected in 1976 and had little time to reverse the course set by Eisenhower and the following administrations.

      To blame Carter for the disaster that Eisenhower created in Iran is simply a foolish and ignorant thing to do.

      And it's no wonder after US sponsered oppression that the Iranians hated us.

      (And thus follows Iraq. We hate Iran. Saddam hates Iran. Lets arm that despot to attack Iran. Oops - that wasn't such a great plan... And thus follows our ignorant, evil, and "to-hell-with-the-rest-of-the-world-as-long-as-we- get-ours " policy of dealing with the rest of the world. The USA has some very good people, but we have often had government who have done massive evil in the name of "freedom" and "democracy." It's a shame.)

      Cheers,
      Greg

  2. The world was different then by sloshr · · Score: 5, Insightful

    Things have changed on the global level more than just a little bit, and I'd imagine a good deal of the security surrounding the prevention of launches centered around the PHYSICAL security. If the bad guy can't reach the keyboard to enter the codes - well, then, does it matter what the passwords set to?

    For better or worse, the system seemed to have worked - there weren't any unauthorized missiles launched that I'm aware of.

  3. Totally wrong. by ObiWonKanblomi · · Score: 4, Insightful

    As with any mission critical systems, there is redundancy in every aspect of the ICBM system from the authentication to the verification of the target being neutralized. So what if there was a password set to 0000000? There still has to be a number of other things set by others in numerous locations in order to do this. One reason was so that the president could not launch a missile on a bad hair day or a mad general (or group, in fact) could not launch in order to lead a coup.

    in addition, the passwords for the different sub-systems would vary as well as require a number of actual physical keys in order to get the nuclear war machine into motion.

    If you really think it only takes one password to launch an american military nuke (even if we were in the 60s), you're totally mislead.

  4. Re:Its only a bad password by Kjella · · Score: 4, Insightful

    I cant imagine anyone who had ACCCESS to ust this password having used it, the fact that were all still here shows it was perfectly secure, dont forget its not like some script kiddie could hop on the "Net" and use this password. There were some SERIOUS layers of physical security.

    *zoom back three years* "the fact that noone has ever deliberately flown a jumbojet into a building shows it is perfectly secure" I hope the military has some better understanding of risk analysis ;)

    There were serious layers of physical security? How serious? Just as serious as their passwords? Besides, the brass may be tough but the grunts guarding it are not above blackmail or greed.

    Good security is layered. That also means that breach of security shouldn't be caused by a single failure. But in reality it often turns out one or no layers of security are actually *working* because everybody assumes the other layers will cover for it.

    Kjella

    --
    Live today, because you never know what tomorrow brings
  5. The article really is quite fascinating by dachshund · · Score: 4, Insightful
    Don't you need launch keys, and oh yeah, physical access to a heavily gurded military installation?

    Given the enormous discretionary power held by whoever has LCC control, effective measures for denying LCC access to individuals or groups bent on carrying out an act of nuclear terror are self-evident security requirements.

    In the recent past, such safeguards were poor or nonexistent. Military personnel, e.g. maintenance airmen, and civilian contractors who possessed minimal security credentials were granted LCC access, and annually thousands of visitors holding no clearance whatsoever were permitted access to operational LCCs. In the interest of public relations, the Air Force permitted ready access to the Minuteman launch network by practically anyone desiring it.

    Requests for visitor access were routinely processed and approved. The requesting party had only to provide a name and social security number, and authentication checks were not usually made. As a matter of course, checks of individual backgrounds or motives for requesting LCC access were not made either. Furthermore, within wide bounds, the number of individuals in a party was limited only by the capacity of an LCC - about eight persons.

    Once military personnel and civilians are allowed inside an LCC, responsibility for them falls squarely on the shoulders of the on-duty crew members.

  6. The writeup is misleading.... by 33degrees · · Score: 5, Insightful

    According to the article, someone in the chain of command decided that they didn't want this safeguard, and ordered that the password be set to 00000000 and the dials used to enter the password left in that position; in effect, the equivalent of having a blank password so that you don't have to bother entering it.

    The story here, then, is not that a bad password was chosen, but that somebody decided to disobey orders by disabling the password, and that the higherups were completely in the dark about it.

  7. Poor ICBM security ...who cares? Right? by Exocet · · Score: 5, Insightful

    That seems to be the concensus at this point. People have repeatedly pointed out that the *physical* security was VERY VERY STRICT. Just because the password, a deterrant that top-level people thought was VERY VERY necessary was completely missing ...oh, that's fine. They still have keys and ummm other stuff, right?

    RTFA. Blair and Brewer point out that, at the time, the military wanted to improve their public relations and would give TOURS of LCC's! B&B repeatedly point out that virtually anyone who asked could get access! The physical security was crap and the codes weren't in place. IE, any moderately funded and motivated terrorist group could have had a field day if they'd know about this severe weakness.

    "Four individuals (two persons in each of two separate LCCs in the same squadron) acting in concert could succeed in mechanically launching one or more missiles." In seconds. Not minutes or hours.

    "[...] annually thousands of visitors holding no clearance whatsoever were permitted access to operational LCCs."

    "Located in each LCC are two launch keys, one for each member of the crew, and the codes needed to authenticate presidential launch directives. Only the launch keys, not the codes, are physical prerequisites for generating valid launch commands, the purpose of the codes being exclusively that of authenticating an execution directive."

    B&B make it sound as if you happened to be on a tour and decided to overpower the minimal security force (two crew members + a couple of guards at best (isolated locations, remember?) then it's good to go - you already know the launch codes because it's always all zero's. Or, even worse:

    "Technically, crew members can launch a nuclear attack with or without approval from higher authority. Unless PAL or its equivalent forecloses this option, as many as 50 missiles could be illicitly fired. Moreover, unless adequate precautions were instituted, an even more drastic option would be available. Crew members could conspire in the formatting and transmittal of strategic strike directives, deceiving the full contingent of Strategic Air Command (SAC) LCCs, as well as higher authorities, into reacting to a spurious launch directive as if it were valid and authentic. Or they could render the U.S. strategic force virtually impotent by formatting and transmitting messages invalidating the active inventory of presidential execution codes. Finally, crew members could aid accomplices in stealing thermonuclear warheads from missiles on active alert."

    Keep in mind that Blair was working in an LCC as a crew member in the mid-70's. He was obviously in a unique position (which virtually none of us were or are) to write this paper. His direct observation on how to subvert the access/security controls on the ICBM's trump anyone else's estimate on what might or might not happen. His letters and paper in 1977 are basically what got those locks activated in... 1977.

    It is especially hypocritical that the majority of the Slashdot comments were fine with this poor use of a password mechanism. In your own place of business you most likely would NEVER allow this to happen and you just run some servers - as opposed to ICBM's capable turning your city into a big kitty litter box. Don't defend the actions of those in charge in the 60's and 70's. They were flat out wrong and frankly should have been thrown in military prison for such a massive security breach.

    --
    Exocet Industries - Taking over the world, one computer at a
  8. Re:WOPR's 'guesses' by the_mad_poster · · Score: 5, Insightful

    I think a +5, Informative on a joke about posting a root password to the world is as funny as the joke itself. It's like the mods adding to the original joke: "Here everyone, r00t this guy."

    --
    Alito: A vote for Alito is a punch in the eye to put that bitch back in her place!
  9. wlll by Anonymous Coward · · Score: 4, Insightful

    As opposed to, say, 1970's vintage soviet tanks in poor repair, and an army without equipment like boots and uniforms. The condition of the army and its material was, very likely, well known to the Iranians.

    Yes, I'd say WMD, or the threat thereof, would be the only significant weapons you could bring to bear.

    The question is, do you stop to consider facts before you make your arguments? A little less blindly jingoistic support for our president, a little more thought is in order.

  10. Re:Someone's gotta say it by ghostlibrary · · Score: 4, Insightful

    That's why 'man in the loop' is worth keeping. Fully automated systems are not just 'risky', but absolutely totally insane.

    You read about trying to cut people out of the loop to save costs, think about this and just pay the $40k/year salary, for goodness sake.

    --
    A.
  11. MAD - Mutually Assured Destruction by lawpoop · · Score: 4, Insightful
    Yes, the passwords were "000000" and *everyone* knew it. Any joker in the military could launch nucler missles. Everyone knew it.

    Including the Kremlin.

    --
    Computers are useless. They can only give you answers.
    -- Pablo Picasso