Air Force To Rewrite the Rules of the Internet
meridiangod writes "The Air Force is fed up with a seemingly endless barrage of attacks on its computer networks from stealthy adversaries whose motives and even locations are unclear. So now the service is looking to restore its advantage on the virtual battlefield by doing nothing less than the rewriting the 'laws of cyberspace.'" I'm sure that'll work out really well for them.
for an organization the size of the air force, and with the mandate it has, there is nothing laughable or overly ambitious about say, creating and implementing your own supersecure protocol, and supporting it within its subnet
and, if successful, watch it leave its military surroundings, be adapted by universities, then corporations, then the general public
kind of like the internet itself
somebody is going to do this at some point, considering the various shortcomings of our present dominant protocol suite
that it would be the military to do it first makes sense
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
If you actually RTFA, you see that they aren't bonkers. Quite to the contrary. See this quote, for example:
"[M]ost threats should be made irrelevant by eliminating vulnerabilities beforehand by either moving them 'out of band' (i.e., making them technically or physically inaccessible to the adversary), or 'designing them out' completely," the request for proposals adds.
Yeah, absolutely. Remember that this is the military we're talking about. These are the guys who are the "customers" of stuff like the NSA's formally verifiable code project. These are the guys who still use 10 year old computers because those are hardened and tested to military standards. If they upgrade to 5 year old computers, the gain in speed will offset pretty much any performance penalty that security methods that don't fly in the commercial world because of said performance penalties, could cause.
These are also the guys who do a ton of things badly.
So it'll be interesting to watch.
Assorted stuff I do sometimes: Lemuria.org
Sure they can. It just adds a step: get the hardware connected. Sometimes that can be accomplished through social engineering, sometimes well-meaning people do it for you, and sometimes people simply don't realize the connection existed in the first place. Of course, it does make things harder, and it is a valuable step... but it should not, under any circumstances, be assumed to be bulletproof by itself. You still need to worry about security against an attack.
I would expect that all of an ISP's addresses should be in the block(s) they received from ICANN. If something on their sub-net is generating headers with foreign addresses, then they ought not to route it.
I can vouch for that. Left a classified syquest cartridge (yes it was some years ago) out on my desk once and it was noticed within 10 minutes by security. My boss was pretty understanding. He said there wee two types of people, those who had committed security procedure breaches, and those who would do so in the future. Had to go through the training again.
The USAF would like to alter the permissive and decentralized nature of the Internet through technological and possibly political means to suit itself.
I reckon that if any entity tries a large scale centralisation of the "the internet" then the users will simply adapt and decentralize in other ways.
The more surveillance present on the internet the less useful it will be as a way to transmit information anonymously. However with advances in wireless technologies setting up other ways to transmit data is not only possible, but easier and cheaper than ever before. It's not about doing things that are illegal, but rather that to ensure freedom, liberty and justice there needs to be ways of communicating that is not subject to government (or corporate) scrutiny.
Of course that is not what this specific case is about, but I fear that whatever measures they implement (or try to) will carry with it a host of other issues that could inhibit the ability of ordinary citizens to access knowledge or data without being logged in an ever growing database. The phrase "if you are not doing anything illegal you have nothing to worry about" is misleading. Since it does not consider the possibility that what you did today, while not illegal, could be used months, years, decades, down the line when the motivations of those with access to the database changes (or indeed the database falls into the hands of antagonistic person(s)).
The Long Now Foundation
As one who grew up on military bases, I can tell you that you generally aren't going to find too many opportunities to park van with tinted windows and a twenty inch dish antenna in front of buildings. Yes, I'm aware that social engineers can accomplish many things and that given enough motivation and resources, there isn't likely anything that can't be broken into. That being said, what was said about unplugging computers from the net is still a good idea because all too often the problems the military is running into these days don't come from advanced espionage groups with large resource pools and dedicated staff, but rather a bored individual with access to kiddie scripts which is fairly embarrassing to them.
The Air Force has announced similar programs to this in the past with little or no actual outcome. Every now and then they have to come out with another program with a spiffy name to distract us from the fact that they can't keep kids from breaking into their networks.
Not true. While working for the Dept of Defense I saw this scenario played out - it was around 1995.
A van pulled up about a quarter-block away from a BDM building (located on a very public street) but the van was just too suspicious, for reasons I'd rather not elaborate on. Secretaries returning from lunch noticed it and reported it to security. Local police cordoned off the area very, very quickly - almost real-time - coincident with a first-responder team from the local USAF base. Automatic rifles were pointed at the van from three directions, two Ruger AC-556s were layed against the back door, and the solid side of the van was struck with some sort of hammer, and a cry to get the fuck out of the van ensued. Public area, people put rapidly out of harm's way. I recall that from phone report to guy laid out being handcuffed took less than 20 minutes.
And yes, he was a spy, using the latest EM-based eavesdropping equipment. Saw it and heard it. None of this sir, please step out crap.
Maybe a decade later we've learned to coddle suspected spies... no, wait - I saw Harold and Kumar Escape from Guantanamo Bay (sorry, couldn't resist) - I rather doubt it, but then, I could be in error.
Pathological kinda promises Path + Logical - but instead, you get stuck with pathetic.