NSA Wages Cyberwar Against US Armed Forces Teams
Hugh Pickens writes "A team of Army cadets spent four days at West Point last week struggling around the clock to keep a computer network operating while hackers from the National Security Agency tried to infiltrate it with methods that an enemy might use. The NSA made the cadets' task more difficult by planting viruses on some of the equipment, just as real-world hackers have done on millions of computers around the world. The competition was a final exam for computer science and information technology majors, who competed against teams from the Navy, Air Force, Coast Guard and Merchant Marine as well as the Naval Postgraduate Academy and the Air Force Institute of Technology. Ideally, the teams would be allowed to attack other schools' networks while also defending their own but only the NSA, with its arsenal of waivers, loopholes, and special authorizations is allowed to take down a US network. NSA tailored its attacks to be just 'a little too hard for the strongest undergraduate team to deal with, so that we could distinguish the strongest teams from the weaker ones.' The winning West Point team used Linux, instead of relying on proprietary products from big-name companies like Microsoft or Sun Microsystems."
Anyone surprised by the OS choice of the winner? It was going to be either that or BSD.
How bad-ass must one be to withstand concerted hack attempts by the NSA? I'd think that would look really, really impressive on a resume. Especially for someone applying for a .gov job!
NSA tailored its attacks to be just 'a little too hard for the strongest undergraduate team to deal with, so that we could distinguish the strongest teams from the weaker ones.'
Nobody wins, but lets see how long you hold out.
The programmers that contribute to OS projects are pretty adamant about good code, something Microsoft will learn one day.
And yet in practice this statement doesn't hold up because there is plenty of shit code floating around in open source projects.
The fact that the NSA was willing to participate at all strongly suggests to me that the NSA was just playing games, and was not in fact utilizing anywhere near their full capabilities in this exercise. Which says something pretty impressive about the NSA.
"It is possible to commit no errors and still lose. That is not a weakness. That is life." -Peak Performance
When it comes to stories like this, or the one about the Dali Lama's computers being compromised, etc., I'm always surprised that no one considers using OpenBSD as their operating system; it's the only one that I know of that is specifically, purposely built, for security. Because it's Unix, it can still run pretty much everything (though you want to use the OpenBSD version because it's been reviewed for security holes, etc.).
Seriously, if I wanted to keep my battle plans, aircraft designs, etc. out of the hands of the "enemy", I'd lock them up in an OpenBSD server, preferably on some less-common architecture like the Alpha, so that anyone trying to hack my system would have an enormously hard time.
Yes I understand this doesn't take into consideration social networking. So I'd take a page from the elevated privilege playbook and say that in my organization, no one trusts the person below him/her so as secrets can never flow downhill. Going back to the operating system, this would presumably be handled by ACLs.
Of course, no system is immune from the booze-n-hookers style of temptation, but that's someone else's job; I'm just here to install and configure software. :)
More than do the same with Windows
You're talking about bad drivers like its the OS's fault.
The trade-offs of having drivers in userspace outweigh the positives.
They weren't testing the operating systems, they were testing the cadets.
Agreed 100%. While supposedly the country's best & brightest, Cadets truly aren't more than horny 21 year-olds (I was a cadet... trust me I know! ;).
Yes, the NSA could've SMASHED them in minutes. But the bigger concept here is to get the cadets to wrap their brains around the idea of a Pearl Harbor on the US' IT infrastructure & how to protect against it.
Assuming this exercise started this year (it didn't... just saying), we'll start to benefit in ~5 yrs, as these horn-dogs assume senior roles.