Cyber Vulnerabilities Found In Navy's Newest Warship
An anonymous reader writes with some potentially troubling news about some security issues with the Navy's newest class of coastal warships."A Navy team of computer hacking experts found some deficiencies when assigned to try to penetrate the network of the USS Freedom, the lead vessel in the $37 billion Littoral Combat Ship program, said the official, who spoke on condition of anonymity.
The Freedom arrived in Singapore last week for an eight-month stay, which its builder, Lockheed Martin Corp., hopes will stimulate Asian demand for the fast, agile and stealthy ships.
'We do these types of inspections across the fleet to find individual vulnerabilities, as well as fleet-wide trends,' said the official."
"The Freedom arrived in Singapore last week for an eight-month stay, which its builder, Lockheed Martin Corp., hopes will stimulate Asian demand for the fast, agile and stealthy ships"
we paid for it so they can advertise?
USS Yorktown circa 1997
When information is power, privacy is freedom.
Trap!
Think about it. Some official comes out and talks about how vulnerable a ship is that just entered "that" area.
That is like an official coming out and saying that some new Drone over in Iraq that can be taking control over by yelling your name and location into radio ch-4.
I can't imagine spending $37 billion dollars of taxpayers money on anything better for the the taxpayers than some more naval vessels. Why waste it on schools, or roads or infrastructure, when you can have... um, well, some nice new ships for the Navy to sail around in?
A brain is a terrible thing to waste... Mind? That's debatable.
Windows for Warships 2012 now with more touch controls.
To fire swipe the screen.
The software and network vulnerability issues are the least of the problems for this Water Turkey.
The LCS is not expected to be survivable in a hostile combat environment
From the Congressional Research Service: "The LCS is not expected to be survivable in a hostile combat environment as evidenced by the limited shock hardened design and results of full scale testing of representative hull structures completed in December 2006."
"So, we have a warship design that is not expected to fight and survive in the very environment in which it was produced to do so. Poorly-armed, poorly-protected, with an over-abundance of speed that will eat through a fuel supply in half a day."
This New $350 Million Combat Ship Has Nearly Two Equipment Failures For Every Million Bucks
"The Project on Government Oversight (POGO) researches Pentagon weapons procurement and has published its April 23 letter to members of the House Armed Services Committee, who have themselves 'repeatedly questioned the utility and effectiveness of the Littoral Combat Ship program' in the past.... From the time the Navy accepted LCS-1 from Lockheed Martin on September 18, 2008, until the ship went into dry dock in the summer of 2011 - not even 1,000 days later - there were 640 chargeable equipment failures on the ship. On average then, something on the ship failed on two out of every three days."
Hello US Navy! Thanks for accelerating climate-change, while subverting your mission and betraying the tax payer. I guess your next job, at Lockheed or General Dynamics will be worth all the criminal fraud and needless deaths.
"Flyin' in just a sweet place,
Never been known to fail..."
It should give pause to anyone joining the military that our citizens, and our own government would seek to arm the rest of the world, potentially to be used against us. better to stay in school, join the military industrial complex and create the weapons, rather than be paid a pittance and die prematurely on the battlefield. Take a page from our congressional leaders.
The first mistake was to call it the "Littoral Combat Ship", which makes people confused about the intended mission specs. I mean, literally who the hell uses the word "littoral"? "Almighty Almighty, this is Littoral Combat Ship Street Gang. Radio check, over!" Yuck.
They should have called it the "Riparian Combat Ship". Ya, that's the ticket.
I deny that I have not avoided attaining the opposite of that which I do not want.
Dr. Gaius Baltar
Without even a vague idea of what the threat scenarios utilized in this assessment are, there is essentially no information available in the linked story.
Surprising no one.
USS Freedom.
What a name, just like something out of a satirical comic book. Seriously, you 'murricans seem to have a fetish for the word, but the more you use it, the more you seem to forget its actual meaning.
Circumcision is child abuse.
They are buying telecom gear that goes straight to some storage closet and never taken out the box. They have to spend it or lose it, so the telco sales reps are happy, general is happy, and the tax payers are buying crap that have NO legitimate purpose to running our govt. This is in just 1 industry. Can you imagine all the money they're spending on stuff that winds up growing legs, or being sold off as "surplus"?
The Littoral Combat Ship should have been cancelled a long time ago. It was originally supposed to be some cheap, expendable ship that would get up close and personal with enemies. Instead it grew into a big, overpriced ship. If the US Navy wants a good, small military ship. Buy one from Israel. If the US Navy wants a ship with modules, buy a ship from Denmark, the inventor to ships with modules.
The Freedom arrived in Singapore last week for an eight-month stay, which its builder, Lockheed Martin Corp., hopes will stimulate Asian demand for the fast, agile and stealthy ships.
Why is the US Navy deploying a potentially flawed product at the behest of the company it paid to build the damn thing, when the sole reason to do so is that it can sell the same thing to other countries, as marketed by the Navy. WTF? That's either the most clever and expensive trojan horse ever, or one of the best examples of the military industrial complex ever.
That word is so overused, it's lost all meaning - and I don't even know what the meaning was in the first place any more.
What the hell does that even mean? Perhaps you mean software vulnerabilities?
And each time you fire something, pay a fee to Apple, as they have a patent swiping.
Initiate Machine Gun Rage!
A "cybersecurity vulnerability" discovered by these teams could cover a wide spectrum of possibilities - their reports will cite everything from a single client with an out-of-date virus definition file to weak password enforcement to unprotected Windows shares on their domain controllers. While there are no doubt a plethora of security issues across this and every other ship, what should be more concerning is that these so-called "team[s] of computer hacking experts" are comprised of people who are not adequately trained or experienced, and whose expertise is usually limited to things like knowing how to update a video driver or install a minecraft mod.
I asked one of these teams of 1337 4aX0rz how they went about looking for vulnerabilities, and their answer amounted to collecting executables and running a handful of virus scanners on them. When I asked how they verify the network routing tables with the hardware connected to the network, the said they didn't. When I asked them how they check for rootkits I got blank stares in response. Eventually one of them chimed in and asked, "What's a rootkit?"
It looks like you're trying to return fire. Would you like help with this?
0 find hostile ships in the area using cloud services (recommended)
0 check online help for rules of engagement.
0 I don't need help. I can return fire by myself.
---
ECHELON is a government program to find words like bomb, jihad, plutonium, assassinate, and anarchy.
Rhymes with a female body part !! Though last I heard, clitoris does not rhyme with Deloris !!
There is little difference in design philosphy between a WWII Fletcher class destroyer and the Freedom class Littoral Combat Ship. Fast, shallow draft, thin skinned. Just because they aren't currently bristling with armament doesn't mean they can't be up armed. One of the major design considerations for the LCS class is its "plug-and-shoot" architecture. From what I've seen of the design it wouldn't be hard to up gun the Freedom class LCS with 3 5"/62 guns. That would give the LCS about as much firepower as a WWII heavy cruiser. The new generation of 5" gun is really_freaking_deadly.
The LCS has a couple of design advantages over its WWII predicessor: it has a wider beam and is therefore a better weapons platform and it has aviation capability. As in supersonic stealth in-your-face F35 aviation capability.
I dunno, LCS looks ok to me.
Just some littoral stimulation for Asia. Haha.
Are they any different from regular vulnerabilities?
Client software shouldn't be able to bring down an O/S. Never mind an entire network.
It didn't. The network did not go down. LAN consoles crashed.
The "Littoral Combat Ships" are "targets" not "ships"
We used to call things this small and vulnerable "boats" but now that most of our tax dollars go to paying interest on the debt and paying geezers to nap in their recliners, the Navy needs to prepare for a smaller and smaller future... I see rowboats ahead...
I haven't read the article but I'll wager that they're using Windows. I remember an article posted here about ten years ago that reported on a Navy ship that was being run completely using Windows NT 4.0. It's kind of strange to depend upon such a wonky piece of software. But today with everything being so interconnected, using Windows today would seem to be a bad gamble. But then it might be interesting. When it was demonstrated that voting machines were using Windows it was seen to be an opportunity to figure out who the hackers wanted to be president. Now it can even more interesting given the state of cyberwarfare. Not only can we learn who the Chinese want to be president, we can learn who they want to have the Americans destroy.
It's really quite a simple choice: Life, Death, or Los Angeles.
Cyber cyber..cyber....cyber.cybercyber..cybercybercyber... siber syberrrrrrr cibrasrdasnmb.. compewter hakka esperts..
I'm sorry - I don't care.
Just roll out Microsoft - it will be che-*snigger*-per.. pwahaha. You think 150 brazillion dollars would buy you a decent rig.. Old guys with cigars.
Memory-Safe languages could eliminate about 50% of exploits in the CVE database. This can be done while retaining most of the high-performance/high-efficiency features of C and C++ such as
+ synchronous Destructors, no GC required, at least soft-realtime capable
+ stack alloaction of almost everything
+ object aggreation without pointers (class A contains and instance of class B, which contains an instance of class C, etc)
+ value arrays as opposed to arrays of references, which have something like 24 byte overhead per entry
Here's an invention of mine, which delivers all of the above, plus memory safety even in case of multithreading:
http://sourceforge.net/p/sappeurcompiler/code-0/HEAD/tree/trunk/doc/SAPPEUR.pdf?format=raw
http://sourceforge.net/p/sappeurcompiler/code-0/HEAD/tree/trunk
And yeah, it is not a silver-bullet which will magically eliminate all security and reliability issues. But I consider it major progress if you can eliminate 50% of the exploit potential.
It will probably corrode before it's hacked. They actually designed an ocean-going war vessel _without_ a cathodic corrosion protection system. I think they tacked one on later when real Navy men found out, but it's a damning insight into how this ship was 'designed' in the first place.
or does naming ships like "Freedom" sound a bit too dystopic.
Also perhaps I am the only one that thinks it is funny that eventually someone is going to get killed by Freedom... It is a Warship after all.
"Today Freedom killed thousands of people, truly a great day for Freedom!" LOL
gosgog:
I find it absolutely apalling that a U.S. Military Vehicle is based on utilizing MSN at all! Every Hacker in the world can attack and disable this crap with Viruses, Trojanhorses etc!
But then what can we expect from a Gov't that allows the CIA, continually to provide Hamid Kharzai in Afghanistan, suitcases full of U.S. Dollars to feed corruption, war lords & the Taliban! Then turn around and talk SEQUESTRATION and fuck with the SOCIAL SECURITY SYSTEM for money!!!