Slashdot Mirror


Britain's Newest Warship Runs Windows XP, Raising Cyber Attack Fears (telegraph.co.uk)

Chrisq shares a report from The Telegraph: Fears have been raised that Britain's largest ever warship could be vulnerable to cyber attacks after it emerged it appears to be running the outdated Microsoft Windows XP. A defense source told The telegraph that some of the on-board hardware and software "would have been good in 2004" when the carrier was designed, "but now seems rather antiquated." However, he added that HMS Queen Elizabeth is due to be given a computer refit within a decade. And senior officers said they will have cyber specialists on board to defend the carrier from such attacks.

302 comments

  1. Makes sense to me by alvinrod · · Score: 5, Funny

    It makes sense to me. Where else are they going to get minesweeper?

    1. Re:Makes sense to me by Anonymous Coward · · Score: 0

      I spent 20 big, To have one custom made. Crashes half of the time, They want another 10 big to fix it,

    2. Re:Makes sense to me by ArmoredDragon · · Score: 2

      This is what you call a big floating disaster.

    3. Re: Makes sense to me by Anonymous Coward · · Score: 0

      So short it needs a ramp for a runway...

    4. Re:Makes sense to me by Anonymous Coward · · Score: 0

      there's an app* for that

      *with in-app purchases

    5. Re: Makes sense to me by dougdonovan · · Score: 1

      im sure the sysadmins are just thrilled to not work with cutting edge tech but hey, the money is good...

    6. Re: Makes sense to me by Deadstick · · Score: 1

      ...and US carriers are so short they need a catapult.

    7. Re: Makes sense to me by currently_awake · · Score: 1

      Given the British carriers won't have catapults, your comment makes no sense. On the bright side, the F35 won't be combat ready before 2025 (when this carrier goes into refit for modernization) so everything is good.

    8. Re: Makes sense to me by Talderas · · Score: 1

      This is not uncommon? It's also addressing an issue for modern planes, which is takeoff speed.

      We've progressed from...

      1. Turning the carrier into the wind and adding the ship's speed.
      2. Catapult systems.
      3. Ski-jumps.

      Each of these designs serves a purpose to either increase the speed of the aircraft, and thus lift, or effectively increase the length of the runway for takeoff. In this case the runway is the distance the plane covers before it crashes into the sea. Watch footage and you will find it common for planes to "fall" off the end of the aircraft carrier before coming back up. A ski jump is a practical method to increase the effective distance the plane has to obtain the required speed/lift because the other method of doing so is constructing even larger hulls and longer flight decks all of which has a cost associated with it that is much higher than a ski jump.

      --
      "Lack of speed can be overcome. In the worst case by patience." --Znork
    9. Re: Makes sense to me by Deadstick · · Score: 1

      I don't think you got the point of that. The Elizabeth doesn't have a ramp because it's short: it's short because the Brits -- for better or for worse -- have adopted a different concept of carrier flight ops that doesn't need as long a deck as the US carriers.

      If the F-35 doesn't work out...well, they're fucked.

    10. Re: Makes sense to me by Anonymous Coward · · Score: 0

      Actually it's because US carriers routinely fly larger planes with heavier loadouts. Most of these planes can't use a skijump because their landing gear can't take the stress at combat loads.

    11. Re: Makes sense to me by Anonymous Coward · · Score: 0

      We still turn into the wind for takeoff. Catapults still have advantages in allowed takeoff weight. That is one of the reasons the US stuck with them for the next carrier class.

  2. Cyber specialists by manu0601 · · Score: 5, Insightful

    they will have cyber specialists on board to defend the carrier from such attacks

    They are supposed to defend unsupported proprietary software. The right name is not cyber specialist, but rather priest.

    1. Re:Cyber specialists by Anonymous Coward · · Score: 1

      Cyber priest?

    2. Re:Cyber specialists by Anonymous Coward · · Score: 0

      funniest thing that I have heard this morning.... the weapons onboard might as well be *gigantic* crossbows.!

    3. Re:Cyber specialists by NotInHere · · Score: 4, Interesting

      This is the most ridiculous part of the whole story. They think that some people at the board of the carrier can fend off attacks. They believe that it can be solved by like a local scale problem, like aircraft attacking the carrier. So they think they can solve it by people on board specialized to protect you, like they probably have someone on board to operate the anti aircraft cannon.

      These attacks aren't local scale though. They are global scale. Vulnerabilities in Windows XP get discovered by someone at the other side of the globe and get used against you. Similarly, a patch to fix a vulnerability in Windows XP can be developed once and then applied locally. And in the case of a total and complete hack during the heat of a battle, even the best team on board won't help them to get the systems back up before the battle finishes.

    4. Re:Cyber specialists by Gravis+Zero · · Score: 4, Funny

      The right name is not cyber specialist, but rather priest.

      Oh please, don't be an idiot. The government isn't dumb enough to rely on just some priest. For the money they are paying out, they are going to at least demand a cyber priest. ;)

      --
      Anons need not reply. Questions end with a question mark.
    5. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Maybe. I could administer a win xp box that I worked next to all day. Sure it wouldn't have direct Internet access, etc.

      The summary sounds dumb but it might be logical (although obviously more logical to change the OS)

    6. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Maybe they do have the source code to XP.

      I don't think it's out of the questions for governments to demand source code access to the operating systems they are using (especially for military installations).

    7. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Yeah because all computers on Royal Navy ships are connected directly to the internet through BTInternet and Gramps is at the keyboard downloading that ParisHiltonNaked.exe attachment from an email his bestest buddy sent him. Yup, that exactly how it works.

      How fucking stupid are you people?

    8. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Tell us all how you know from a movie that it doesn't :3

      Seriously.
      Go on.

      Yeah there are standards. There are also edge cases. The fact you don't hear about compromises certainly doesn't mean they don't happen.

    9. Re: Cyber specialists by LostMyBeaver · · Score: 3, Interesting

      The systems are very likely DoD (or at least) connected for remote maintenance. There will be a minimum of 3 encryption black boxes before satellite uplink.

      Switching OS is nice. But the US government pays for Windows XP support and updates.

      I'm far more concerned about software which actually requires XP. The entire ship should be running NSA Secure Host Baseline (https://github.com/iadgov/secure-host-baseline).

    10. Re:Cyber specialists by manu0601 · · Score: 1

      Maybe they do have the source code to XP.

      Even if they do, imagine you discover during the battle that your systems are crippled by a specialized malware. Do you have time to identify the flaws used for infection, fix them, rebuild and redeploy the OS? I bet you will be drowning before you have completed malware analysis.

    11. Re: Cyber specialists by Anonymous Coward · · Score: 3, Insightful

      The systems are very likely DoD (or at least) connected for remote maintenance. There will be a minimum of 3 encryption black boxes before satellite uplink. Switching OS is nice. But the US government pays for Windows XP support and updates. I'm far more concerned about software which actually requires XP. The entire ship should be running NSA Secure Host Baseline (https://github.com/iadgov/secure-host-baseline).

      Why would we want the Americans to control the software?
      Did you read the article? Do you think we trust your president?

    12. Re: Cyber specialists by manu0601 · · Score: 2

      Switching OS is nice. But the US government pays for Windows XP support and updates.

      If I recall correctly, they did it once but not nowadays.

      And even if you have support and updates, a general purpose OS such as Windows has a huge surface attack.

    13. Re: Cyber specialists by fustakrakich · · Score: 2

      There will be a minimum of 3 encryption black boxes before satellite uplink.

      Hmm, ROT39... Excellent...

      --
      “He’s not deformed, he’s just drunk!”
    14. Re:Cyber specialists by Anonymous Coward · · Score: 0

      ~~~One day soon~~~

      Cyber specialist: Our firewalls are at 15% and falling captain!
      Captain: Redirect all power to firewalls! Flood intertubes 3 and 4 with youtube traffic!

    15. Re:Cyber specialists by Darinbob · · Score: 3, Insightful

      It's outright scary that they would consider using a Windows of any version. Can you see them on Windows 10 and just as they engage with the enemy all the computer screens say "Restarting to Install Advertising Update. Please Do Not Power Off Your Computer."

    16. Re:Cyber specialists by gravewax · · Score: 0

      This is a warship, they generally don't have internet connectivity to critical systems and any attacks would have to be performed locally. while I am sure what happens with vulnerabilities needs to be monitored an isolated system regardless of OS can be defended locally by decently knowledgeable individuals without too much effort.

    17. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Let's hope they don't have WiFi or easily accessible ethernet ports, because if they do, it will only be a matter of time until those PCs are compromised.

    18. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Yeah, seriously!

      Physical access control takes care of nearly all of the problems. Baking the software load into a ROM (and using computers and attached hardware without any EEPROMs) so that it's not possible to design an attack that remains resident in the system takes care of the rest.

    19. Re:Cyber specialists by Jamu · · Score: 3, Insightful

      I'm sure you're mistaken, Michael Fallon, Conservative MP, drunk driver, and graduate in Classics and Ancient History, says they're properly protected.

      --
      Who ordered that?
    20. Re:Cyber specialists by Anonymous Coward · · Score: 0

      The local defender probably can. All he has to do is make sure it doesn't talk to any other computers.

    21. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Amen.

    22. Re:Cyber specialists by Anonymous Coward · · Score: 0

      "Classics" and "Ancient History" is where WinXP belongs. It needs to be conserved by a conservative, alcohol is
      good for conserving biological specimens, like old conservative MP's, why not WinXP.
       

    23. Re:Cyber specialists by deek · · Score: 4, Funny

      They need someone there to change the lightbulb to red, whilst a cyberattack is in progress.

    24. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Sorry to disappoint you but it is actually an EDE stack, not an EEE stack. That way only 2 ASICs of each type are required, not six.

    25. Re:Cyber specialists by Anonymous Coward · · Score: 0

      No less than a cyber bishop.

    26. Re:Cyber specialists by SvnLyrBrto · · Score: 2

      Nah. You just have Clippy do it all for you; digital assistants finally being en vogue and all.

      --
      Imagine all the people...
    27. Re: Cyber specialists by Anonymous Coward · · Score: 1

      Given how you guys handled the Falklands /Exocet missle thing, I'd say letting another nation able to electronically dick with your stuff is a bad idea I'd even when your on the best of terms.

    28. Re:Cyber specialists by Anonymous Coward · · Score: 0

      The last time I installed window xp, it took literailly 8 hours, due tothe amount of reboots that are nessesarry for all the updates that are needed.

    29. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Yes!

    30. Re:Cyber specialists by Xest · · Score: 4, Informative

      They don't just take an off the shelf copy of Windows XP and install it on the ship, companies like BAE systems have agreements with Microsoft over source code access and provide hardened versions to their customers.

      Thus, the unsupported and proprietary elements of consumer Windows XP are entirely irrelevant - they both pay for bespoke extended support from Microsoft, and they have source code access themselves.

      Whilst there are legitimate questions about using Windows XP for a brand new ship, it's not quite as bad as "OMG they use Windows XP lol" type headlines and comments make out. The reality is that they have support for and source code access to perhaps the single most tried and tested OS in the world. Lines of communication and inputs into the systems are both limited and restricted, and thus any vulnerability discovered against XP in the real world will likely be fixed and patched on a ship well before anyone can find a way of getting the exploit onto the ship's systems.

    31. Re:Cyber specialists by SigNuZX728 · · Score: 2

      What makes you think it's unsupported? Microsoft still supports XP if you pay for it.

    32. Re:Cyber specialists by Anonymous Coward · · Score: 0

      This, from the Book of Schneier (chapter 10010, verse 00101):

      People don't understand computers. Computers are magical boxes that do things. People believe what computers tell them.

      Yours,

      Brother Port Scanner

    33. Re:Cyber specialists by Anonymous Coward · · Score: 0

      LOL, marvellous rationalization sir! "Classics" and "Ancient History" is where WinXP belongs - I go to work with a smile.

    34. Re:Cyber specialists by aberglas · · Score: 5, Informative

      Tell that to the Iranians.

      Their centrifuges were not attached to the Internet. Physical security. But Stuxnet got them anyway.

    35. Re: Cyber specialists by Anonymous Coward · · Score: 0

      The US was also replacing Windows with Linux on warships too.

    36. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Yes they do.

      It is how they exchange e-mail with family. Then there is the virus transferred via baby pictures.

    37. Re:Cyber specialists by Anonymous Coward · · Score: 0

      "tried and tested"

      and found lacking in capability and security every day.

    38. Re:Cyber specialists by Anonymous Coward · · Score: 0

      > But Stuxnet got them anyway.

      Through a failure of both their physical and electronic security!

      You prevent Stuxnet by signing any new software load that gets put into your system and verifying that signature before installing it.

      You further bolster your physical security by -as I mentioned above- putting both your software and data into ROM, so that any attack can't be made persistent. This makes upgrades and updates a pain, but we're talking about control systems for A GODDAMN WARSHIP.

    39. Re:Cyber specialists by Anonymous Coward · · Score: 0

      It's outright scary that they would consider using a Windows of any version. Can you see them on Windows 10 and just as they engage with the enemy all the computer screens say "Restarting to Install Advertising Update. Please Do Not Power Off Your Computer."

      Would be funnier if it was something a windows PC actually says.

    40. Re: Cyber specialists by dwywit · · Score: 2

      Eh, who won the Falklands conflict?

      --
      They sentenced me to twenty years of boredom
    41. Re:Cyber specialists by Opportunist · · Score: 1

      I think the correct term is Tech Priest.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    42. Re:Cyber specialists by TheRaven64 · · Score: 1

      They do, but not the build environment, and their license does not permit them to compile it.

      --
      I am TheRaven on Soylent News
    43. Re: Cyber specialists by Opportunist · · Score: 1
      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    44. Re:Cyber specialists by TheRaven64 · · Score: 1

      Indeed. It didn't make sense in 2004, because the EOL for Windows XP was known to be far closer than the expected lifetime of the ship. Would they buy guns or an engine for the ship where the vendor announced that they'll stop making compatible spare parts in under a decade? Off-the-shelf consumer software is entirely inappropriate for this kind of deployment. If the vendor won't give you a support contract for 20 years, it's completely inappropriate (after 20 years, you probably want to do a refit, so can replace the software).

      --
      I am TheRaven on Soylent News
    45. Re:Cyber specialists by Opportunist · · Score: 1

      Amen.

      I mean, Enter.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    46. Re: Cyber specialists by dwywit · · Score: 2

      "general purpose OS" - that's the nub of the issue. Why, in a multi-billion pound/dollar project would you not have your own OS?

      Even a cut-down, customised version of Windows has to be better than XP+Norton antivirus (or whatever has been used). MS can do this, remember the original XBox? Wasn't it supposed to be running a cut-down version of W2K?

      "Hey, Microsoft, we need a custom version of Windows. It needs printing, networking, {list of needs}, and it doesn't need {list of components that provide attack vectors}. It needs to run on business-grade and mil-spec hardware. How much?"

      also:

      "Hey RedHat, we need a customised OS. It needs {list} and it doesn't need {list}. It needs to run on business-grade and mil-spec hardware. We'll talk to (vendor) about drivers. How much?"

      I realise that's a simplistic view, but what are the priorities for the UK govt? Is it worth pursuing a custom solution, or do they accept the risk of a consumer-grade OS + layered-on security?

      --
      They sentenced me to twenty years of boredom
    47. Re:Cyber specialists by Anonymous Coward · · Score: 0

      I prefer the term Electric Monk

    48. Re: Cyber specialists by Anonymous Coward · · Score: 0

      UK has it's own linux. It's called Ubuntu.

    49. Re:Cyber specialists by CSMoran · · Score: 2

      Tech evangelist.

      --
      Every end has half a stick.
    50. Re:Cyber specialists by Anonymous Coward · · Score: 0

      All praise the omnissiah! The great machine spirit of this vessel must be appeased, bring the ether of purification and the wires of jaytag.

    51. Re:Cyber specialists by Anonymous Coward · · Score: 0

      > They are supposed to defend unsupported proprietary software

      They'd likely have at least two more years of support.

      "Windows Embedded Standard 2009. This product is an updated release of the toolkit and componentized version of Windows XP. It was originally released in 2008; and Extended Support will end on Jan. 8, 2019."

    52. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Along with additional help from the United States.

    53. Re:Cyber specialists by AmiMoJo · · Score: 1

      I wonder if the NSA has helped them to patch all the zero day vulnerabilities that they are keeping secret. Hardening only goes so far if there are unknown exploits on an OS that lack defence in depth.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    54. Re: Cyber specialists by jeremyp · · Score: 1

      Always make sure you have an odd number of black boxes then.

      --
      All I want is a secure system where it's easy to do anything I want. Is that too much to ask ~~ Randall Munroe
    55. Re:Cyber specialists by Big+Hairy+Ian · · Score: 1

      Cyber priest?

      I'm sure there are priests who cyber

      --

      Build a Man a Fire, and He'll Be Warm for a Day. Set a Man on Fire, and He'll Be Warm for the Rest of His Life.

    56. Re:Cyber specialists by Anonymous Coward · · Score: 0

      They need someone there to change the lightbulb to red, whilst a cyberattack is in progress.

      I don't know the details. There are some systems though that can run with older OS's forever. Just don't connect them to the internet or ever use untrusted media with them, which generally means don't use media at all unless you need to reload the OS.

      Seriously, if the system is important enough and can be left off the internet, then that is a good thing... I'd rather have an older OS operated only by trusted workers who are trained not to plug usb sticks into ports (that are already disabled), than a newer OS connected to the internet and where any idiot can plug in random usb sticks.

      I am reminded of I think it was Jared Kushner's whining about the military using 8" floppy disks for our weapons. Those are fine. They do the exact same job now that they did originally. They are fully isolated systems and I could care less about the costs associated with producing more every now and then. I doubt people could even easily get hold of 8" floppy disks and the real security is physical. I for one don't want our nuclear weapons networked such that one unstable president could just press a button.... We know they have a certified system that if they maintain it will continue to work just as delivered, and that is all it ever required.

      I could just see the SNL sketch where Trump gets all the nuclear weapons updated to use windows 10, where he pays a guy to rig them so he could launch them all with twitter. Ridiculous... sure. Possible, yes...

    57. Re:Cyber specialists by houghi · · Score: 1

      "likely be fixed". So can you put a number on that? 100:1 or 10.000.000:1 or even more? You are looking at the number on the left. I look at the number on the right : 1. That is all there is needed.
      And how do all these updates work with the unfound 0 day things that are being found?

      XP is unsafe by design. You should not start with an unsafe system and then make it safe when a safe system is available.

      Also: an update within the next decade? That means 15-25 years if at all. They should design it where they can update more often and sooner.

      --
      Don't fight for your country, if your country does not fight for you.
    58. Re:Cyber specialists by StormReaver · · Score: 1

      Lines of communication and inputs into the systems are both limited and restricted, and thus any vulnerability discovered against XP in the real world will likely be fixed and patched on a ship well before anyone can find a way of getting the exploit onto the ship's systems.

      And all it takes is one person plugging a flash drive into ANY Windows computer on the ship to compromise the entire vessel. Windows is unique in the vast scale of its ability to contract malware. It's so-called security has more holes than any other major operating system ever made.

      Remember the Yorktown, and learn your lesson about Windows. This is stupid beyond belief, and everyone involved in approving Windows on Warships(R) needs to be fired and never allowed near a military plan ever again.

    59. Re: Cyber specialists by DarthVain · · Score: 1

      Agreed, I'd guess that warship systems are pretty isolated, and what links they do have would be highly protected.

      Also I have to think if another warship had to get within Wifi range to launch a "cyber attack", they would probably be in a world of hurt from say a normal attack.

      That said, while I don't think it would be all that effective or reasonable, I suppose a sub could sneak right under the warship and perhaps be close enough to hack systems. Though I don't know how Wifi really behaves through water (that would be a neat piece of trivia), and anyway if they were that close they could do far worse likely with a conventional attack anyway so why bother with the cyber attack. It would make for a great prank in peace time naval exercises, where the sub does exactly that, and launches a virus that populates all the monitors with a smiley face and a "Got You!" message. Would make for a good movie scene at least.

      One vulnerability would be if they had a saboteur on board that could physically access VIA panel or USB or something. Probably only reasonable in movies.

    60. Re:Cyber specialists by DarthVain · · Score: 1

      Unless the opposing ship blasts them with infected USB drives that is unlikely to happen.

      Though that wouldn't stop some dummy on shore leave picking up a brothel USB, and plugging it in somewhere he shouldn't... That said, some simple physical limitations (i.e. no USB ports etc...) would pretty much prevent that from happening (which is likely the case, or if there are USB connects they are in a physically protected place with limited access).

    61. Re: Cyber specialists by Anonymous Coward · · Score: 0

      it is enough to install sp3 and the corporate network is always a hole there

    62. Re: Cyber specialists by DarthVain · · Score: 1

      On further thought as the the unreasonableness of the sub idea, if enough walls and such can block wifi within my house, I'd imagine a ships HULL might not be a great medium to get through, though I suppose they could launch a buoy or something... Anyway would make for a good movie scene if you can suspend some of those thoughts for awhile.

    63. Re:Cyber specialists by Anonymous Coward · · Score: 0

      With some experience and levels the cyber priest will have an option to change class to Tech-Priest to appease the Omnissiah.

    64. Re:Cyber specialists by Anonymous Coward · · Score: 0

      This is Britain we are talking about. Cyber warlocks, witches, shamans and druids is what they are really after. Cyber shaman has a nice ring to, doesn't it?

    65. Re: Cyber specialists by Wulf2k · · Score: 1

      While I'm sure it's still a ridiculous idea, people can get wifi to extend for miles with homemade antennas.

      "IF" wifi on a carrier were a vulnerable target, I'm sure somebody with a military budget could target their wifi from safety.

    66. Re: Cyber specialists by Wulf2k · · Score: 1

      Since you posted twice, I get to as well.

      As a potential attack source, do a "message in a bottle" type thing. Toss a Raspberry Pi in a flotation device with a battery, have it perform automated attacks when it detects a wifi signal. Float 30 of them in the general direction of a naval group and wait a few days.

    67. Re:Cyber specialists by Xest · · Score: 1

      Why for one moment would you assume that a warship system even has a USB drive? you realise they don't just go down to their local PC World/Best Buy and just pick up a Packard Bell and plug it in in some corner of the warship and install "Tomahawk Launch Command for Windows 3.0" that they download from cnet right?

      This is precisely the problem with Slashdot couch commentary, it's so unbelievably naive about things that it results in the most absurdly stupid and nonsensical comments such as those you made here. You have no idea about the design of warship computer systems yet here you are pretending to be a guru, it's farcical.

    68. Re:Cyber specialists by Actually,+I+do+RTFA · · Score: 1

      They think that some people at the board of the carrier can fend off attacks... these attacks aren't local scale though.

      P>Of course they are. The main systems aren't on the fucking internet. A Marine with a gun can stop untrusted people from attacking the system. And if you have enough redundancy in access, or trusted enough people, etc, than of course you can secure a system.

      My Win 98 machine is perfectly secure. It has no access to the internet, and I don't load new software (it only exists to run some legacy code).

      --
      Your ad here. Ask me how!
    69. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Bullshit. We deal with these same crappy off-the-shelf
      'hardened' versions of old operating systems from these same vendors, including BAE, every day. In no way are they bespoke or secure. Exhibits A - Z are the global ransomware attacks that have impacted XP over the last month, many of the infected devices are running PLCs and are not directly connected to the Internet.

    70. Re:Cyber specialists by Anonymous Coward · · Score: 0

      They don't just take an off the shelf copy of Windows XP and install it on the ship, companies like BAE systems have agreements with Microsoft over source code access and provide hardened versions to their customers.

      Sooo...... MicroSoft knowingly provides an insecure OS to consumers? Cause that's my take away here. MicroSoft 'can' make a secure OS, but instead deliberately chooses to sell an insecure OS to consumers.

      Or maybe their 'hardened version' isn't any more secure after all.

    71. Re:Cyber specialists by NicknameUnavailable · · Score: 0

      They are supposed to defend unsupported proprietary software. The right name is not cyber specialist, but rather priest.

      I'm not sure if it applies to the filthy Brits or not, but the DoD versions of Windows are significantly more secure than the civilian versions - in fact the DoD Win2K is likely still secure. MS creates separate defense versions with people in the DoD overseeing a good chunk of the security audits, so chances are anything they have access to for backdoors is already patched in their systems and MS's rolling vulnerabilities (the reason each new security patch "seems to" open a new backdoor when it fixes something) don't apply like they do with civilian copies of Windows.

    72. Re: Cyber specialists by NicknameUnavailable · · Score: 0

      Why would we want the Americans to control the software? Did you read the article? Do you think we trust your president?

      It's America's internet too, get over it or get off, filthy Brit.

    73. Re:Cyber specialists by Anonymous Coward · · Score: 0

      Techno-mage

    74. Re:Cyber specialists by painandgreed · · Score: 1

      I think the correct term is Tech Priest.

      Tech Priest of the Adeptus Mechanicus under the command of The Fabricator-General who must communicate with the machine sprits and appease them.

    75. Re:Cyber specialists by Headw1nd · · Score: 1

      Are we living the Foundation series?

    76. Re:Cyber specialists by Darinbob · · Score: 1

      Of course, this is not consumer XP, I suspect there's a way to get extended support if you can afford it. Probably real support, meaning you can call up microsoft, unlike those of us where "support" means they will never talk to us or work on any of our unique problems (sort of as if Ford's support meant that they'll broken starter motor in 2018).

      Also this is embedded XP in most cases. No one controls a ship off of a desktop sitting in the captain's office. Not all of these systems are on a network either, and if they're air-gapped then they're no less secure today than they were a decade ago.

    77. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Ubuntu is an afro word for "can't make Debian work".

    78. Re: Cyber specialists by Anonymous Coward · · Score: 0

      It's unlikely that an attack during combat would be effective. Attackers often need to probe the target systems and understand what to attack before long before they can execute. Unlikely that this would happen in the timeframe of a battle. More likely an attack would simply reduced the combat rediness of the ship.

    79. Re: Cyber specialists by Anonymous Coward · · Score: 0

      "Windows Embedded Standard"; Commercially supported by MS til 2020. Is EXACTLY that - a stripped down XP kernel and low level system "modules" like SMB or Explorer or WMI you can mix and match for your platform. Nothing more, nothing less.

      This is a total non-story. But the kernel string says 'NT5.1' so the sky is falling!

    80. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Specialized malware requires intimate understanding of how the ships systems interact with each other and XP. If the enemy has this then the OS version hardly matters.

    81. Re:Cyber specialists by purple_cobra · · Score: 1

      He's the same tool that thinks the UK should a) bomb foreign hackers (because they wouldn't obfuscate their location, of course) and b) the UK would authorise the first use of nuclear weapons in a war (thereby running counter to every other government the UK has had with nuclear capability). This disingenuous sack of shit is spouting this tripe in a poor attempt to smear the Labour Party as being dangerous on national security. How many terrorist attacks did our existing Trident fleet stop? I believe that would be none. The likelihood of a war in which Trident activation would be "warranted" is pretty slim, mostly because it wouldn't be profitable. There's far more profit in pissant skirmishes against terrorist groups you fund yourself, after all; that way you can sell arms to both sides.

      To ensure our safety - inasmuch as that's possible - try funnelling 10% of the initial cost of replacing Trident to the armed forces, then spend some of the remainder on the emergency services and education; that would be a great deal more effective in protecting national security than replacing 4 nuclear submarines that would only be of use once the UK is a radioactive wasteland. People checking passports/criminal records can't be used as a weapon against the opposition though, can they? Never mind that it's as much use as a weapon as a flaccid penis; he has to give it a go because the Conservatives tanked at the last election and are continuing to nosedive.

      I am hoping against hope that enough people have finally woken up to the fact that the Conservatives couldn't care less about you if you aren't wealthy; any small crumbs thrown at you are solely to bribe you for your vote, a vote that will allow them to continue cutting taxes for their donors and their families.

    82. Re:Cyber specialists by TheRaven64 · · Score: 1

      Of course, this is not consumer XP, I suspect there's a way to get extended support if you can afford it.

      The UK government was paying (a huge amount) for that, but Microsoft would only offer it for one year and it's expired.

      --
      I am TheRaven on Soylent News
    83. Re:Cyber specialists by Sir+Holo · · Score: 1

      They think that some people at the board of the carrier can fend off attacks... these attacks aren't local scale though.

      P>Of course they are. The main systems aren't on the fucking internet. A Marine with a gun can stop untrusted people from attacking the system. And if you have enough redundancy in access, or trusted enough people, etc, than of course you can secure a system.

      My Win 98 machine is perfectly secure. It has no access to the internet, and I don't load new software (it only exists to run some legacy code).

      Likewise. Except I do need to install software occasionally. It must be a trusted source. I will download it on the MacOS side; copy it over; and install. XP is otherwise completely sand-boxed from my system AND from the internet.

      I do not dual boot, but use it virtualized. My Win 8.1. . . I will dual boot into that, but only for games.

    84. Re:Cyber specialists by aberglas · · Score: 1

      Nope. Not how Stuxnet happened. Wikipedia is your friend.

    85. Re:Cyber specialists by gravewax · · Score: 1

      no they don't. systems that allow family to exchange email and talk are not connected to the control systems of the ship. They are on a completely separate network

    86. Re: Cyber specialists by Anonymous Coward · · Score: 0

      Are you describing Windows XP Embedded?

    87. Re:Cyber specialists by Anonymous Coward · · Score: 0

      What makes you think it's unsupported? Microsoft still supports XP if you pay for it.

      OR do the registry hack. Been getting updates for years.

  3. why windows? by Anonymous Coward · · Score: 0

    are missiles plug and play with no *nix drivers or something?

    1. Re:Why Windows? by AHuxley · · Score: 1

      So new staff feel ok using the GUI.

      --
      Domestic spying is now "Benign Information Gathering"
    2. Re:Why Windows? by toadlife · · Score: 1

      Because it's cheaper to implement than the alternatives you listed and whatever security shortcomings it might have don't matter if they are properly isolated systems.

      --
      I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
    3. Re:Why Windows? by Opportunist · · Score: 1

      It doesn't matter if they never go to war with it, you mean?

      Because that's basically the game BAE is in. Making weapon system that are peace-compatible. Not really battle worthy, but also not as expensive as they'd have to be to be battle-worthy.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:Why Windows? by toadlife · · Score: 1

      Your assertion is completely baseless and reeks of FUD - the same thing GNU/Linux apologists like yourself have slammed Microsoft for for decades.

      Why exactly are they not battle worthy for using some flavor of NT on some of their ships systems? Do have some inside knowledge of the design to share with everyone that would back up your assertion?

      I don;t know much about the British, but I know for a fact that Microsoft products are used extensively in battlefield situations by the U.S. military. I've worked with a Sergeant in the U.S. Army who did two tours in Iraq and worked with Windows based systems. Windows was the least of his problems on the battlefield.

      If you would like an example of Linux-based system being battle-tested, here you go:

      https://www.theinquirer.net/in...

      --
      I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
  4. on-boar by Anonymous Coward · · Score: 0

    There are wild pigs on the warship too?

    1. Re:on-boar by blindseer · · Score: 2

      Yes, the Royal Marines like their meat fresh.

      --
      I am armed because I am free. I am free because I am armed.
    2. Re:on-boar by Anonymous Coward · · Score: 0

      Pork-Barrel Politics. Cameron was always fond, maybe a bit too fond, of Pigs and their purty mouths.

      Captcha: lustily

    3. Re:on-boar by Anonymous Coward · · Score: 0

      Quoting Churchill on Naval Traditions, 1913:
      "And what are they? They are rum, sodomy and the lash"

      They got rid of Rum and the Lash long ago.

    4. Re:on-boar by Opportunist · · Score: 1

      Damn. What's sodomy good for if you can't get whipped and drunk?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:on-boar by Deadstick · · Score: 2

      Boar does not mean wild pig. It means male pig with his balls intact. (/syntaxrant)

  5. And the navigation... by Vylen · · Score: 4, Funny

    ... control system is assisted by Clippy.

    1. Re: And the navigation... by Anonymous Coward · · Score: 0

      It looks like you are trying to...
      Wait, you can't be serious! I'm not programmed for this!
      BSOD General protection fault. Press ctrl+alt+del to reboot the warship.

    2. Re:And the navigation... by fustakrakich · · Score: 1

      Where do you want to go today?

      Topeka!

      --
      “He’s not deformed, he’s just drunk!”
    3. Re:And the navigation... by symes · · Score: 1

      If compromised systems had clippy enabled as a consequence then I am sure the world would take security a whole load more seriously.

    4. Re:And the navigation... by mjwx · · Score: 5, Funny

      ... control system is assisted by Clippy.

      Imagine the timers.

      Missile incoming! Impact in:
      5 seconds.
      2 seconds.
      132 seconds.
      1 second.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    5. Re:And the navigation... by Errol+backfiring · · Score: 2

      ...

      * * * No Carrier * * *

      (pun intended)

      --
      Nae king! Nae laird! Nae yurrupiean pressedent! We willna be fooled again!
  6. It comforts me by Anonymous Coward · · Score: 0

    It comforts me the flagship named ship in the GB fleet will get a computer upgrade in a DECADE when the threat is TODAY.

  7. Windows for warships by Joe_Dragon · · Score: 1

    that crash's when you enter zero into the data field for the Remote Data Base Manager

    1. Re:Windows for warships by Anonymous Coward · · Score: 0

      that crash's when you enter zero into the data field for the Remote Data Base Manager

      Blaming the operating system for user land division by zero makes about as much sense as all this ZOMG.... XP??!?!!! knee jerk from the know nothing public.

    2. Re:Windows for warships by Anonymous Coward · · Score: 4, Informative

      It makes sense when the divide by 0 error in userland takes down the entire ship.

      "On 21 September 1997, a division by zero error on board the USS Yorktown (CG-48) Remote Data Base Manager brought down all the machines on the network, causing the ship's propulsion system to fail."

      https://en.wikipedia.org/wiki/USS_Yorktown_(CG-48)

    3. Re:Windows for warships by Anonymous Coward · · Score: 0

      Really secure code base, I know that "I" feel
      safer already. Put some real time and talent
      into a linux/linex base...

  8. Holding a Warship Ransom by Camel+Pilot · · Score: 1

    Ransomware writers around the world are salivating.

    Seriously who would make such a boneheaded decision?

    1. Re:Holding a Warship Ransom by ScentCone · · Score: 1

      Maybe the sort of bonehead who can't make it all the way through the summary in order to discover the system was provisioned many years ago?

      --
      Don't disappoint your bird dog. Go to the range.
    2. Re:Holding a Warship Ransom by DontBeAMoran · · Score: 2

      You're right. After all, when Windows XP came out Microsoft had a pristine security history from MS-DOS 3 to Windows 98.

      --
      #DeleteFacebook
    3. Re:Holding a Warship Ransom by quenda · · Score: 1

      You're right. After all, when Windows XP came out Microsoft had a pristine security history from MS-DOS 3 to Windows 98.

      That does not really count as XP is based on NT, not DOS as win-98 was. But still, Microsoft.
      Such a choice does not inspire confidence in the technical competence of the decision makers. Are they really using Windows for the combat systems?

    4. Re:Holding a Warship Ransom by Darinbob · · Score: 1

      Well of course, we know those are insecure. But Windows 10 is perfect! It will stay perfect until there's a later release. But wait, they'll never have another Windows version, ever, so it should stay perfect forever!

      You can run your coffee makers on Windows, but if it's mission critical you don't want to go anywhere near Microsoft software.

    5. Re:Holding a Warship Ransom by TheRaven64 · · Score: 1

      When it was commissioned, Microsoft had publicly stated the EOL for XP was 2009. They pushed it back a few years afterwards when people hated Vista. Designing in an OS that would not be getting security updates by the time the ship was scheduled to launch (even if it hadn't been delayed) was dangerously negligent.

      --
      I am TheRaven on Soylent News
  9. But can it avoid collisions by Anonymous Coward · · Score: 1

    It might be high tech like US destroyers, but can it avoid becoming a hood ornament for a container ship? That is the test.

  10. HMS Brixit by Anonymous Coward · · Score: 3, Funny

    "And senior officers said they will have cyber specialists on board to defend the carrier from such attacks."

    ALL UNPLUG FULL!

    Answering all unplug full aye!

    1. Re:HMS Brixit by Anonymous Coward · · Score: 0

      Too late.

      Entire ship is infected.

      And since the computers are now unplugged.... the ship is disabled.

    2. Re:HMS Brixit by Anonymous Coward · · Score: 0

      I'd mod this a funny if I had points and the will to regain access to my /. account.

  11. This is crazy by El+Cubano · · Score: 5, Interesting

    Every military appears subject to the same idiocy. Seriously, you are spending literally billions of USD, GBP, or EUR (I tried to use the actual symbols for GBP and EUR, but I forgot about Slashdot and unicode). You can't spring a few million for a custom built or customized (e.g., based on OS/2, QNX, VXWorks, Linux, etc.) OS that has all the networking and other non-essential components removed? Then you can allow network access via a very tightly controlled and well audited interface.

    The main reason, I think, for this conundrum is that there are two competing objectives: 1) extremely rigorous system engineering processes with the attendant configuration control; 2) use more COTS and fewer custom components. For instance, those decisions were definitely made over a decade ago and any change to them would require tons of paperwork, additional certification, and also add to the cost and delay the schedule. It's no wonder they just stuck with what was already approved.

    That said, I simply cannot believe that one or more of the big defense firms (e.g., BAE, Lockheed-Martin, Boeing) has not come up with something better than slapping Windows on it.

    Now, I know (or rather, I truly hope) that things like navigation, fire control, and other critical ship functions are not dependent on any Windows (or other consumer OS). However, I know that some years ago the US Navy had a "Windows-power ship" end up dead in the water and had to have it towed back to port. That was the result of a divide by zero bug in some piece of software but Windows did not handle it gracefully, if I recall correctly.

    Either way, they will be lucky if they don't end up with some very serious problems along the way. It seems like it is just not possible to keep ransomware out of any decently sized network. And I can imagine a major world power's flag ship being a tempting target.

    1. Re:This is crazy by darthsilun · · Score: 1

      $ € £ What's the issue?

    2. Re: This is crazy by Anonymous Coward · · Score: 0

      Well depends on how you see spending ..The taxpayer spends the billions . The contractor spends peanuts so probably can't "afford" a custom stack

    3. Re:This is crazy by AHuxley · · Score: 1

      All the people at the port are trusted and totally and fully vetted. The crew is totally trusted by default.
      The buddy system always ensures nobody can use their own computer from home they took with them.

      What could another nation or faith group do?
      Sign up an unexpected person to go for ship education, become a sailor and then rise up the ranks for years?
      One spy on a ship? The buddy system would totally prevent that. Two spies on average would not get to work alone together given the crew size so that would not happen. The buddy system always works.
      Hope someone walks a very special XP computer virus into the port as part of their day job or takes a computer thats infected from home onto a ship with them?
      Thats not allowed.

      --
      Domestic spying is now "Benign Information Gathering"
    4. Re:This is crazy by Anonymous Coward · · Score: 0

      a few few million? you mean a few billion right? custom support, custom training and certification and maintenance. there may be better options then windows but doing their own customized built aint fucking it.

    5. Re:This is crazy by Anonymous Coward · · Score: 1

      Does Slashdot provide a convenient reference page listing the allowed non-ASCII characters?

    6. Re:This is crazy by Anonymous Coward · · Score: 0

      Uh oh, now you've done it. Slashcode has healed itself - by the end of august, it will be self-aware....

    7. Re:This is crazy by Anonymous Coward · · Score: 0

      And yet, it happens. And it didn't require a spy either.

      How do you think the USAF had drone flight control systems get viruses?

      They don't now because the flight control systems run linux instead. They learned their lesson.

    8. Re:This is crazy by Anonymous Coward · · Score: 1

      I think you need to use the HTML entities: £ € ¥

      Because otherwise they turn out like this: £ â Â¥

      With HTML you get: £ € ¥

    9. Re:This is crazy by darthsilun · · Score: 1

      $ € £ What's the issue?

      I think you need to use the HTML entities: £ € ¥

      Because otherwise they turn out like this: £ â Â¥

      With HTML you get: £ € ¥

      No, I didn't use HTML entitles. I'm on a Mac. I just used the 'Show Emoji & Symbols' pulldown menu to enter them.

      /. likes some things, e.g. £ € ¥ é ü ñ. Most of the other things I might use – degree sign, thorn, eth, certain accented characters – don't work whether I enter them directly, from Show Emoji & Symbols, or as HTML entities.

    10. Re:This is crazy by TheRaven64 · · Score: 1

      The spy doesn't need to bring their own computer, they just need to find an exposed USB port and plug in a malicious device smaller than a thumbnail to an device on the ship network. Want to bet that there are exposed USB ports for routine maintenance?

      --
      I am TheRaven on Soylent News
    11. Re:This is crazy by Anonymous Coward · · Score: 0

      You have most of that right.

      As someone who worked on that software around the time the switch was made to XP (it was going to be Windows 2000 before that), (hence posting as anon), I can tell you just how difficult that switch was (and hence expensive).

      Caveat: My information is at least 10 years out-of-date, but my experiences suggest things haven't changed that much.

      The problem is really one of time-scale and costs. Work on these ships starts 10 or more years before they even start building them. The ships have an expected lifespan of 25-50 years (before they are scrapped or sold; some ships then continue to serve with a 2nd or 3rd world navy for another 50 years), and will need replacements for that entire time. Remember NASA buying chips for the space shuttle on E-bay? The same thing will happen with COTS ships, either that or all the hardware is bought in advance and stored.

      Buying in advance, COTS components, is probably a lot cheaper than designing, testing, manufacturing etc custom hardware. Not to mention the need to write drivers and all the other things that go with that. Once you've got a system that you've tested extensively (it is mission critical) you are unlikely to want to change anything (like the motherboard, or graphics drivers, or god forbid the OS) unless you really have to. Not to mention that these are not standard PC cases, but specially hardened, shock-proofed, and fire suppressing units, so a change in shape of any component will also have potential issues (not to mention new testing to approve it).

      That said critical system like the C3 systems are on private networks, and the C2 system doesn't even run explorer.exe, it uses a custom shell and is very heavily locked down and constrained. Penetration risks are more likely to apply to ancillary systems, like the computers running Office for writing reports, or the crew mess menu, or those connected to the internet for intelligence gathering etc, and I have no idea what those might be running and those are on an entirely separate network to the really critical systems.

      Governments keep wanting more expensive and elaborate tech at much cheaper prices and quicker time-scales. If you don't have to design and build the hardware, or a large chunk of the software, that's a massive saving in time and money. Of course the downside is that you increase your attack surface.

    12. Re:This is crazy by jittles · · Score: 1

      You can't spring a few million for a custom built or customized (e.g., based on OS/2, QNX, VXWorks, Linux, etc.) OS that has all the networking and other non-essential components removed? Then you can allow network access via a very tightly controlled and well audited interface.

      How do you know they don't run a customized install of Windows XP? I don't know how the UK does it, but in the US there are DoD Information Assurance policies that make sure that any machine the DoD procures has certain security settings based on the OS installed. They have different rules depending on the OS you're using, and only have certain OSes that have been officially sanctioned. The rules vary based on the purpose of the machine and they have software that automatically checks to make sure that the image used to create a machine has the correct settings enabled. They often fill spare USB ports with epoxy, or have them physically disconnected so that they provide a charge only. Then they white list specific USB devices for the ports that are enabled. Going through the Information Assurance certification process on a Windows machine is a nightmare. It's relatively easy with RedHat Enterprise Linux. I worked on simulators that were never connected to any network (outside of the locked cabinet that contained all the machines used in the simulation) and we hated dealing with certification. I'm not saying that those policies completely protect against all attack vectors but I bet you did not see WannaCry hitting any DoD computer network. I certainly did not hear of any.

      That's not to say that the ship may be free of critical software bugs that could cause serious problems with the functioning of the ship. I'm just merely stating that they don't go down to Best Buy, get a copy of Windows, and throw it onto the machine with default services and settings. If they are using Windows, it is almost certainly on a human interface and they're probably doing so because it's what most people are accustomed to. Though that does not rule out the possibility that they are doing so to leverage legacy software / code.

    13. Re:This is crazy by Anonymous Coward · · Score: 0

      Sign up an unexpected person to go for ship education, become a sailor and then rise up the ranks for years?

      Nah, usually you groom someone already in place.
      You don't even need them to be fully on your side, just compromised enough to do something stupid and ideally they should not realize what the consequences will be.
      "Here is a USB stick, have a look at the documents on it once you are out on the sea."

    14. Re:This is crazy by AHuxley · · Score: 1

      Yes one person is often turned due to faith, cult, politics, weakness or poverty and might just be give a rather safe long term task.
      To watch and make a list of all the bad people at their base.
      Parties, who went out off base and did what. Contractors and mil staff then got approached as they had a lot of negative issues.
      The other change is party political suggestions to change the mil. Just let more people in and not worry so much about traditional issues like vetting or standards.
      The desperate need for skills and just keeping staff. Very average staff start to push some of the rules. They bring entertainment electronics with them. That then needs power after a while. Anything USB is discovered and made to supply power over the long hours on duty.

      --
      Domestic spying is now "Benign Information Gathering"
    15. Re:This is crazy by Anonymous Coward · · Score: 0

      Every military appears subject to the same idiocy. Seriously, you are spending literally billions of USD, GBP, or EUR (I tried to use the actual symbols for GBP and EUR, but I forgot about Slashdot and unicode). You can't spring a few million for a custom built or customized (e.g., based on OS/2, QNX, VXWorks, Linux, etc.) OS that has all the networking and other non-essential components removed? Then you can allow network access via a very tightly controlled and well audited interface.

      I expect that is preceisly what they are doing. They are however using Windows as the base OS.

      I mean, they'd be paying Microsoft for support and the needs of a warship would likely me a lot of that support is in customizations for interoperability with the warship's systems and such.

      They probably chose Windows over in-house Linux so that Powerpoint would work on the Captain's terminal.

      And with auto-run turned off, XP can be in some ways more secure than 10 which will try to update from external sources at the drop of a hat.

    16. Re:This is crazy by dpidcoe · · Score: 1

      You can't spring a few million for a custom built or customized (e.g., based on OS/2, QNX, VXWorks, Linux, etc.) OS that has all the networking and other non-essential components removed?

      I'd be willing to bet that most of the systems "running windows XP" are actually running XP embedded, which *is* a stripped down and highly customized OS with all non-essential components removed.

    17. Re:This is crazy by Sir+Holo · · Score: 1

      Either way, they will be lucky if they don't end up with some very serious problems along the way. It seems like it is just not possible to keep ransomware out of any decently sized network. And I can imagine a major world power's flag ship being a tempting target.

      Yeah. With 1600 people on-board, not one of them will sneak in a USB stick with their porn. . . that is infected with a worm or trojan. Will never happen.

      People are trustworthy, and I am sure that all of the grunts (sorry, squids) will dutifully run the most sophisticated antivirus scans available on their porn before boarding ship to leave port for sail. Don't people join the Navy primarily because they are "good at computers"?

    18. Re:This is crazy by Sir+Holo · · Score: 1

      Does Slashdot provide a convenient reference page listing the allowed non-ASCII characters?

      No kidding. Why do I have to use an escape character to get an "em dash"? ––

      I don't. ASCII has an en-dash, so I just combine two.

  12. As opposed to... by xlsior · · Score: 4, Insightful

    ... Windows for Warships? (Seriously, that exists) Anyway: despite windows XP's age Microsoft will still actively support it for organizations willing to send them a boatload of money, and the rates only go up the more time passes. But when you're talking about the operating costs of a large warship, the cost for continued xp support is only a rounding error in the total.

    1. Re:As opposed to... by Anonymous Coward · · Score: 0

      'boatload of money' - I see what you did there.

    2. Re:As opposed to... by Anonymous Coward · · Score: 0

      Let's hope they don't start using Windows for Submarines next.

      I'll see myself out.

    3. Re: As opposed to... by Anonymous Coward · · Score: 0

      If it's got the xp embedded write filter on it, a clean slate is only a reboot away.

    4. Re:As opposed to... by Anonymous Coward · · Score: 0

      They are fine as long as they don't run Java on nuclear subs:
      Excerpt from https://technet.microsoft.com/en-us/library/cc976720.aspx

      Java technology is not fault tolerant and is not designed, manufactured, or intended for use or resale as on-line control equipment in hazardous environments requiring fail-safe performance, such as in the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, direct life support machines, or weapons systems, in which the failure of Java technology could lead directly to death, personal injury, or severe physical or environmental damage. Sun Microsystems, Inc. has contractually obligated Microsoft to make this disclaimer.

    5. Re:As opposed to... by Trax3001BBS · · Score: 2

      ... Windows for Warships?

      (Seriously, that exists)

      Anyway: despite windows XP's age Microsoft will still actively support it for organizations willing to send them a boatload of money, and the rates only go up the more time passes. But when you're talking about the operating costs of a large warship, the cost for continued xp support is only a rounding error in the total.

      I LOL'd We have an aircraft carrier running NT.
      "The data contained a zero where it shouldn't have, and when the software attempted to divide by zero, a buffer overrun occurred – crashing the entire network and causing the ship to lose control of its propulsion
      system. https://www.wired.com/1998/07/...

  13. That's depressing, it's such old news by Anonymous Coward · · Score: 4, Interesting

    The last time I recall the Navy being concerned about running Windows was maybe 15 years ago. The LinuxBIOS project attracted a lot of attention from some Navy guys because of its rapid reboot capability.

    At LANL, LinuxBIOS researchers could reboot a small (1K diskless compute nodes connected via Myrinet) scientific computing cluster in 3 seconds, ready for work. So, theoretically, one could change from a Linux cluster to a Windows cluster, but no one ever wanted to.

    Whatever became of that technology?

    1. Re:That's depressing, it's such old news by Anonymous Coward · · Score: 0

      > Whatever became of that technology?

      It became CoreBoot:
      https://www.coreboot.org/

      Now this is only a low-level firmware, so it's not a complete OS ready to run user-space applications with a clustering library. I'm a bit dubious of the claim that 1K diskless compute nodes were ready to perform work in 3 seconds after being reset, but perhaps they were running something quite small and specialised.

      The biggest problem in any large project is that you end up bringing in people who are great at writing and checking specifications, but nearly clueless when it comes to the technical aspect. This is how you end up with Windows being chosen as the OS for an air craft carrier.

    2. Re:That's depressing, it's such old news by l20502 · · Score: 1

      You mean coreboot? It's still there, and is also used by chromebooks

  14. Is there even a word for this level of stupidity? by JustNiz · · Score: 5, Insightful

    The die-cision to use anything from Microsoft in a mission-critical environment, let alone a 16+ year old OS with a giant list of known exploits goes so far beyond amazingly stupid I can't even find the words.

  15. Got Ya!! by Anonymous Coward · · Score: 0

    April Fools!!! LMAO! Wait... we are in April right?

  16. That's good by Anonymous Coward · · Score: 0

    I suppose better than having your latest battleship subject to some of the latest ransomware attacks.

    Really, it depends on how isolated the system is. If it's air gapped or VPN'd only and not readily accessible with inputs like USB ports, it's more secure than a Win10 system on a WAN. There are DOS and Win3.1 systems you're never going to hack unless you get physical access to them. Sometimes a dumb, limited configuration is better than the latest connected hardware.

  17. Anyone over there watch the IT crowd? by s_p_oneil · · Score: 1

    Anyone over there watch the IT crowd?

    Moss: "What kind of operating system does it use?"

    Bomb squad: "Vista!"

    Moss: "We're going to die!"

  18. thats not really the issue... by Anonymous Coward · · Score: 0

    Lets see what the real issue is :
    1. The carrier has enough reserves only for 7 days. That means it can only fight for 7 days unsupported if it has to.
    2. Its a carrier with no aircraft. It cant fight to begin with.
    3. It relies on gas turbines. Which means continuous refueling when in use. And the fuel only lasts for 7 days anyway.
    4. It has two islands. That means the captain cant handle ship navigation and oversee aircraft operations at the same time. instead he has to run between the two islands if he wants to be present for both or requires that situational awareness.
    5. The radar can only go upto 400km for normal aircraft or 20km for stealth fighters. Yes thats 20km to detect a stealth aircraft, well within launch range of anything.
    6. The two huge islands aka office towers block anti missile defenses That means they cannot defend against missiles or even detect the due to the block shadow.
    7. There are only 3 anti missile guns on board. Yes only 3 CIWS weapons suitable for engaging last ditch missile attacks. And they are all blocked by the huge office towers sitting on the deck.
    8. There are tons of egress and therefore ingress points on the flight deck - any hostile force landing will have an easy time to reach the internals.

    1. Re:thats not really the issue... by Anonymous Coward · · Score: 0

      There's a reason aircraft carriers are part of battle groups.

  19. Re:Is there even a word for this level of stupidit by Gravis+Zero · · Score: 2

    Is there even a word for this level of stupidity? The die-cision to use anything from Microsoft in a mission-critical environment, let alone a 16+ year old OS with a giant list of known exploits...

    I believe the word you're looking for is "congressional". ;)

    --
    Anons need not reply. Questions end with a question mark.
  20. silk worm? by Anonymous Coward · · Score: 0

    if falkland.

    s is any indication, well yeah

    uk needs beater ship defence

    1. Re:silk worm? by AHuxley · · Score: 1

      AC that should have all been ok.
      The UK did not expect anyone to work out how to use that French systems in the time allowed.
      It was an export grade weapons system and was expected to stay on an internal surrender setting.
      Crews worked very hard and very quickly to discover full French access to the very complex system.
      Most nations now know that have to fully trust who they buy from or what systems they use.

      --
      Domestic spying is now "Benign Information Gathering"
  21. Re:Is there even a word for this level of stupidit by WaffleMonster · · Score: 1

    The die-cision to use anything from Microsoft in a mission-critical environment, let alone a 16+ year old OS with a giant list of known exploits goes so far beyond amazingly stupid I can't even find the words.

    Can you name a single known exploit that applies to this ships XP systems as deployed?

  22. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    That's because you assume a control system with an HMI that runs on a version of XP is at all like your grandma's computer. There is no reason for an operator interface to run Windows 7, or Windows 10, or some specialized Unix that costs $10,000 per HMI.

    Yes it's possible to infect any system, but the odds that it will happen here are slim. It's not connected to the internet like your computer and most of the HMIs I've worked on are locked down and behind firewalls.

    Control systems have to run with high uptime, and there is no reason to assume a new version of Windows is better in this use case.

  23. So what? by Anonymous Coward · · Score: 0

    FTFA:

    It is unclear how networked HMS Queen Elizabeth is - the machines are likely to be “air gapped”, protecting them from external attacks. Of course a human could still gain physical access to them - Iranian nuclear plants running XP were infected by USB sticks. However, a spy on board a warship may mean bigger problems than computer hacking.

    This snippet is the key - is the mission critical computer in question on a LAN with other machines, or not? Because if it's not, the OS vulnerabilities could be mostly a moot point. Yes, someone could infect it with a USB key (if the thing even has USB ports enabled). Generally, if you have physical access to the machine, the game is already over.

  24. Good enough for US Missle Defense by Anonymous Coward · · Score: 0

    You can find XP in 24/7 use in the US missile defense command.
    It has been extremely reliable.
    However, these control systems are never connected to an external network.

  25. Almost every luxury vehicle manufacturer... by kdubb1 · · Score: 2

    ... has managed to develop their own QNX based base operating system to ensure safety & security. They've also been doing it for a couple decades.

    It seems insane that the Royal Navy & BAE systems couldn't figure this out themselves. This has the smell of a kickback based sales agreement to me. Almost any other operating system is a better choice simply because they are smaller attack targets than any version of Windows.

    1. Re:Almost every luxury vehicle manufacturer... by WaffleMonster · · Score: 1

      It seems insane that the Royal Navy & BAE systems couldn't figure this out themselves. This has the smell of a kickback based sales agreement to me. Almost any other operating system is a better choice simply because they are smaller attack targets than any version of Windows.

      When your adversaries are other nations security by obscurity is especially inoperative.

    2. Re:Almost every luxury vehicle manufacturer... by dbIII · · Score: 1

      It seems insane that the Royal Navy & BAE systems couldn't figure this out themselves. This has the smell of a kickback based sales agreement to me. Almost any other operating system is a better choice simply because they are smaller attack targets than any version of Windows.

      When your adversaries are other nations security by obscurity is especially inoperative.

      Security by installing a system designed to be secure is the idea - there are many. Even MS had one with WinCE that is far more up to date than WinXP.

  26. Joseph Lucas, Prince of Darkness? by boudie2 · · Score: 0

    Anyone who buys anything made in the U.K. should not be surprised when it falls apart. That's the reputation the British have developed over decades. Crappy McCrapCrap.

    1. Re:Joseph Lucas, Prince of Darkness? by jcr · · Score: 1

      Rolls Royce still makes some of the finest engines in the world, right in Derby.

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    2. Re:Joseph Lucas, Prince of Darkness? by boudie2 · · Score: 1

      Agreed, not every thing is crap. Although for every good example you can provide, there are a hundred bad. And you must mean jet engines, as the cars are as German as Herman Goering.

  27. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    Do you believe the ship's control systems will be browsing the net? It's highly unlikely they're networked into a general network and thus the largest concern is someone plugging in an infected device. Don't forget the military pays top dollar to continue to get support from Microsoft and has access to the source code. Well, that's American ships. I don't know if Britain bought the same support package.

  28. Re:Is there even a word for this level of stupidit by JustNiz · · Score: 1

    Just fucking google it. There are large numbers of unpatched XP exploits. Microsoft themselves even admit the entire OS is fundamentally insecure and will never be fixed. They even said the same thing about Win 7 as soon as they wanted you to buy Win 8.

  29. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    Just because they used XP in there, doesn't mean the MI-666 won't show up in his doorstep if he actually *knows* of an exploit that can cause damage to that ship (or is unlucky enough to actually guess it correctly).

  30. Re:Is there even a word for this level of stupidit by JustNiz · · Score: 1
  31. That's not all. by Gravis+Zero · · Score: 4, Interesting

    The Register in 2009

    According to the Ministry of Defence (MoD), HMS Montrose has now entered a planned docking and refit period during which BAE Systems plc will replace her original DNA(1) gear with DNA(2), said to be "based on the system being fitted to the Royal Navy's powerful new Type 45 Destroyers". This means it will be based on fairly everyday hardware running legacy Windows OSes - people who have worked on these programmes inform us that both Win2k and XP will be in use across the fleet.

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:That's not all. by Anonymous Coward · · Score: 1

      There's a good reason for that: Microsoft gave up the source code for 2k and XP to security audit and they passed. Nobody could understand the Vista source code, so most military around the world stopped upgrading around XP (and isolated machines from the internet, each other, and USB devices in order to prevent infection).

  32. XP Embedded != XP by Anonymous Coward · · Score: 0

    You don't need to run explorer.exe as your shell (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell) under XP Embedded. Writing your own shell and turning off things like network discovery are but a couple of the many techniques that were available to harden XP Embedded back in the day. Given how much research goes into hacking these days it was only a matter of time before those techniques ceased being effective.

  33. Re:Is there even a word for this level of stupidit by WaffleMonster · · Score: 1

    Just fucking google it. There are large numbers of unpatched XP exploits. Microsoft themselves even admit the entire OS is fundamentally insecure and will never be fixed. They even said the same thing about Win 7 as soon as they wanted you to buy Win 8.

    The existence of exploits is different from question of which exploits are applicable to XP systems as actually deployed on this ship.

  34. Solutions exist by Anonymous Coward · · Score: 0

    1. For major vulns Microsoft is still releasing free security patches for XP (just recently happened)
    2. For a few million you can buy security patches from Microsoft still
    3. McAfee SolidCore or other whitelist technologies do allow for only permitted authorized code to execute and not malware

    In general though the longer you go the more you end up paying for mitigating controls and operational maint. expense versus replacing the hardware and OS.

  35. Uh oh! by Anonymous Coward · · Score: 0

    Uh oh! Your missile launch codes have been encrypted by ransomboatie. To get the decryption key, send $10,000,000 worth of Bitcoin to: 15VnnCwcXKxzDoeGvErBYg2oqJmPWrpKCJ

  36. Everybody hates windows 10! by Anonymous Coward · · Score: 0

    The real story here is how much even normal people hate everything that came after XP. They hate it so much they'll put up with an the ancient XP.

    It's all about that classic start-button-in-the-corner interface.

    1. Re:Everybody hates windows 10! by Z80a · · Score: 1

      I think that probably the whole "you're being updated by forced and shoved ads up your ass" thing have a bit to do with it.

  37. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    It is light years beyond stupid. Darwin Awards would approve.

  38. 13 years by Anonymous Coward · · Score: 0

    ... been good in 2004 ...

    It costs a lot of money for certification so Lockheed-Martin and Boeing don't want to do that again. Lockheed-Martin and Boeing earn more money for fixing stuff, so they want the military to buy upgrades: Building for early obsolescence is a capitalist necessity.

    The real issue being, software was locked-in early on a 13 year project to design, certify and build military hardware. Their project management needs to address software later in the process and concentrate on specifying the API (eg. Win32) and hardware interfaces (USB, SATA, PCI, DIMM, FPGA), not versions/releases.

    This also allows project management to address the UI and user experience long before the coding phase of the software. Given that modern warfare control rooms have failed spectacularly (USS Vincent), they might want to reduce the chance of a re-occurrence.

    1. Re:13 years by Anonymous Coward · · Score: 0
  39. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 1

    I believe the word you're looking for is "congressional". ;)

    In England, they call it "Parliamentarian" old chap, bip-bip, cheerio.

  40. At least they upgraded. by Snufu · · Score: 1

    The U.S. nuclear fleet still runs on Microsoft Bob.

  41. On boar by slazzy · · Score: 1

    I'd love to see the on boar systems they mention.

    --
    Website Just Down For Me? Find out
    1. Re:On boar by Opportunist · · Score: 1

      Boars with lasers, I hope?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  42. Armageddon Clippy by Snufu · · Score: 4, Funny

    It looks like you are trying to turn the surface of the earth into glass. Would you like help?

    1. Re: Armageddon Clippy by aliquis · · Score: 1

      Ah, give it to me!
      I'm trustworthy!

    2. Re:Armageddon Clippy by freeze128 · · Score: 1

      That's going to be hard since it's mostly water...

    3. Re:Armageddon Clippy by Anonymous Coward · · Score: 0

      They're going to target the sandy parts

    4. Re:Armageddon Clippy by Zaatxe · · Score: 1

      You missed the detail that he/she spelled "earth" with a lowercase "e"...

      --
      So say we all
  43. Why Windows? by Anonymous Coward · · Score: 0

    Windows being used in security critical applications simply boggles the mind. Have they ever heard of seL4 or QNX, Linux or pretty much anything else that would be open source. At least you can continue to maintain it after it becomes obsolete. I assume these ships are going to be used for more than 5 years. Your tax dollars at work...

    That said why do people use Windows in some embedded applications? I think it makes no sense to use a proprietary operating system when they drop support after a few years anyway.

  44. Re:Is there even a word for this level of stupidit by AHuxley · · Score: 1

    Think of it from a UK mil perspective.
    They have to find people to use the computer GUI. Make a bespoke UK OS? Thats a lot of new computer tasks to learn and teach to average people new to the navy.
    Trying to keep people in the navy is not helped by some strange, new, expensive, complex new UK mil OS.
    No need to teach the users how to write code in something like a new Ada to do GUI things.
    That keeps teaching costs lower and makes teaching methods for new crews more easy. Just like a really big home computer but at sea.

    The gov and mil security thinking works like this:
    The port, repair areas are totally secure as all the contractors and mil staff are allowed to be on site and are 100% trusted.
    When the ships need service or get towed back to port again contractors get all systems working again.
    No cult, person who is loyal to their religion or another nation or is political motivated can get to the XP computers that are secure thanks to a big, high, strong fence around the port.
    No person is allowed to bring any different electronic device with them from home. Thats a really strict rule and no personal equipment is allowed on any UK ship or near a ship in port.
    So nothing can go wrong. The fence around the port is huge. When the ship is at sea its totally protected from random people walking onto the ship.
    Staff, contractors and people at sea would never ever use or bring any other digital devices. From home to the port or for their own use for the long time spent at sea or under the sea.
    People at sea are sleeping, learning about the GUI, eating or taking tests and are not alone. They have no time to use their own computers they would never have with them as they have been searched for such devices.
    So the selection of the OS saves the gov money when teaching very new users, GUI applications look like what average people are used to, its easy for contractors to work with a lot and get overtime to fix when in port. Its win, win, win if everyone is vetted, the fence is big and nobody ever brings files or computer devices from home to the port or on the ship.
    The term is air gap.

    --
    Domestic spying is now "Benign Information Gathering"
  45. They would gladly upgrade... by Picodon · · Score: 1

    ...but they’re held back by some unresolved incompatibility that causes Harpoon to crash on Windows Vista.

  46. Heh, thanks to me by Snotnose · · Score: 1

    this hit fark a good 12 hours ago.

    That said, I don't get the thinking here. WinXP is old, outdated, and insecure. If you don't want Win10 or whatever you've got linux, along with several modern RTOS's. Hell, rolling your own is probably better than WinXP.

    If you've got a CNC machine, or bioassay device, or whatever, it's fine. As long as the internet can't find it. Soon as the $bad_guys find it, game over.

    1. Re:Heh, thanks to me by toadlife · · Score: 4, Informative

      If they ran Linux on the ship it would be Linux from back when the ship was designed, full of potential vulnerabilities just like whatever flavor of XP they're running. With giant systems like this, there is a much higher potential risk when introducing changes to the systems and given the fact that the systems are not connected to the outside world, the reward for keeping software up to date can be very little to none.

      --
      I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
    2. Re:Heh, thanks to me by Anonymous Coward · · Score: 0

      The thinking really is pretty simple. They have a stack of software that works on that version of windows and one of the cost, time, complexity, ability to move it to another OS MS or otherwise is seen to be problematic; none of which means it might not be a stupid call.

      With that said using antiquated OS is very controlled environments isn't necessarily the clusterfuck it sounds like. If you have a system that is entirely self-contained with the exception of perhaps a dozen strongly regulated communications (receiving coords, sending specific instruction) then it doesn't really matter if the OS is secure. Additionally in the military theatre just installing Linux and assuming that means your safe is a little naive, you're not just worried about random malware but also concerted efforts by wealthy enemies to exploit your systems.

  47. Re:Is there even a word for this level of stupidit by RightwingNutjob · · Score: 1

    You know, I built a WinXP HMI back in 2010 and had it work wonderfully for me for years on an airgapped machine. And then about two years in, some screw condition with one of the proprietary hardware drivers on it causes the whole thing to reboot entirely on its own.

    Now, you might ask, why would I do something like that at all. And the answer is that the nameless industrial controls vendors Allen-Bradley and National Instruments explicitly marketed a WinXP/LabView solution for HMI as an alternative (not even a cheaper alternative, just an alternative) to a dedicated touchscreen box for customers like me who needed more out of the HMI than what the touchscreen dowhicky came with, namely datalogging and additional helper logic that's naturally implemented somewhere besides the safety-critical ladders.

    Now, a the Linux driver for that gizmo that caused the windows box to reboot didn't have that issue. And even if it had, Linux would have failed more gracefully and the controls would have still worked. But Allen Bradley was a Windows-only outfit. So the once a year spontaneous reboot is the price I paid for not having to reinvent a very expensive wheel. I suspect that this aircraft carrier is the same. They need Windows for something that would be very expensive to reinvent, and between their budget pressures, military procurement silliness, and the fact that they just might not have enough time and enough good people to do it...they went with WinXP.

  48. Re: Is there even a word for this level of stupidi by Anonymous Coward · · Score: 0

    "They even said the same thing about Win 7 as soon as they wanted you to buy Win 8."

    Shows what they know.

  49. do you want to play a game? by Joe_Dragon · · Score: 1

    It looks like you want to play global thermonuclear war

    what side do you want??

    1. USA
    2. Russia
    3. United Kingdom
    4. France
    5. China
    6. India
    7. Pakistan
    8. North Korea
    9. Israel

    1. Re:do you want to play a game? by Aighearach · · Score: 1

      I'll take France, who else on that list is even bothering to target them?

    2. Re:do you want to play a game? by Joe_Dragon · · Score: 1

      Please list primary targets by
      CITY AND/OR COUNTY NAME:

    3. Re:do you want to play a game? by Aighearach · · Score: 1

      Pass.

      Look, I win 1 wasteland!

    4. Re:do you want to play a game? by Maritz · · Score: 1

      I'll take France, who else on that list is even bothering to target them?

      The Brits. All their problems are Europe's fault.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
    5. Re:do you want to play a game? by TheRaven64 · · Score: 1

      Britain. We've replaced all of our tactical command with machine learning, which has determined that for most of the last thousand years (the training set), the enemy was France, and so any appearance by France of not being the enemy is probably a ruse. After that, it will attack Spain and then Germany.

      --
      I am TheRaven on Soylent News
    6. Re:do you want to play a game? by Opportunist · · Score: 1

      Careful, everyone picks France as a target. Didn't you learn anything from your Simpsons?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:do you want to play a game? by Aighearach · · Score: 1

      Yeah, but Russia has to target the UK, and the UK only have a few warheads, so as much as they'd love to toss a few off on the French, they just don't have the time.

  50. It is Windows for Warships, which is based off XP by Anonymous Coward · · Score: 0

    It is a hardened version of Windows, and no it will probably have a BSOD before it is hacked. Plus, the ship's computers cannot be accessed from the 'Net, and I doubt anyone will be allowed to hook up a USB drive either.

  51. Network DDE by Anonymous Coward · · Score: 0

    Network DDE is used to communicate with the fire control systems running Windows for Warships.

  52. Man the Brits are LUCKY by sit1963nz · · Score: 1

    Just imagine if this was on one of their submarines and someone opened a Window while they were submerged. Talk about a crash dive.

    Mind you, this is from the same country that bought you flammable warships during the Falklands war.

    1. Re:Man the Brits are LUCKY by chthon · · Score: 1

      Must have been the same design as the Grenfell Tower, then

  53. Re:Is there even a word for this level of stupidit by gravewax · · Score: 1

    I googled, could not find a single exploit that applied to the isolated systems of warship. perhaps you can point at some?

  54. Lemmings.. my God you are all Lemmings. by Anonymous Coward · · Score: 0

    https://www.theregister.co.uk/2015/12/18/windows_for_warships_not_on_queen_elizabeth_class_aircraft_carriers/

    Hopefully enough of you read this before you commit yourselves to they abyss.....

    https://en.wikipedia.org/wiki/Lemmings_%28video_game%29

  55. Navel Warfare by mad-seumas · · Score: 2

    The last thing you want to see in naval warfare:

    Your cruise misses have been encrypted. Do not bother trying to decrypt your cruise missles as they can only be decrypted by us. Send ${YOOGE_BITCOIN_MONIES} to our friendly decryption service to decrypt your cruise missles.

  56. The MoD has lied ! by Mosquito+Bites · · Score: 5, Interesting

    This is serious !

    Back in 2015 the MoD declared that this vessel would be 'Windows-XP Free'

    Read the article below if you do not believe ---

    https://www.theregister.co.uk/...

    1. Re:The MoD has lied ! by mugurel · · Score: 1

      However, he added that HMS Queen Elizabeth is due to be given a computer refit within a decade.

      What's the fuss about? In 2027 this warship will be up-to-date with bleeding edge Windows 10. Oh wait...

    2. Re:The MoD has lied ! by stealth_finger · · Score: 3, Funny

      However, he added that HMS Queen Elizabeth is due to be given a computer refit within a decade.

      What's the fuss about? In 2027 this warship will be up-to-date with bleeding edge Windows 10. Oh wait...

      Until it decides to update in the middle of a battle.

      --
      Wanna buy a shirt?
      https://www.redbubble.com/people/stealthfinger/shop?asc=u
    3. Re:The MoD has lied ! by Meneth · · Score: 1

      If Microsoft's new strategy holds, of releasing update packs instead of new major versions of Windows, then your prediction might very well come true.

    4. Re:The MoD has lied ! by rtb61 · · Score: 2

      Why bother fussing with anything at all. The vessel has largely served it's purpose, spending 3.5 billion dollars on the military industrial complex. It was designed to be built 'out of date' so a life time of upgrade cycles will be required which will preferably eclipse the 3.5 billion spend, more profits, fuck infrastructure, fuck social services, war, war, war. It matters not one iota how well it works, just how much corporate profit it can generate. The floating version of the F35 Flying Pig, destined to generate billions in profit from all over the globe, paid as required tribute to the US military industrial complex or else regime change.

      --
      Chaos - everything, everywhere, everywhen
    5. Re:The MoD has lied ! by AmiMoJo · · Score: 1

      Why would their battle critical systems be connected to the internet anyway?

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    6. Re:The MoD has lied ! by currently_awake · · Score: 1

      Windows 10 isn't exactly bug free. XP might actually be safer, because it's not actively targeted due to its age (security via obsolescence). Or you could run OpenBSD and have a secure OS.

    7. Re:The MoD has lied ! by FictionPimp · · Score: 1

      Not actively targeted?? Are you reading the news at all?

    8. Re:The MoD has lied ! by gnick · · Score: 2

      What if you want to launch a missile strike from your phone? I saw Arnold do it in a commercial. Think about these questions before you ask them.

      --
      He's getting rather old, but he's a good mouse.
    9. Re:The MoD has lied ! by Anonymous Coward · · Score: 0

      Because XP stops running if you don't activate after installing. That's the Genuine Advantage(tm).

    10. Re:The MoD has lied ! by Anonymous Coward · · Score: 0

      If you build something that takes a decade and you always rework to include the latest technology. You will never finish the project.

      Do you think if there were no machinations or willingness to fight war we would all just sing together by campfire in peace? I have a bridge to sell you.

    11. Re:The MoD has lied ! by penandpaper · · Score: 1

      To receive orders from Twitter. How else would it be a battle critical system if it couldn't receive orders from heads of state?

    12. Re:The MoD has lied ! by stealth_finger · · Score: 1

      Because the joke doesn't work otherwise.

      --
      Wanna buy a shirt?
      https://www.redbubble.com/people/stealthfinger/shop?asc=u
    13. Re:The MoD has lied ! by Anonymous Coward · · Score: 0

      So that they can activate Windows. They may also need to reactivate it if the hardware configuration changes, e.g. too many missiles are uninstalled from their racks.

    14. Re:The MoD has lied ! by Anonymous Coward · · Score: 0

      I keep on reading tech news and realized EternalBlue exploit and WannaCry ransomware won't function properly on XP machines. Google is your friend.

    15. Re:The MoD has lied ! by amicusNYCL · · Score: 1

      I don't see what the big deal is.

      I want to reassure you about Queen Elizabeth, the security around its computer system is properly protected and we don't have any vulnerability on that particular score.

      The security is protected. Even the security has security, how can it get better than that?

      It's like, how much more secure could this be? And the answer is none. None more secure.

      --
      "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
    16. Re:The MoD has lied ! by Anonymous Coward · · Score: 0

      Why do you think that internet connectivity is a mandatory prerequisite for a cyber attack?

  57. Experts, all of them. by martinX · · Score: 1

    "senior officers said they will have cyber specialists on board to defend the carrier from such attacks" translates to "they have the original installation floppies standing by".

    --
    When they came for the communists, I said "He's next door. Take him away. Goddam commies."
    1. Re:Experts, all of them. by Anonymous Coward · · Score: 0

      "they have the original installation floppies standing by"

      Enemy lieutenant: "Sir, they have the install floppies at the ready! Our ransomware attack is foiled!"

      Enemy commander: "Damn, I was hoping to avoid the casualties, but we have no choice. Helm, move the ship closer to the enemy vessel, broadside. Lieutenant, start up the DCX-012. We're taking out those floppies."

      Enemy lieutenant: "Aye, sir."

      Computer: *Degaussing cannon online*

  58. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    Yes, that word is "cyber"
    When you hear someone say cyber, you know you've found stupid.

  59. Re:Is there even a word for this level of stupidit by redmid17 · · Score: 0

    That's because you no literally nothing about long term asset procurement, fixed asset operation, military equipment, non-networked computer security, or physical access prevention.

    Other than that, I completely agree with you.

  60. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    can't see any on that list that would be relevant for isolated custom systems? perhaps you should be more specific?

  61. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    Hmmm. Maybe if something seems outrageously stupid to you, and also seems important, with a lot of resources dedicated to it, you should think to yourself, "Maybe I'm not getting something here..."

    Of course, on slashdot *everyone* is a reactionary who does not think for a moment before posting, so it doesn't surprise me at all that you're not thinking here.

  62. Can't wait for the headlines by nospam007 · · Score: 4, Funny

    "Warship sunk by fat Russian boy on the couch of his mother's basement."

    1. Re:Can't wait for the headlines by Anonymous Coward · · Score: 0

      "Warship sunk by fat Russian boy on the couch of his mother's basement."

      I find that very offensive! It's an aircraft carrier, not just "a warship".

    2. Re:Can't wait for the headlines by Anonymous Coward · · Score: 0

      Carry McHarrierface

    3. Re:Can't wait for the headlines by StormReaver · · Score: 2

      "Warship sunk by fat Russian boy on the couch of his mother's basement."

      You forgot to end it with, "Sad!"

  63. Re:Is there even a word for this level of stupidit by 91degrees · · Score: 1

    For the first 36 of those issues, you need local access. Someone with intent to cause damage, who has local access could probably do more damage to the ship than they could do using the computers.

    Most of the remote issues are web based, so it might simply be an idea not to browse random websites.

    Which could be used to affect an aircraft carrier in some way?

  64. Pirated XP by wolfheart111 · · Score: 1

    Probably... ROFL... Smoke another one. :P

    --
    [($)]
  65. Are those computers Connected by Anonymous Coward · · Score: 0

    So they are run on Windows XP big deal, are those pc's connected to the net. if yes then its a big problem, if no and its a closed network then it isn't really that much of a problem unless someone brings something in. Chances are they are just using it cause its cheap easy to use and somewhat stable without appearing intimidating to the users.

  66. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    I suppose the one that left warships dead in the water don't count?

  67. What happened to the promises of 2015? by Keith_Beef · · Score: 1
    The Register reported in 2015 that "Britain's new Queen Elizabeth-class aircraft carriers will be Windows XP-free zones". Later in the article,

    The MoD can confirm that Windows XP will not be used by any onboard system when the ship becomes operational,” the spokesman added. “This also applies to HMS Prince of Wales.

    Article is here: https://www.theregister.co.uk/...

  68. Never mind XP, it's connected to the INTERNET? by Kazoo+the+Clown · · Score: 1

    The fact it's connect to the INTERNET is the height of stupidity. If it wasn't it would matter all that much what OS it uses...

    1. Re:Never mind XP, it's connected to the INTERNET? by Actually,+I+do+RTFA · · Score: 1

      What on earth makes you think that its on the Internet? Nothing in the article implies that, and it would be really stupid.

      Although the article implies its off the shelf WinXP, as opposed to the long-term support WinXP (which, e.g., was not affected by WannaCry).

      I can even see a case for the long-term support version being more secure, as there are no new features, just new bug fixes.

      --
      Your ad here. Ask me how!
  69. On a lighter note... by Opportunist · · Score: 1

    Old joke: What does a navy pilot have in common with an internet junkie?

    Both break out in cold sweat if their display shows NO CARRIER

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  70. They have the best people! by IRGlover · · Score: 1

    Hardly a surprise that it is going into service with such outdated, insecure systems. This is the Navy that genuinely put this out as a recruitment video a few years back. Now it might have been a joke from the crewman, but the ad is edited in such a way that it suggests not.

  71. Re:Is there even a word for this level of stupidit by AHuxley · · Score: 1

    re "physical access prevention"
    "Margaret Thatcher ordered troops to shoot intruders on sight after protesters boarded nuclear-armed Navy sub
    The PM was livid when three demonstrators broke into the control room of vessel carrying Polaris missiles, newly released files show"
    http://www.mirror.co.uk/news/u...

    --
    Domestic spying is now "Benign Information Gathering"
  72. Cyber Witch or Cyer Warlock by Anonymous Coward · · Score: 0

    Witches are more powerful, and if red haired, look better in TV grabs.
    But we all know women are bad luck on boats, and would impair the effectiveness
    of everything, and imperil all the other souls.

    Therefore, what is needed is a Cyber Warlock. In Startrek they even come with English accents. Is this new boat Dreadnought class?

    Seroiusly - if they had talent it wold run at least Win7. I don't think it would be a good look for telemetry to give the enemy intel on a plate.

    1. Re:Cyber Witch or Cyer Warlock by Anonymous Coward · · Score: 0

      The Navy's spokesman is Lord Haw -Haw
      https://en.wikipedia.org/wiki/Lord_Haw-Haw

  73. Re:BeauHD Flunked The Third Grade ;) by stealth_finger · · Score: 1

    Just think how fucked up you have to be to pick that as your username. Man you must have had an unhappy childhood, overbearing (maybe worse) parents? Gotta love the weird hangups and kinks of people raised by conservative christians. I'm sure having a handle called 'gay boner sex' is just a part of it.

    Most of the rest of us grew up and stopped finding differing sexualities interesting a looooong time ago. What a sad little prick you must be. Even if you're straight, which is probably debatable, you evidently think about men fucking a LOT.

    I think the point of him picking that name seems to be getting people like you up. Who gives a shit? You claim not find differing sexualities 'interesting' yet you can't help having a go at a stranger on the internet for reminding you of it. Grow up and don't feed the trolls.

    --
    Wanna buy a shirt?
    https://www.redbubble.com/people/stealthfinger/shop?asc=u
  74. Clippy the Clipper Ship by Anonymous Coward · · Score: 0

    :)

  75. One country's bug is another country's feature by TheOuterLinux · · Score: 2

    The U.S. Navy develops Tor and the Airforce, as well as several other agencies use LPS to log into places. You'd think the UK navy would be smart enough to not use Window$ anything. But, this is coming from a country that wants backdoors in everything. One country's bug is another country's feature, I guess.

  76. Re:Is there even a word for this level of stupidit by Anonymous Coward · · Score: 0

    then you better provide a citation of an exploit that was used to leave them dead in the water.

  77. Re:Is there even a word for this level of stupidit by jcr · · Score: 1

    The term I would use is "gross dereliction of duty".

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
  78. Who said by Anonymous Coward · · Score: 0

    Who said the systems will not be connected to the internet? The US naval systems that use Windows are. Or at least they were a few years ago. Windows For Warships, ver. 1.1

    Besides, I can probably dig up a quote by Microsoft saying XP is the most secure Windows ever. Of course, I can dig that up about almost every version.

  79. They have no airplanes - XP is the payload by bazorg · · Score: 1

    This aircraft carrier is so expensive that there are significant budget limitations for the rest of the Royal Navy, including the carrier group in question.

    Since they don't have any airplanes for this carrier, their plan is to reach the enemy port, plug an ethernet cable and let Windows XP do its thing.

  80. That's the problem with outsourcing ... by Anonymous Coward · · Score: 0

    But at least they are not running it in the cloud ... yet.

  81. The MOD can use up-to-date Linux by Anonymous Coward · · Score: 0

    RHEL 6 and 7 have full NIST Secuirty STIGS and are ready to go. And there's a reasonable
    chance your 10 year old software will still run.

  82. Tomorrow, somewhere in the Persian Gulf... by Randseed · · Score: 1

    "Vampire! Vampire! Track 3872 bearing 285 at 20 klicks!" "Taking out track 3872 with bird--" (Screens all over the ship turn blue with the text "A problem has been detected and Windows has been shut down to prevent damage to your computer"...) "What the bloody hell?" "Gates, you arrogant ass! You've killed us!"

  83. ..except it doesn't by JasterBobaMereel · · Score: 1

    Some contractors used Windows XP or Windows 7 on laptops but the warship uses a custom built hardened version of Windows "Windows for Warships" it is mostly based on Windows 2000 server ...

    This is much the same as the US fleet, which uses a mixture of Windows 2000 and Windows NT based custom systems ...

    --
    Puteulanus fenestra mortis
  84. Retro Gaming by puddingebola · · Score: 1

    Real reason for this decision is obvious, retro gaming. https://games.slashdot.org/sto...

  85. Pretty simple by backwardsposter · · Score: 2

    A lot of people keep calling this stupid, but it's actually pretty simple. The design started back in 2004. When you're working a rigid project like this, things get locked in once approved, like design and technology. If you postponed even whenever a new Windows came out, you'd have to go back, have a new CONOPS, new requirements, and start all over again and the project would never finish. Yes you'd get to reuse a lot of the previous architecture, but just think about it. If you're running the program, and software people tell you they're going to just use a new OS, you have a whole host of new things to think about.

    And in the government, hardware tends to drive software, so software is constantly trying to keep to the same milestones. And believe me, once you've tested, NOBODY wants to think about switching OS and libraries now. Throw in a few of the typical delays that come in the government, (funding/changing of the guard, etc...) and this all makes sense.

    So stupid? That's not really the issue here. It's choosing between a rigid process, that can't afford to do things quickly and is very risk averse...or finishing quickly. The most common mitigation to this issue is to include an update later, with newer Windows and some regression testing. You can't really win with the public these days anyway...imagine if they pushed it out quickly and the report instead said that there was a malfunction because it was a rush job. These days, you're damned if you do (spend a lot of money but this is what we get) and damned if you don't (rush job leads to malfunction leads to public embarrassment).

    1. Re:Pretty simple by Anonymous Coward · · Score: 1

      A lot of people keep calling this stupid, but it's actually pretty simple. The design started back in 2004.

      You're absolutely right.... they're computer engineers, not damn fortune tellers! It was simply IMPOSSIBLE in 2004 to foresee the problem of a proprietary OS going EOL on a ship with an expected service-life measured in decades. Where can I hire your brilliant consulting services!?

  86. This is actually great news, long term. by Anonymous Coward · · Score: 0

    The sooner hackers, (independent, extremist group, or state-run, who cares) take control of some lethal piece of military hardware and kill a few dozen civilians with it, the better. Governments and companies don't seem to be able to understand that this lack of security is a serious issue, and that running Windows or any other insecure OS on critical devices/infrastructure/machines is begging for a major disaster. Humanity in general seems to have real trouble learning any way but the hard way.

    I just hope it happens BEFORE they release some war machine armed with nuclear weapons running Windows Me or something.

  87. Virtuall retarded story by Anonymous Coward · · Score: 0

    As MS updates those XP computers. They buy special services.

  88. Re:Is there even a word for this level of stupidit by NicknameUnavailable · · Score: 0

    The die-cision to use anything from Microsoft in a mission-critical environment, let alone a 16+ year old OS with a giant list of known exploits goes so far beyond amazingly stupid I can't even find the words.

    Microsoft makes different military and civilian versions of Windows.

    It's nice you felt you had the knowledge to speak on the subject anyway. /s

  89. Re:BeauHD Flunked The Third Grade ;) by Anonymous Coward · · Score: 0

    Exactly. I mean come on. How can you have gay sex without boners.

  90. they're stupid to use Windows by Anonymous Coward · · Score: 0

    Run Linux. You can completely customize your distro for warships.

  91. Windows xp flagship ???!??? by Anonymous Coward · · Score: 0

    BWA-HA-HA-HA-HA.

    There just are not enough derogatory remarks that can be made about designing a warship around a Microsoft Windows version. Especially Windows XP of the Caribbean.

    No, No, No. It's just too wrong.

    Well, if it will run Windows XP it will run Linux, which would make a much more secure environment for the computing infrastructure of such a warship.

    Now, if you'll excuse me, I have to go catch my butt. It ran away when I started laughing.

  92. Re:Is there even a word for this level of stupidit by redmid17 · · Score: 1

    Yep things sure have come around in 28 years!

    But that's not what I meant either. I meant having physical access to the actual "box" itself. Getting onto the boat is a chunk of the battle but the ability to physically compromise the box is the most important part. Gonna be kind of hard to do that with 24 x 7 shifts running, no?

  93. Re:Is there even a word for this level of stupidit by AHuxley · · Score: 1

    Depends on the navy, the security the person has and if the buddy system can be staffed for that rank, clearance, every mission.
    After a while someone gets to be along and needs power for their USB device. They have hours and days to go looking and the need to find any USB power builds.

    --
    Domestic spying is now "Benign Information Gathering"
  94. Just postpone it for another decade... by Anonymous Coward · · Score: 0

    by then XP will literally be a thing of the past.
     

  95. Pure Insanity by argontechnologies · · Score: 1

    Using ANY Windows platform for a military application is the stupidest thing I have ever seen (yes, I've done it, but it was not tied to the world). I cannot see any reason why Linux is not the default OS for all military applications. You can make it as small as you need, or as powerful as you need. All with relative security.

    1. Re:Pure Insanity by Anonymous Coward · · Score: 0

      Maybe they are afraid that systemD would swallow all torpedo logs.

      captcha: unarmed

  96. Re:BeauHD Flunked The Third Grade ;) by amicusNYCL · · Score: 1

    It's good to see that you finally decided to create an account, APK.

    --
    "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
  97. Thank You! by Anonymous Coward · · Score: 0

    I would think that a software upgrade would be not only in order, but perhaps even expected? It would be similar to any large enterprise upgrade, requiring quite a bit of planning, testing and IT support. Not exactly trivial, but neither should it require dry-docking the fleet...

  98. Re: BeauHD Flunked The Third Grade ;) by Anonymous Coward · · Score: 0

    Gay women seem to do it just fine...

  99. Re:Is there even a word for this level of stupidit by david_thornley · · Score: 1

    That was Windows N(eeds)T(owing). This is XP. They've probably improved it to the point that it eXplodes the Propellers instead.

    --
    "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  100. Re:Is there even a word for this level of stupidit by Sir+Holo · · Score: 1

    The die-cision to use anything from Microsoft in a mission-critical environment, let alone a 16+ year old OS with a giant list of known exploits goes so far beyond amazingly stupid I can't even find the words.

    So, you're saying that a country's only aircraft carrier is a mission-critical environment? How so?

    Can't they just pop another one out within a month? A boat is a boat, after all.

  101. Re:Is there even a word for this level of stupidit by JustNiz · · Score: 1

    As a Brit i can tell you that there are MANY islamic people living in the UK as citizens, and are completely eligible to join the forces.

    Like it or not it's a fact that the UK is living in denial about many real risks since its a repeat story of young UK Muslims being brainwashed/radicalized in UK mosques. Many have in the past even gone off to fight for IS.

    Its a no-brainer that the smarter radical Imams are telling them all to get into positions of trust where they can perform Allah's will.

  102. Re:Is there even a word for this level of stupidit by JustNiz · · Score: 1

    If you think everyone on that ship cannot possibly be in any way a security threat (even unintentionally) then you are beyond VERY naive.

  103. What? You don't trust the US of A? What??? by Anonymous Coward · · Score: 0

    Think of the efficiencies gained by having the US maintain the British military - why stop with the Royal Navy? NSA wouldn't even have to intercept - there could be a 24x7 direct feed! And then of course with tRump in charge, not only would he make amerika grate again, Britain would be on track to re-establishing the empire!

  104. Re:Is there even a word for this level of stupidit by 91degrees · · Score: 1

    Of course they can be. And they don't need a computer to do so.

  105. In all seriousness by Anonymous Coward · · Score: 0

    If you are still running Windows XP in 2017, FUCK YOU.