Slashdot Mirror


The F-35's Greatest Vulnerability Isn't Enemy Weapons. It's Being Hacked. (popularmechanics.com)

schwit1 shares a report: Every F-35 squadron, no matter the country, has a 13-server ALIS package that is connected to the worldwide ALIS network. Individual jets send logistical data back to their nation's Central Point of Entry, which then passes it on to Lockheed's central server hub in Fort Worth, Texas. In fact, ALIS sends back so much data that some countries are worried it could give away too much information about their F-35 operations. Another networking system is the Joint Reprogramming Enterprise, or JRE. The JRE maintains a shared library of potential adversary sensors and weapon systems that is distributed to the worldwide F-35 fleet. For example, the JRE will seek out and share information on enemy radar and electronic warfare signals so that individual air forces will not have to track down the information themselves. This allows countries with the F-35 to tailor the mission around anticipated threats -- and fly one step ahead of them.

Although the networks have serious cybersecurity protections, they will undoubtedly be targets for hackers in times of peace, and war. Hackers might try to bring down the networks entirely, snarling the worldwide logistics system and even endangering the ability of individual aircraft to get much-needed spare parts. Alternately, it might be possible to compromise the integrity of the ALIS data -- by, say, reporting a worldwide shortage of F-35 engines. Hackers could conceivably introduce bad data in the JRE that could compromise the safety of a mission, shortening the range of a weapon system so that a pilot thinks she is safely outside the engagement zone when she is most certainly not. Even the F-35 simulators that train pilots could conceivably leak data to an adversary. Flight simulators are programmed to mirror flying a real aircraft as much as possible, so data retrieved from a simulator will closely follow the data from a real F-35.

137 comments

  1. That's two wring guesses. Try again by raymorris · · Score: 1

    Neither of those. Care to try again?

    1. Re:That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      Damn - nothing like trying to call someone out and then falling flat on your face with typos in your subject line.

    2. Re: That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      Python. A hell of a shitty language. One misplaced space in the source code could mean a whole new backdoor to let the Russians in.

    3. Re:That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      NEITH3R OF THOS31!!!!! LOL R 2 TRY AGANE???!? OMG

    4. Re:That's two wring guesses. Try again by fahrbot-bot · · Score: 2

      in C/C++?

      Neither of those. Care to try again?

      COBOL?

      --
      It must have been something you assimilated. . . .
    5. Re:That's two wring guesses. Try again by Sarten-X · · Score: 3, Funny

      Considering the size of the program, I'd be more surprised if any language wasn't involved somewhere.

      When I worked in defense, the only rules on languages for one component (a sub-contract to a sub-contract) was that it had to be more than 10 years old, with compilers still supported. I suggested INTERCAL. The engineers laughed, and my boss was pissed, but he couldn't object. I suggested Java. He was happier, but the engineers weren't. I think we settled on Perl for that component...

      --
      You do not have a moral or legal right to do absolutely anything you want.
    6. Re: That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      Typically, it is APL.

    7. Re:That's two wring guesses. Try again by Ksevio · · Score: 3, Insightful

      I'm guessing Ada - defense contractors love that

    8. Re: That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      The F35 contains a lot of C++ code, with very stringent coding guidelines.

    9. Re:That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      in C/C++?

      Neither of those. Care to try again?

      COBOL?

      ADA if the powers that be have an once of salt; C/C++/Language of month if the powers that be are penny pinching idiots.

    10. Re: That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      + enemy combatant in a foxhole with a SAM
      - 15yo kid in a basement drinking mountain dew

    11. Re:That's two wring guesses. Try again by sconeu · · Score: 3, Informative

      Mulitple languages... Ada for sure, and also C++, and probably others.

      C++ coding standards for JSF. http://www.stroustrup.com/JSF-AV-rules.pdf

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    12. Re:That's two wring guesses. Try again by 0100010001010011 · · Score: 2

      There's C++ in there, they bill it as such.

      We were once required to use a MIL-STD-1760 processor with Ada or other military languages; now we use commercial PowerPC with C++."

      source

      Here's their toolchain: https://www.ghs.com/AerospaceD...

      From RTOS to IDE to Compiler, GHS the only name in this space.

    13. Re:That's two wring guesses. Try again by Archtech · · Score: 2

      I'm guessing Ada - defense contractors love that

      People who want to fly and stay alive love Ada.

      --
      I am sure that there are many other solipsists out there.
    14. Re: That's two wring guesses. Try again by Archtech · · Score: 1

      The F35 contains a lot of C++ code, with very stringent coding guidelines.

      That explains a lot.

      --
      I am sure that there are many other solipsists out there.
    15. Re: That's two wring guesses. Try again by Type44Q · · Score: 1

      Turbo Pascal?

    16. Re:That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      People that want it to be fast use C.

    17. Re: That's two wring guesses. Try again by hey! · · Score: 1

      Emacs Lisp?

      --
      Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
    18. Re: That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      So thank god that the Ariadne flight was unmanned?

    19. Re:That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      in C/C++?

      Neither of those. Care to try again?

      COBOL?

      Is that what the Cylons were programmed in?

    20. Re: That's two wring guesses. Try again by Plus1Entropy · · Score: 1

      One misplaced space in the source code could mean a whole new backdoor to let the Russians in.

      Could you please cite this vulnerability? I'm genuinely curious.

      --
      Only crack the nuts that crack. You don't put the ones that don't crack in the sack.
    21. Re: That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      Cylons was clearly Rust. Duh.

    22. Re:That's two wring guesses. Try again by Anonymous Coward · · Score: 0

      Ada is not an acronym asshat. Learn something OK?

  2. Lockheed takes this pretty seriously by raymorris · · Score: 2

    Lockheed takes the security of this system, and all of their weapons systems, pretty darn seriously.

    1. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 1

      So do Microsoft and Intel.

    2. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Why do you think those who would target the system would take it any less serious? All it takes is _one_ slip up on the defending side.Further, the more the complexity of the system goes up, the sooner it will happen. And it _will_ happen. With mathematical certainty.

    3. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Very unlikely to be Windows based.

    4. Re: Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      So does equifax

    5. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      James Kelly from Microsoft here. The ILLEGAL F-35 is using unlicensed Linux software instead of the Lord's One True Operating System Windows 10. That's why these unauthorized tinkerers keep having problems with their ILLEGAL F-35. If you want a computer that works perfectly, use Windows 10 and Apps from the Windows Store. Otherwise, you'll have a computer with lower marketshare than Windows 10, and that's unauthorized.

    6. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Thank you for that, random citizen who is not in any way working for Lockheed's PR department.

    7. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Lockheed takes the security of this system, and all of their weapons systems, pretty darn seriously.

      Oh, that's nice. I'm sure there are no weak links.

    8. Re:Lockheed takes this pretty seriously by BringsApples · · Score: 1

      Proof?

      --
      Politics; n. : A religion whereby man is god.
    9. Re:Lockheed takes this pretty seriously by currently_awake · · Score: 1

      China has an aircraft that is said to be a copy of the F35. The plans for the F35 should be better protected than the Alis data, since they don't need to be remotely accessed.

    10. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Well, yeah. So?

      I mean, I'm sure that Lockheed takes the budget and schedule of their weapons systems "pretty darn seriously" too, and those get blown all the time. I've been reading for literally years how full schematics and plans for entire weapons systems got leaked, and I'm sure that security for those were "serious" too.

      "Serious" is one thing, and effective is another.

      Ultimately any adversary is looking for any edge or weakness they can, in times of both peace and war. I don't know if this ALIS or JRE is a vulnerability and I'm not qualified to say. What I do know is that you take any advantage you can get in war. And in peacetime you keep testing the windows and doorknobs, in case of war.

    11. Re: Lockheed takes this pretty seriously by Type44Q · · Score: 1

      The problem isn't Lockheed's seriousness; the problem is Lockheed.

    12. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      The plans were stored on a Windows server.
      Of course they were taken.

        https://arstechnica.com/information-technology/2017/10/australian-defense-firm-was-hacked-and-f-35-data-stolen-dod-confirms/

    13. Re: Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      It wasn't taken from Lockheed.

      It was stolen from an Australian company.

    14. Re: Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Oh, oh, settle down everybody! Chief Faggot raymorris says there's nothing to worry about.

    15. Re:Lockheed takes this pretty seriously by rtb61 · · Score: 1

      Obviously the idiot countries buying the F35 flying pig, take their defence a whole lot less seriously. WTF? a US corporation can control all F35s at all times, put them straight out of the air if it wants to. You totally dumb fuckers, you are not buying aircraft you are renting them, wait until the next model comes out, the current model will fall out of the sky like nobodies business. Seriously what are you stupid fuckers thinking.

      --
      Chaos - everything, everywhere, everywhen
    16. Re:Lockheed takes this pretty seriously by liquid_schwartz · · Score: 1

      Lockheed takes the security of this system, and all of their weapons systems, pretty darn seriously.

      Then how did this happen? https://en.wikipedia.org/wiki/...

    17. Re:Lockheed takes this pretty seriously by arglebargle_xiv · · Score: 1
      They're serious about software update security, I've seen the manual, it's just:

      curl -sSL https://firmware-upgrade-f35.lockheed.com/ | bash

      As you can see, they use SSL, so it's perfectly safe.

    18. Re:Lockheed takes this pretty seriously by Anonymous Coward · · Score: 0

      Until that is evidenced in combat "Lockheed takes this pretty dam seriously" is nothing but marketing-speak.

      And there is very little reason to suspect this aircraft will perform well in combat. In fact, the evidence already suggests otherwise.

      It's advantage is not in performance but in keeping ahead of the curve with technological tricks -- which means its margin of outperformance will degrade over time.

      And that time may already be up.

  3. Greatest? by mi · · Score: 4, Insightful

    The F-35's Greatest Vulnerability Isn't Enemy Weapons. It's Being Hacked.

    Although we should not discount the danger of such hacks, I doubt, it is the greatest vulnerability of the weapon.

    TFA goes to great length explaining the potential dangers, but offers no justification for using "the greatest" in the title... Seems like a cheap sensationalism...

    --
    In Soviet Washington the swamp drains you.
    1. Re:Greatest? by PPH · · Score: 2

      Not by a long shot. The greatest vulnerability would be fueling an F-35 from a truck painted something other than white.

      --
      Have gnu, will travel.
    2. Re:Greatest? by DCFusor · · Score: 1

      How can you hack something that doesn't even always run as it is? Did ALIS suddently start working and become highly available? Last I heard....not so much.
      You gotta fly before you can crash. (but you can burn without flying!)

      --
      Why guess when you can know? Measure!
    3. Re:Greatest? by Nidi62 · · Score: 2

      The F-35's Greatest Vulnerability Isn't Enemy Weapons. It's Being Hacked.

      Although we should not discount the danger of such hacks, I doubt, it is the greatest vulnerability of the weapon.

      TFA goes to great length explaining the potential dangers, but offers no justification for using "the greatest" in the title... Seems like a cheap sensationalism...

      Right now the biggest danger to the F-35 fleet are pilots passing out due to oxygen flow issues.

      --
      The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
    4. Re:Greatest? by Anonymous Coward · · Score: 0

      2012 called they want their F35 problems back...

    5. Re: Greatest? by Type44Q · · Score: 1

      it is the greatest vulnerability of the weapon.

      Nope, that would likely br gravity. Pedantic much?

    6. Re:Greatest? by Anonymous Coward · · Score: 0

      Your boss appreciates the astroturfing, I'm sure. Many of 2012's problems aren't yet solved.

    7. Re:Greatest? by Anonymous Coward · · Score: 0

      That was a simple fix nothing to worry about.

      The real issue is that 30 and 40 year old planes are not only outperforming it there doing it no matter the pilot skill levels.
      The best pilots are loosing dogfights in the JSF to the worst pilots in the air.

      The world wanted a "do everything" platform and they got it in spades.

  4. Speculation as Story? by Anonymous Coward · · Score: 0

    The only piece of fact in this article is that there are two networks. Everything else is hysteria and buzzwords. Yes, networks are potential hackable. I expect this bullshit from popular mechanics, but doesn't Slashdot have some actual story to post dupes of?

  5. another msmash pos by Anonymous Coward · · Score: 0

    lets make up shit and call it an article. this "could" happen, that "could be done". ffs get some real news. just because you use the word hack in the article, does not automatically make it tech news.

  6. Lots of "coulds" and "maybes" in that headline by Anonymous Coward · · Score: 0

    nt

  7. A non-story by Sarten-X · · Score: 4, Insightful

    TFA reads like FUD. If I were trying to sell my services as a cybersecurity contractor, this is the kind of crap I'd write. Essentially, it boils down to "complexity is bad", and "wireless is scary".

    I've worked defense contracts. They're always trying to "shore up vulnerabilities", and always making a big deal about every tiny detail that isn't perfectly in compliance with a rule written for an entirely-different scenario. Exceptions are the norm. That doesn't mean the system is actually vulnerable to any attack, or even that a possible attack would be successful.

    Now, I'm not suggesting that anyone stop looking at security, especially in such important systems... I'm just saying that shouting about generic insecurity doesn't improve anything, and in fact makes things worse by encouraging a checklist-based approach to compliance.

    --
    You do not have a moral or legal right to do absolutely anything you want.
    1. Re:A non-story by Anonymous Coward · · Score: 0

      It's OK... I got this.

      ssh root@f35.secret.air.us.gov
      f35> systemctl enable firewalld
      f35> systemctl start firewalld

      America saved!

    2. Re:A non-story by Drethon · · Score: 3, Interesting

      TFA reads like FUD. If I were trying to sell my services as a cybersecurity contractor, this is the kind of crap I'd write. Essentially, it boils down to "complexity is bad", and "wireless is scary".

      I've worked defense contracts. They're always trying to "shore up vulnerabilities", and always making a big deal about every tiny detail that isn't perfectly in compliance with a rule written for an entirely-different scenario. Exceptions are the norm. That doesn't mean the system is actually vulnerable to any attack, or even that a possible attack would be successful.

      Now, I'm not suggesting that anyone stop looking at security, especially in such important systems... I'm just saying that shouting about generic insecurity doesn't improve anything, and in fact makes things worse by encouraging a checklist-based approach to compliance.

      I don't know how the F-35 handles network security, but I found this a fascinating read for network security for a military UAV prototype helicopter: https://journals.plos.org/plos...

    3. Re:A non-story by Anonymous Coward · · Score: 0

      You've just locked out everyone, effectively disabling the entire network - global fleet is grounded, and you can't login back.

  8. IOT on a new level by kiviQr · · Score: 1, Funny

    I did not know that F35 were considered IOT devices. Any one has a link to live webcam?

    1. Re:IOT on a new level by Anonymous Coward · · Score: 0

      I, personally, have always used IoT to mean embedded systems that are connected to the internet. While these avionics systems are likely to be on a private, protected network, I'm sure there is a communications pathway from all those systems to the internet. I'd call that IoT.

    2. Re:IOT on a new level by Anonymous Coward · · Score: 1

      If the avionics systems are connected to the internet that is called:

      Id1oT.

    3. Re: IOT on a new level by Type44Q · · Score: 1

      Any one has a link to live webcam?

      Fuck that; how about RC/FPV with our Fat Sharks?

  9. TAHTS TWO WRNG GUAS3S!11!! OMG TRY AGANE (SCOR32) by Anonymous Coward · · Score: 0

    NEITH3R OF THOS31!!!!! LOL R 2 TRY AGANE???!? OMG

  10. I wonder if I can use Shodan to find F-35s by sinij · · Score: 3, Funny

    I wonder if I can use Shodan to find F-35s?

    1. Re:I wonder if I can use Shodan to find F-35s by grep+-v+'.*'+* · · Score: 1

      I wonder if I can use Shodan to find F-35s?

      You COULD, but they're not there if you look, only if you ping. And if it's flying greater than Mach 1 even that'll be in the wrong place. ;-)

      --
      If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  11. Blueprints have same vulnerability by Anonymous Coward · · Score: 0

    So remember, don't write anything down ever, cause someone could get it and analyze it for flaws.

  12. Cloud services suck ass by rtkluttz · · Score: 1

    Everywhere

    --
    Digital is, by definition, imperfect. Analog is the way to go.
    1. Re:Cloud services suck ass by Anonymous Coward · · Score: 0

      Every single air force plane in history has always used cloud services.

  13. Nah by argStyopa · · Score: 1

    It's greatest vulnerability? Its own cost.

    At $85 million per plane, that probably resulted in several hundred aircraft that were supposed to be purchased, never being bought - far more than will ever be brought down in combat.

    --
    -Styopa
    1. Re:Nah by Dorianny · · Score: 2

      It's greatest vulnerability? Its own cost.

      At $85 million per plane, that probably resulted in several hundred aircraft that were supposed to be purchased, never being bought - far more than will ever be brought down in combat.

      The only comparable Fighter is the Advanced Super Hornet F/A-18F and Boeing is pricing it at $80 million. Not exactly tremendous savings

    2. Re:Nah by sycodon · · Score: 1

      The planned acquisitions is in the thousands (2,443).

      The more that are bought the cheaper they become as sunk costs are recovered.

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    3. Re:Nah by Anonymous Coward · · Score: 0

      Don't forget first 50 (100?) are so broke they aren't even going to fix them...

    4. Re:Nah by currently_awake · · Score: 1

      It's not $85 million. The current design has hundreds of critical flaws that must be fixed, and Lockheed won't do that for free. Expect to pay another $100 million for repairs to get a working aircraft.

  14. Crash and Burn by PopeRatzo · · Score: 1, Offtopic

    What we spent on these stupid fucking planes that we're never going to use would be enough to pay for universal health care AND shore up social security for decades to come.

    I mean, as long as we're borrowing the money anyway, can we please invest it in people and not dumb shit?

    --
    You are welcome on my lawn.
    1. Re:Crash and Burn by Anonymous Coward · · Score: 0

      Defense is the FIRST and most important function of the Government.

      The LEAST important function is providing you fuckers with Free Shit.

    2. Re:Crash and Burn by PopeRatzo · · Score: 2

      Defense is the FIRST and most important function of the Government.

      The F-35 has nothing to do with "defense".

      --
      You are welcome on my lawn.
    3. Re:Crash and Burn by Anonymous Coward · · Score: 0

      Do you just spend your days huddled in your bunker peeking out through your peeky hole at the big scary world, waiting for "them" to come and get you?

    4. Re: Crash and Burn by Type44Q · · Score: 1
      Unless they get hit on the ground, they'll see use.

      Unfortunately.

    5. Re: Crash and Burn by Type44Q · · Score: 1
      I'm not so sure about that; VTOL capability, more than anything else, means far less vulnerability due to runways getting destroyed.

      Pretty sure that's a defensive matter...

    6. Re:Crash and Burn by Anonymous Coward · · Score: 0

      No it wouldn't.

      The F35 has an expected $857 billion full life cycle cost over 53 years. That's about $16 billion per year. The total US federal budget in 2016 was $3.9 trillion dollars. That year alone, US federal healthcare spending accounted for $1 trillion dollars or 26% of the entire budget. Social security accounted for another $916 billion or 24% of the entire federal budget. That's for the currently system that US has, flawed as it is.

      The F35 has it's problems. Saying that we could buy everyone healthcare for the price of the F35 program is flat out wrong.

    7. Re:Crash and Burn by Anonymous Coward · · Score: 0

      Maybe it would. But I see no reason to skimp on the military in order to feed the parasites. I'd rather they just took the money and burned it.

    8. Re:Crash and Burn by PopeRatzo · · Score: 1

      But I see no reason to skimp on the military in order to feed the parasites.

      But what if the military and military contractors are actually the parasites?

      --
      You are welcome on my lawn.
    9. Re:Crash and Burn by PopeRatzo · · Score: 1

      The F35 has an expected $857 billion full life cycle cost over 53 years.

      Since the F-35 first hit the drawing board in 1992, I'm not sure where the "53 years" comes from. Maybe you're using military math.

      Plus, when did you ever hear of a military program that actually came in at it's expected expenditure? Originally, the price tag for the F-35 was supposed to be about $50 billion. We're up to $857 billion and counting (and that's a very conservative estimate).

      --
      You are welcome on my lawn.
    10. Re:Crash and Burn by Anonymous Coward · · Score: 0

      The F35 program is expected to end in 2070 (previous expectation was 2064), although I do apologize, looks like I was reading off of outdated information. Expected life cycle cost is $1.502 trillion all said and done in 2070 (just going off of Wikipedia for now but these numbers sound more reasonable)

      http://www.jsf.mil/news/docs/20160324_Fact-Sheet.pdf

      US$1.508 trillion (through 2070 in then-year dollars):
      * $55.1B for RDT&E
      * $319.1B for procurement
      * $4.8B for MILCON
      * $1123.8B for operations & sustainment

      The point does still stands. The entire F35 program from now to 2070 isn't going to pay for decades of universal healthcare and social security. Not even close.

    11. Re:Crash and Burn by PopeRatzo · · Score: 1

      The F35 program is expected to end in 2070

      Seriously, the F35 program will be 80 years old in 2070. Do you really think the F35 will still be viable sixty years from now? For comparison, the F8 Crusader's lifespan was 45 years from first flight to when it was retired.

      Let's not bullshit: The F35 program is not about the F35 being used by the military, but being sold by Lockheed Martin. It was a taxpayer-funded boondoggle from the beginning. There are moral and practical arguments for why universal health care would be good for the country (and its citizens). There are no such arguments for the F35.

      --
      You are welcome on my lawn.
    12. Re:Crash and Burn by Anonymous Coward · · Score: 0

      >Seriously, the F35 program will be 80 years old in 2070. Do you really think the F35 will still be viable sixty years from now? For comparison, the F8 Crusader's lifespan was 45 years from first flight to when it was retired.

      Assuming there isn't another major conventional war that forces major shifts in tactics, or some other major development in weapons technology? It's certainly possible. The F-35 is in low rate production at the moment but full manufacturing is expected to run until around the late 2030's, assuming that there aren't more orders for F35s between then and now which causes the F35 production line to stay open. Remember, the F35 as a platform has plenty of room for upgrades and with those large numbers spread across a dozen countries it becomes more economical to simply develop weapons using the F35 as a delivery platform. And it's intended to replace a half dozen other aircraft; namely the F16, F18, AV8 and the A10.

      > There are moral and practical arguments for why universal health care would be good for the country (and its citizens). There are no such arguments for the F35.

      One of the major roles of government is mutual defense of the citizens from external threats. The F35 does play into US defense policy. It was always intended for export to allied nations ,the same nations that will be in the front line should another conflict start brewing, and the same ones that would have to be the first to war should Article 5 of NATO be invoked.

      And again, you're looking at incomparable pricing which was my main point. The F35 program spending isn't comparable to healthcare or social security spending. Criticize the F35 for it's actual sins; over budget, behind schedule, under performing, and it's numerous design compromises to make it a one size barely fits all solution. Saying that single fighter program could somehow fund the entirety of US healthcare is wrong and social security is baseless and wrong.

    13. Re:Crash and Burn by PopeRatzo · · Score: 1

      Assuming there isn't another major conventional war that forces major shifts in tactics, or some other major development in weapons technology?

      Major shifts in tactics aren't forced by conventional wars, but by asymmetric warfare.

      One of the major roles of government is mutual defense of the citizens from external threats.

      Our military budget hasn't been spent on the mutual defense of the citizens from external threats for at least 70 years. Some would say that the last time the US military defended US citizens from external threat was more like 150 years ago. So your argument is completely irrelevant to the F-35. It will not be used to defend US citizens. Ever.

      Saying that single fighter program could somehow fund the entirety of US healthcare is wrong and social security is baseless and wrong.

      That's actually not what I said. I'm saying it would fund the difference between what we're spending now on health care and what universal health care for all Americans would cost and still have enough left over to make Social Security solvent for many decades.

      --
      You are welcome on my lawn.
  15. Re:Let me guess, the system is written by DickBreath · · Score: 1

    Some dialect of BASIC maybe?

    --

    I'll see your senator, and I'll raise you two judges.
  16. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  17. Power Mac G4s in the Sky. by 0100010001010011 · · Score: 5, Informative

    It's more or less a PowerPC G4 right down to the Firewire bus.

    Components were billed as "COTS". However those chips were still back when they were Motorola/Freescale

    The system departed from the historical use of low speed Mil-Std-1553B busses, using the high speed Fibre Channel-Avionics Environment (FC-AE) serial bus for high speed internal interconnects.

    built around PowerPC RISC processors - essentially a bigger and faster cousin to the 6U VME packaged PowerPC processors now being used in F-15E, F/A-18E/F and F-111C Block C-4.

    "So we have designed for technology refresh, so at the appropriate time we can stop putting in the 1 GHz processor board and swap out to the 2 GHz board without having to go back and do any redesign. We were once required to use a MIL-STD-1760 processor with Ada or other military languages; now we use commercial PowerPC with C++."

    http://www.ausairpower.net/APA...

    https://www.militaryaerospace....

  18. Not entirely accurate by Anonymous Coward · · Score: 0

    The biggest threat to the F-35 is the F-35.

  19. Slashdot cannot be the first to consider all this by Aristos+Mazer · · Score: 2

    I find it impossible to believe that this is the first time any of these concerns have been brought up. Lockheed has a lot of very savvy and security-conscious engineers. Yes, the networks might be vulnerable to hacks. The question is whether that risk downside is worth the upside of these highly networked machines (say, avoiding friendly fire). I don't know what those tradeoffs are, but this article lacks any analysis of why these security risks were considered acceptable and what is done to mitigate them. Without that balancing content, this is just FUD and useless blather.

  20. JRE? by Anonymous Coward · · Score: 0, Flamebait

    Well shit. That's your problem right there.

    1. Re: JRE? by Anonymous Coward · · Score: 0

      No. We used punch cards made of asbestos and we punched them with our teeth. We all had steel-capped teeth for the purpose. And we LOVED it goddamit!

  21. JRE? by cormandy · · Score: 2

    The f15 was programmed using Java?????

  22. Re:I am a little suspicious of this by PPH · · Score: 4, Interesting

    Not constantly. This is a ground maintenance function. But if it can be monitored, an enemy can gain some valuable information about the status of your forces. And if it can be hacked, that enemy could effectively ground all your planes pending unneeded maintenance*.

    *"I've just picked up a fault in the AE-35 unit. It is going to go 100 percent failure within 72 hours."

    --
    Have gnu, will travel.
  23. Re:I am a little suspicious of this by Anonymous Coward · · Score: 0

    Hint: It transmits UP.

  24. F35 Now allows you to login with Facebook! by Anonymous Coward · · Score: 0

    Only after you agree to the EULA.

  25. Give me an A-10 anyday by neo-mkrey · · Score: 3, Insightful

    "It Just Works"

  26. Too expensive to risk Ground Support. by Zorro · · Score: 1

    Yeah can't EVER get down to visual range or it will get bagged by a $100 MANPAD or a 12.7 MM machine gun.

  27. Comment by Anonymous Coward · · Score: 0

    So what you're saying is, is that the F-35 program comes with an On-Star, so that its value will diminish (even more) if the servers are ever taken offline by the parent company? Great, you can't even buy a military aeroplane these days without a phone-home program.

  28. When China starts flying, they'll send data to LM by Anonymous Coward · · Score: 0

    When China starts flying their clone, they'll send data to Lockheed/Martin.
    Win-win. /s

    Payback for the free Chinese VPNs, Chinese smartphones sending data to the home-land, and all the other corporate espionage they do.
    I just want someone to get China to stop sending spam to my email servers.

  29. Over teched by Anonymous Coward · · Score: 2, Interesting

    I think were developing stuff that is over teched to a point of being fragile in a way. Especially in military environments you have to wonder how these incredibly technical machines can ever survive a war?

  30. Bleeding edge [Re:Nah] by Tablizer · · Score: 2

    Our military has traditionally accepted "ahead of the curve" jet designs, expecting that manufacturing and technology will eventually catch up. The theory is that you have to stay at least one step ahead of the enemy, otherwise your kill ratio will be close to 1-to-1.

    While this philosophy has mostly worked, it has hippucced from time to time. The F-35 may be one of these hiccups.

    For example, our planes had difficulty during the early phases of the Vietnam war because it was felt that air-to-air missiles would render dogfights obsolete, and our planes were designed with this assumption in mind. However, the missiles proved buggy, and the Soviet planes used their maneuverability against our planes and the missiles.

    A combination of better missiles and improved training in "team based" tactics eventually overcame most of these problems, but we took a beating for a good while.

    It could be argued the philosophy pays off more than it doesn't such that we should stick with it. However, we will get occasional expensive duds and/or whippings along the way.

    1. Re: Bleeding edge [Re:Nah] by Type44Q · · Score: 1

      improved training in "team based" tactics

      NAS Miramar...

    2. Re:Bleeding edge [Re:Nah] by phantomfive · · Score: 1

      For example, our planes had difficulty during the early phases of the Vietnam war because it was felt that air-to-air missiles would render dogfights obsolete, and our planes were designed with this assumption in mind

      Note this is also the assumption of the F-35 design.

      --
      "First they came for the slanderers and i said nothing."
    3. Re:Bleeding edge [Re:Nah] by Comrade+Ogilvy · · Score: 1

      Missile guidance systems have gotten better and better with every decade. Flares can still confuse some dirt cheap systems, but how do you fool a well designed phased array radar? It is not the 80s anymore: Russia and China have access to excellent computer technology to build their guidance systems with. What they sell to the highest bidder today is both more lethal and cheaper than

      The bigger question is whether a big expensive craft carrying a pilot makes sense when you might have better mission capability with drones.

      And drones do not come home in flag draped caskets.

    4. Re:Bleeding edge [Re:Nah] by phantomfive · · Score: 1

      It makes sense still to have a pilot because larger countries have the capability to jam GPS and other wireless signals.

      --
      "First they came for the slanderers and i said nothing."
    5. Re:Bleeding edge [Re:Nah] by tinkerton · · Score: 1

      The ahead of the curve design is a euphemism for 'far too long development cycle'. In a rapidly changing environment it does not make sense to try and look decades ahead. In a short development cycle you can be allowed to have duds. Long development cycles are too big to fail.
      With the F35 the all-in-one approach exacerbates those weaknesses. The development process becomes bigger and the compromises become bigger.
      Except of course if you consider that these things are built to make money but not ment to be used in an actual conflict which tests their capabilities. Instead they get used to to things which can be done better by planes at a fraction of the cost.

  31. Any port in a storm by Anonymous Coward · · Score: 0

    This is msmash shouting "hacked!" for the clicks.

    The problem with the F35 is that it's a giant boondoggle, ment to cost a lot and deliver little. It performs as intended.

  32. Glassdoor by raymorris · · Score: 1

    With Glassdoor you can see them hiring a lot of experienced security professionals, and see what the pay is, along with the qualifications they expect of everyone working on the system.

    That's all from ONE open source intelligence resource, which anyone can see in less than 20 minutes.

    If you happen to be a 20-year career veteran in the security space, working 25 minutes Lockheed headquarters and hanging out with their engineers at ISC2 meetings every month, you can really get to know their security culture if you're paying attention.

      You can then easily position yourself, over the next 12 months, to have exactly the knowledge and references they'd like to see in a new hire, giving you an excellent backup plan whenever you decide to quit your job at $major_security_company.

    1. Re:Glassdoor by BringsApples · · Score: 1

      I get your point, but I also work with a bunch of guys that are, on the surface, very intelligent and professional. They make a lot of money, and they seem happy with their lives. However this in no way seems to help them make good decisions when it comes to very basic operations in the work environment. When it comes to egos and personal interests, those things tend to forbid common sense.

      Sometimes, here at work, I feel like our ticketing system runs the same course as slashdot discussions. And the output from it is about as equal. We're not a security company, and I know that matters. I'm just pointing out that just because you met the people, you like them and they like you, doesn't mean that you can attest for the level of security accomplished there. For all you know, they're stuck in an echo-chamber like many other companies.

      Of course, there's also the chance that I also know nothing about their security and that it's comparable to Ft. Knox. Hopefully the latter is true, for the sake of our military overlords.

      --
      Politics; n. : A religion whereby man is god.
  33. Oh dear, too late... by Archtech · · Score: 1

    "As the plane finally reaches full production, the Air Force is racing to plug holes that could allow hackers to exploit the jet's connected systems—with disastrous results".

    Major fail.

    Security cannot be added like a bag on the side, as an afterthought. Since Mr Mizokami evidently thinks it can (as far as one can judge from his breathless prose) it's pretty obvious he doesn't know much about software or security.

    --
    I am sure that there are many other solipsists out there.
  34. And heres me thinking its greatest vulnerability by Anonymous Coward · · Score: 0

    And heres me thinking its greatest vulnerability is reliability, any military machinery which is not in service is useless, whether you have 500 or 1000 aircraft is inconsequential if they are not serviceable.

  35. I see what you did there by William+Baric · · Score: 1

    so that a pilot thinks she is safely outside the engagement zone when she is most certainly not

    She? Considering that very few women have the physical aptitudes to become fighter pilots, considering that men will always be the best fighter pilots, I think the pronoun "he" should be used here. Seriously, can feminists stop trying to shove their crap down everyone's throat?

    1. Re:I see what you did there by Anonymous Coward · · Score: 0

      Yeah feminists are constantly trying to shove their engorged members down mens throats. Then they lube up and peg men deep and hard, over and over and over again until the logic of their fallacies EXPLODES all over mens open and willing faces.

    2. Re:I see what you did there by Anonymous Coward · · Score: 0

      so that a pilot thinks she is safely outside the engagement zone when she is most certainly not

      She? Considering that very few women have the physical aptitudes to become fighter pilots, considering that men will always be the best fighter pilots, I think the pronoun "he" should be used here. Seriously, can feminists stop trying to shove their crap down everyone's throat?

      If it were only feminazis, we might have a hope. But the world is full of white knights who think that if they just chant the same mantra, she'll maybe let them stick it in.

  36. Let's not forget the worst enemy the date line ;-) by Lennie · · Score: 1
    --
    New things are always on the horizon
  37. RAY MORRIS = CAUGHT LYING NAZI FAGGOT PROPAGANDIST by Anonymous Coward · · Score: 0

    RAY MORRIS IS A LYING NAZI FAGGOT - https://tech.slashdot.org/comments.pl?sid=12520486&cid=57184660 - caught DEAD pushing debunked propaganda after being corrected. HANG THIS FAGGOT RAY MORRIS.

  38. Nuke all hackers by Anonymous Coward · · Score: 0

    Premtive strike to the rescue. Problem solved.

  39. Half right - Emacs and systemd. Seriously though by raymorris · · Score: 1

    It's written as Emacs and systemd modules. Nothing to worry about here!

    In all seriousness, I was actually thinking of a different security contractor in town when I posted that. Lockheed asks F-35 candidates to know some of the following:

    Go
    Python
    Java
    Assembly
    C / C++

    The original post was actually somewhat correct.

  40. Management priorities + technical skills by raymorris · · Score: 2

    I figure management sets the overall tone and priorities, the culture. Management values security.

    Their people have the ability and interest to deliver security.

    So there is a pretty good chance that they do a good job. Lockheed isn't a customer of ours, so I haven't done a security audit of them. I do have enough information to make an educated prediction or hypothesis.

    Of course that's relative to other companies. We do have banks as customers, so I know how bad / good some banks are regarding security. Overall, the software industry sucks at security and reliability. We need about four times as many *engineers* in the roles that have job titles like "senior software engineer". Engineering means designing things to meet known requirements based on proven design methods. Software is often built with little or no engineering involved.

    1. Re:Management priorities + technical skills by pnutjam · · Score: 1

      I work for a small to midsize company that sells to enterprise customers. They are always poking at our security and making us do audits, normally in ways that degrade things.
      The open source stuff we use doesn't check their boxes and we end up shelling out for stuff that doesn't improve our security and adds another layer of integration (which of course degrades security).
      We're usually dealing with an HR style department so the hardest thing for companies to understand (aside from linux), is that security relies on culture as much as tools.

  41. Maybe that's why. Maybe the Iran air force by raymorris · · Score: 1

    We don't know how that happened, unfortunately. We do know the Iraqi air force had Russian-built fighter jets, so they certainly have the ability to shoot an aircraft down. They have have aerial refueling capability, the ability to fly precisely next to another aircraft and give it fuel, or even drop a cargo net on it.

    The primary navigation system is inertial guidance, explicitly because spoofing GPS is pretty easy, so GPS spoofing wouldn't be a possibility that would be expected to work.

    It *could* have had programming that said basically "if all your sensors are totally confused and you don't know what to do, land". The hobby version I designed and built does that. Then Iran and their allies would have needed to muck with the onboard gyroscopes and other sensors somehow.

    What we I do have evidence of is that years later, Lockheed takes security seriously.

  42. No benefit over drones by Anonymous Coward · · Score: 0

    Every time i point out that fighter planes with cockpits are obsolete, someones gotta jump in there with "but drones can be hacked so we'll always need manned fighter planes"

    Well thanks to lockheed, our fighter planes are just as vulnerable to hacking as any drone, perhaps more so.

  43. "each user helps improve the system for others" by jago25_98 · · Score: 1

    Info-cartoon highlight:
    "The system is unique because each user helps improve the system for others."

    Wouldn't it be great if you could write messages to other users:
    "Hi infidels. So glad we're finally using the same technology as you now. We've submitted so much feedback on the system but we've noticed maybe you need to contribute more. Perhaps we could get together over a coffee sometime? Lots of love, (insert evil dictator here)"

    I just love this. It seems like something that was specifically designed by a techie smart enough to know war is stupid and boy, did they do a great job of building bridges. Or maybe life just imitates art with a bit of serendipity.

  44. Did They Not Watch Battlestar Galactica? by Anonymous Coward · · Score: 0

    Before they crammed this thing full of hackable components?

  45. You forgot... by Anonymous Coward · · Score: 0

    sand, and rain, and the sun, and heat.

  46. Cui Bono? by Anonymous Coward · · Score: 0

    This plane must be looked as any device that is connected to a network. Network-connected devices are most easily accessible and EXPLOITABLE from within the network. Only those within the death cult running the military's most sacred networks would know best how to exploit the F-35. 1.4 trillion TAX dollars were spent to come up with a plane that can be hacked by the maker only to be blamed on [insert Iran/Russia/China/other bogeyman] Grizzly Steppe-psyop-style.

    Who do you think benefits most from that? Of course, Lockheed. Lockheed has gotten "too big to fail" (a euphemism for being integral to the continuity of government that the banksters UN imposed through Dick Cheney). It will get more "contracts" (money stolen from citizens through the tax theft grid) to improve their fuck-ups. History will look back on the people who keep believe in this shit, not the liars who want to rewrite history as they go along.

  47. There are no vulnerabilities by Anonymous Coward · · Score: 0

    There are no vulnerabilities. Lockheed used the best Chinese security specialists available to ensure the integrity of its systems.