Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Computer hacking as a new battlefield is inevitable if not already a reality.

Much like how at one time in the US there was no Air Force and airplanes were part of the Army, right now there is no Cyber Force and hackers are part of the Air Force. If computers really are a new theater of war, there probably needs to be a new branch of the military to recruit, train, and deploy new kinds of hacker-soldiers.

The hacking operations of the Chinese right now are like American high-altitude spy planes and satellites flying with impunity over the China and the Soviet Union during the Cold War. The longer the US delays to enter the cyber arms race the more it risks conceding dominance for the foreseeable future.

I could actually see a lot of positive economic synergy if the United States were to establish a Cyber Force to recruit and train computer security specialists.

EDIT: I recognize the US does have a Cyber Command. It's in the Air Force. The point is it's under-funded, understaffed, and under-publicized. Recruitment is pretty much limited to a handful of people already in the Air Force with computer backgrounds. There are no commercials on TV or recruitment offices to tell people to join the hacker corps like there are for the other military branches.

Mixing geeks with paratroopers isn't effective. The US needs a new branch that can make its own rules, recruitment standards, and awards to be truly effective in a different kind of war.



> The longer the US delays to enter the cyber arms race the more it risks conceding dominance for the foreseeable future.

I thought that the US was not only the founder of cyber war fare but far and away the leader in it.

http://en.wikipedia.org/wiki/Stuxnet


Stuxnet was Israeli, from what I understood.

That said, I'm pretty sure that if it's anywhere, it's hidden in the NSA or CIA instead, and that they're pretty damn good.


It can take one brilliant person to bild Stuxnet.


There's strong indications that Stuxnet was built by a team of developers, though.


The rhetoric of "battlefield" is over-done and unhelpful.

The US National Security Agency is a world leader if not the world leader in signals intelligence. Signals intelligence has been part of military intelligence for a long time (and military intelligence has alway been, uh, part of the military too for what its worth). It's well known how cracking encryption helped the US win WWII. It never stopped after that.

You and I don't know all details of how this works because naturally (for good or ill) that's how they operate (they being the NSA, NRO and the vast multitude of secret agencies out there).

You think someone histrionically describing signals intelligence as "a battlefield", saying "we need a Cyber Force, this is 'War!" makes much of a difference in the massive, massive investment and resources the US is now very actively using??


Signals intelligence and counter-intelligence is a narrow view of how computers can impact the battlefield. While the NSA and CIA may have some capability beyond listening in on enemy communications, I question whether the responsibility to make attacks on foreign targets which could be considered acts of war should be left separate from the military.

Weaponizing computers can have a much broader use that would be appropriate for a Cyber Force in addition to military intelligence operations. For example, today we might want to knock out a communications array, a factory, or a power plant in enemy territory. Our options at the moment are to send in missiles, bomber jets, or an elite ground unit. But those aren't always good options. The missiles and bombs could cause unwanted collateral damage to civilians. Missiles and bombers are crazy expensive and so is the cost to get them to the target. The risks to using an elite ground unit are enormous not only to the unit itself but to foreign policy if they are killed or captured.

But a Cyber Force could electronically disrupt or disable a facility through any number of means. This would be far cheaper in terms of financial and human costs. Even if there are counter measures in place for the facility to run offline on a private grid, such an attack could sufficiently hinder it until it can be disabled more permanently.

This is no different than sending a bomber jet instead of an infantry platoon. The goal is to make a surgical strike, the generals need to choose the right tool for the job. For an increasingly large class of technologically advanced targets in increasingly urban areas the military will more often want to employ hackers instead of bombers.

The point, then, was that this will be equally true for enemies wishing to attack the United States. A dedicated team of hackers can easily cause as much or more damage than a fleet of bombers. And the United States can either be ready for it or watch as enemies walk over them with impunity like the United States air force flies over enemies today.


>there probably needs to be a new branch of the military to recruit, train, and deploy new kinds of hacker-soldiers.

Agree, but I'd suggest it likely that this branch is already well-established and operational, if hidden from the public eye.


I imagine this is a very large portion of NSA operations.

There's no need for "cyber command" to really be part of the military. There's no need to put hackers through boot camp, or make 'em wear uniforms, or salute... it would bring down the average quality of the hackers and the average quality of the military. Far better to fold it under the roof of the intelligence agencies.


On the the contrary. Military discipline developed from the necessity of training reliable soldiers who don't question critical orders. Independent thinking is an admirable trait, but knowing your soldiers wont leak information is crucial.

In Israel there is a mandatory draft. Every soldier goes to boot camp and units like 8200 have strict military structures. (Success is hard to measure, but Israel's high tech industry is some indication of the benefits of military discipline.)


On the the contrary. Military discipline developed from the necessity of training reliable soldiers who don't question critical orders. Independent thinking is an admirable trait, but knowing your soldiers wont leak information is crucial.

The CIA and NSA have... (goes to look it up)... uhh, some large but undisclosed number of employees. They seem to do a perfectly good job of keeping secrets without needing full-on military discipline.

I'm not actually saying that military training would make anyone a worse hacker, though, I'm just saying that the need for military discipline would limit the number of people (especially in that particular demographic) who wanted to sign up. I have no doubt some of the NSA's best hackers are completely unable to do a single chin-up.


> unable to do a single chin-up

To say nothing about the willingness to salute someone who just learned they can copy and paste text.


Military discipline developed from the necessity of training reliable soldiers who don't question critical orders.

Military discipline was a necessity to get a company, a battalion, and larger units to work together at all. Strict organization is necessity as chaos is unmanageable with traditional communication means.

Modern organizations have moved on from rigid, hierarchal organizational models to network-centric models. Even military organizations have moved to this direction (discipline and military courtesy is still maintained).

Success is hard to measure, but Israel's high tech industry is some indication of the benefits of military discipline.

High tech industry has been proved to benefit from military funding. Israel spends larger portion of its GDP to (military) R&D than any other nation.


Please take this as a quote and as tongue-in-cheek, but during my (very limited, I know that I'm not representative) military services the 'US grunt' was one of the things our superiors made most fun of.

'Follow orders blindly' (which is more or less the thing we're arguing about) was actively discouraged from the leadership.

Is this good? How can I tell.. But since I started out biased (i.e. with a working brain) I did enjoy that part of my service.


I didn't explain myself well. My goal wasn't to suggest that the Israeli army teaches soldiers to blindly follow orders - by all accounts the opposite is true. Rather, I was addressing the grandparent post's derisive comment about teaching soldiers to salute, respect authority, and generally behave in a disciplined manner.


So by this idea, then PFC Bradley Manning is a soldier trained to not leak information? He is the guy who sent wikileaks a large pile of confidential information.


Well, one out of several hundred thousand is a pretty low failure rate.


silverstorm, the mandatory draft includes women. (Although exemptions are common in orthodox communities where woman trade army service for two years of mandatory social work.)


why people still think it's ok to have secrets in a government?

is it the many movies where the hero help the gov to hide some alien invasion to prevent panic that causes people to think this is right?


Because people who wish you harm for various reasons really exist, and nobody's figured out how to tell the entire world every detail about our defensive capabilities without substantially weakening them in the process.

I'm a little-l libertarian and I'll happily join the calls for "more transparency" where appropriate, but "government should have no secrets", especially in the area of self defense, is not a realistic position. It's an abusable-but-necessary evil.


I don't want to be dragged into politics right now, but

> Because people who wish you harm for various reasons really exist, and nobody's figured out how to tell the entire world every detail about our defensive capabilities without substantially weakening them in the process.

..sounds like security through obscurity to me.


..sounds like security through obscurity to me.

That sounds like you are echoing something you heard once without understanding the reasoning behind it.

security through obscurity usually doesn't make sense WRT computer security because the attacks the computer systems are often subject to are sustained for long periods and can't be stopped (think of someone downloading your software to attack it).

In a military situation you do have the capability to retaliate and/or reinforce. This changes the situation because it makes time a critical factor. In that case, obscurity makes a lot of sense because it slows down the attacker. When you have the ability to change things yourself anything that slows down the attack is useful.

This applies to computer security too - if you can detect an attack, then anything that stops that attack from being successful for long enough that you can neutralize the attack vector is useful. This doesn't imply "security though obscurity", but it does imply that you have defence-in-depth, and you don't give out information about what those lower level defences are. Then if your outer layer is breached there is at least some chance the attacker will trigger some kind of alert while working out what the next layer of defence is. That isn't "security though obscurity", it is "security and obscurity".


No more than keeping your encryption keys a secret is security through obscurity.

Even if you're transparent about your overall scheme, you need to keep some execution details hidden.


no. security and government decency is telling everyone "we spend x billions here and use z and y to encrypt access to it"

what happens is "we spent x billions on toilet seats (to quote an alien movie) and password go over the air unencrypted, but we are not telling you the frequency"


Interestingly I think that anti-government paranoia in the US is largely itself fed by all those movies in which some corrupt US government agency turns out to be the villain.

As a fun exercise, count the number of movies and TV shows in which the CIA is shown in a positive light. The FBI often is, the military usually is, the CIA almost never. Heck, the CIA has such a bad name in American movie land that on the odd occasion they want to show a good American spy (e.g. Die Another Day) they'll put 'em in the NSA instead despite the fact that the activities depicted are much more CIA-like than NSA-like.


Either that or the fact that one minute the President swears to defend the constitution and then the next minute orders unconstitutional wiretaps, torture, invasion, etc.

Or maybe that the country exists because of government tyranny.

Or because the government arrests people just for showing up to the wrong meeting.

Or because they have studied International Relations at Cambridge University and have an understanding of world history. (that one is probably quite rare, but its very effective).


What makes you think they are delaying anything? You think they haven't been doing the same to others? They've been building a cyber division for years.


Every branch of the military has been 'building a force' for years. They all want to be the branch that is more necessary than the others (and therefore gets more funding/prestige). The reality is that 'cyber warfare' is less warfare and more espionage. It's probably already being handled by the NSA/CIA/etc.


I wonder if some of the inventors of the airplane were disappointed to see it used for military purposes, or if it's just my 1990s upbringing that makes me think of the Internet as something beyond the trivial concerns of humanity, and use of it as a battlefield as tragic.


and use of it as a battlefield as tragic Isn't that why it was invented in the first place? Just because it has grown in to something more doesn't mean it has completely cast off its military upbringing.


In terms of publicizing it, I used to see adds for the Air Force Cyber Command on Hulu. It showed pictures of guys in fatigues doing simple things on Windows in cubicles. It didn't look terribly exciting, though they did have red rotating alarm lights in the ceiling at their office.

I think they are putting some effort into it, and they did know what audience to advertise to. You can find a few commercials on YouTube, but I couldn't find the one I saw.


My PC's firewall reports "U.S.DoD" as the owner of every other ping on my computer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: