I often wonder how idiots get into positions of authority
So I’m flipping on the news at zero dark thirty this morning, and, to my surprise, I discover that the video feeds from the Air Force’s super-duper unmanned Predator intelligence-gathering-and-Hellfire-missile-launching aircraft are unencrypted. This means that anyone with a little technical knowledge, a satellite receiver, and a little software can watch, in real time, the video sent from the Predator during operational missions. I don’t suppose it occurred to the designers (note that I’m not referring here to the engineers involved in building the solution, usually the targets of my wrath, especially if they work for Microsoft) of this system that this might be a possibility. That’s why they’re idiots, after all. And, of course, it appears that no one up the chain of command thought to inquire as to the security of this rather sensitive video, perhaps assuming, as I did, that all transmissions to and from an armed military aircraft would be encrypted. Silly me. Shame on them.The problem (among many other related breeches of wireless security, in fact), according to the CBS News report, has been around for a long time. There is now hard evidence that unauthorized entities have in fact gained access to the feeds. There is no quick fix here, but this should never have been a problem in the first place. I lecture frequently on the importance of building a culture of security, on the requirements for basic security elements (a security policy, encryption of the file and VPN varieties, strong authentication, etc.), and on how, when it comes to security, one is never “done”. And here we have a vital national-security system where apparently the job never got started.I occasionally work on government programs. I have no moral or ethical qualms about such, and I am proud to be able to contribute to national security programs whenever I can. I may not agree with the mission (I’ve always been against the “wars” in Iraq and Afghanistan, for example), but I think it’s important to have the capabilities should they ever be required (or for their value as a deterrent). But if the system is fundamentally insecure or otherwise compromised, what’s the point?In the private sector, we fire idiots. I think it’s time to do the same here, well up the management chain, and not just at the contractor responsible for this nonsense. There are plenty of secured satellite systems available; it’s obvious these should be used in situations like this. Obvious to non-idiots, anyway.




